Risk & Governance Consultant

NexGen Associates

Cheltenham

On-site

GBP 50,000 - 60,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

NexGen Associates is seeking a Risk & Governance Consultant with mandatory SC clearance to join a leading technical defence consultancy in the UK. The role involves advising clients on security governance, risk management and regulatory compliance, and may require frequent travel across the UK.

You will contribute to client delivery, help win new business, and mentor junior staff as part of a growing business unit.

Qualifications

  • SC clearance is mandatory to be eligible for this role.
  • Experience delivering Risk & Governance consultancy in Defence or UK government sectors.
  • Ability to perform security risk assessments and provide technical assurance.
  • Strong communication skills and ability to manage multiple clients and stakeholders.

Responsibilities

  • Provide security advice and guidance for clients in business as usual, technical refresh and new project environments.
  • Identify and establish security governance to meet client business requirements.
  • Identify client risks and determine remediation based on business risk appetite.
  • Perform compliance activity to assess CS&IA controls and address gaps.
  • Create or review client policies and procedures to meet regulatory requirements.
  • Build relationships with team members, customers and stakeholders to improve service value.
  • Work with clients to implement controls that deliver investment value and support operations.
  • Mentor others and assist the Head of Services in strategy and growth of the BU.

Skills

Security governance
Risk assessment
Communication
MS Office
Stakeholder management
Project juggling

Education

ISO 27001 CS&IA degree-level education
CIISec / UK Cyber Security Council membership (or eligible)
Security clearance (SC) current or maintainable

Job description

Salary £50,000 - £60,000 depending on level of experience

You must have a minimum of SC clearance to be eligible for this role

NexGen Associates is working with a leading technical defence consultancy. Our client are looking to take on a Service Leaver or Veteran to fill there Risk & Governance Consultant role. They are a veteran friendly company and will support and guide you through your transitioning process.

Main Responsibilities:
  • The successful candidate will be a knowledgeable, enthusiastic and conscientious individual who has the relevant qualifications, certifications and experience in line with the level of consultant you are applying for. You will work on a range of client-facing projects, large and small, but will also be expected to contribute to winning new business and managing delivery. To be successful in this role, you need to have the ability to work on multiple projects and with many stakeholders concurrently. Your key responsibilities will encompass the following:
  • Provide security advice and guidance for clients in ‘business as usual’, technical refresh and new project environments.
  • Identify and establish good security governance to meet client business requirements.
  • Identify client risks within client operational environments and determine appropriate remediation based on business risk appetite that protects information assets from loss, misuse, leakage or corruption.
  • Perform compliance activity on client systems and business processes to assess the levels of CS&IA controls and identify gaps to address.
  • Create or review client policies and procedures to meet corporate and regulatory requirements.
  • Build successful working relationships with team members, key customers and stakeholders that improves the value of the services being performed.
  • Work in partnership with clients to implement controls in pragmatic ways that deliver investment value and support business operations.
  • Mentor others within the team in a technical and consultancy capacity.
  • Proactively assist the Head of Services in the strategy and growth of the BU.
The Ideal Candidate:
  • The ideal candidate will meet the majority or all of the following (in line with the level of consultant you are applying for):
  • Willingness to frequently work at secure government facilities (minimum 3 days/week for periods of time).
  • Experience of delivering technical Risk & Governance consultancy within a Defence environment, or other UK Government sectors.
  • Ability to provide technical assurance, risk management and solutions within complex scenarios.
  • Ability to conduct, deliver and maintain technical security risk assessments using established or novel approaches.
  • Excellent verbal and written communication skills.
  • High proficiency in all Microsoft Office applications.
  • Ability to work on multiple projects and tasks concurrently, successfully balancing business and client priorities.
  • Ability to provide high-quality work under pressure that delivers security outcomes to tight deadlines and manage client-stakeholder expectations.
  • Ability to work effectively both individually and as a senior team member in a multi-disciplined organisation.
  • Ability to coordinate and manage multi-disciplined resources, including technical specialists, while providing coherent reporting to non-technical business stakeholders.
  • Ability to provide threat detection and monitoring technologies and services.
  • Ability to produce incident response plans and coordinate desktop incident response exercises.
  • Broad knowledge and application of common bodies, standards, frameworks, guidelines and legislation, including:
  • HMG/NCSC Information Assurance Policies, Standards and Guidelines
  • Cross-government security accreditation and secure by design processes
  • JSP440 (plus other standard MoD IA methods)
  • DCPP’s Cyber Security Model
  • List X, List N
  • Office for Nuclear Regulation (ONR) Security Assessment Principles (SyAPs)
  • NIST
  • GDPR, DPA, Computer Misuse Act, Official Secrets Act
  • NIS-D
  • Flexibility to travel and work throughout the UK.
  • Ambition to work in a challenging and rewarding role that provides real benefit to clients.
  • A proactive interest in maintaining and enhancing technical and consultancy skills.
Professional Qualifications, Certifications and Security Clearances:
  • Full Member of CIISec and/or UK Cyber Security Council (Security and Information Risk Advisor, Auditor or Security Architect) or the agreement and ability to achieve such certification within 6 months of employment.
  • Holder of current key security industry certifications such as COMPTIA Security +, CISSP, CISM, and ISO 27001CS&IA associated degree-level education (desirable)
  • Current high-level security clearance and ability to maintain it.

Our client is a Defence Employer Recognition Scheme Gold Award winner.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Risk & Governance Consultant – Defence Sector
Senior Risk & Governance Consultant – Defence Sector

NexGen Associates • Cheltenham

On-site
GBP 50,000 - 60,000
Cyber & Information Assurance Consultant / Senior Consultant / Principal Consultant
Cyber & Information Assurance Consultant / Senior Consultant / Principal Consultant

Cyber UK • United Kingdom

Hybrid
GBP 65,000 - 120,000
Cyber Security Consultant
Cyber Security Consultant

Anson McCade • Greater London

Hybrid
GBP 70,000 - 110,000
Competitive salary
Comprehensive benefits package
Hybrid working
Security Consultant
Security Consultant

Anson McCade • High Wycombe

On-site
GBP 80,000 - 105,000
Cyber Security Consultant
Cyber Security Consultant

Anson McCade • West of England

On-site
GBP 70,000 - 95,000
25 days' vacation
Private medical insurance
3 extra days leave for charitable work
GRC Consultant
GRC Consultant

identifi Global Resources • Reading

Hybrid
GBP 94,000 - 127,000
Cyber Security Consultant
Cyber Security Consultant

Datasource • Greater London

Hybrid
GBP 39,000 - 95,000
26 days Annual Leave
Pension contribution matched up to 8%
Private Medical Insurance
+5
Cyber Security Consultant
Cyber Security Consultant

Matchtech • Portsmouth

Hybrid
GBP 65,000 - 90,000
Hybrid working
Annual bonus
Private healthcare
+5
Cyber Security Consultant
Cyber Security Consultant

Matchtech • Plymouth

Hybrid
GBP 65,000 - 90,000
Private healthcare
Enhanced pension scheme
Life assurance
+1
Cyber Security Consultant – Incident and Vulnerability Management
Cyber Security Consultant – Incident and Vulnerability Management

Searchability • Greater London

Hybrid
GBP 91,000 - 119,000
Hybrid working
Locations: Preston, London, Birmingham
Defence sector exposure