Location: High Wycombe (2 days per week onsite) Sector: Defence Clearance: Active SC required Contract: 2-4 months initially Rate: Up to £500 per day Start: ASAP/within a few weeks
Role Overview
A high-profile defence programme is seeking an experienced Security Consultant/Security Analyst to provide security assurance, risk management and compliance expertise across a key technology and AI-enabled application.
This role sits at the intersection of security assurance, security-by-design, and government security compliance, working closely with engineering teams, programme leadership and senior military stakeholders. Around 50% of the role involves stakeholder engagement, making strong communication and relationship-building essential.
Key Responsibilities
- Security assurance across the full application lifecycle.
- Security-by-design implementation for new and existing systems.
- Conduct structured risk assessments, identify vulnerabilities and recommend mitigations.
- Advise on government security, risk and compliance requirements.
- Produce and review security documentation, policies, processes and assurance evidence.
- Ensure security requirements are Embedded within technical and programme deliverables.
- Work closely with engineering, architecture and delivery teams to manage security risks.
- Support assurance activities for AI-enabled applications and emerging technologies.
- Engage senior stakeholders and communicate risks clearly and confidently.
- Contribute to programme-wide security governance and assurance forums.
- Interpret and apply MOD security policies and JSPs (JSP 440, JSP 451*, JSP 453).
- Support internal and external assurance activities as required.
Key Skills & Experience
- Proven background as a Security Consultant, Security Analyst, or Security Assurance Consultant.
- Experience within UK Government, MOD, Defence or National Security environments.
- Active SC clearance.
- Strong understanding of government security risk and compliance.
- Experience implementing or assessing security-by-design.
- Knowledge of MOD security policies including JSP 440 , JSP 451, JSP 453 .
- Understanding of government security frameworks and assurance models.
- Experience with Cyber Assessment Framework (CAF) principles.
- Knowledge of ISO 27001 and wider information security standards.
- Ability to produce high-quality risk assessments, security reports, and assurance evidence.
- Strong stakeholder management and communication skills.
- Ability to translate complex risks into clear, actionable recommendations.
- Experience supporting complex, multi-stakeholder technology programmes.
- Exposure to AI-enabled applications or AI security/policy.
- Experience within the MOD.
- Knowledge of MOD AI policy and governance requirements.
- Experience working with military security environments.
- Experience within secure government application environments.
- Knowledge of additional government security standards and assurance frameworks.