Overview
The Cyber Security Consultant will play a pivotal role in a UK public-sector R&D programme focused on cybersecurity and operational assurance of AI agents. This part-time position involves leading the development of security-risk methodologies and providing independent technical oversight throughout the research process. The consultant will collaborate with a senior technical team to assess security implications, establish evidence-based evaluations, and enhance the understanding of risks associated with AI technologies.
Responsibilities
- Develop and challenge the threat model for consequential AI-agent actions.
- Identify credible threat scenarios, security assumptions and important failure conditions.
- Define practical consequence and exposure categories relevant to CISO and operational security decision-making.
- Translate research questions into measurable security evaluation criteria.
- Establish evidence-backed approaches to evaluating current exposure, organisational controls and residual risk.
- Review experimental methods for validity, reproducibility and potential bias.
- Help interpret negative, ambiguous or inconclusive research findings.
- Contribute to final evaluation conclusions, recommendations and technical limitations.
Requirements
- Significant senior experience in cybersecurity risk, security architecture, threat modelling or technical security evaluation.
- Strong understanding of enterprise security controls and operational cyber risk.
- Experience designing, developing or critically reviewing threat models.
- Ability to distinguish evidence from assertion and challenge unsupported conclusions.
- Strong analytical skills, technical writing and sound independent judgement.
- Preferred experience with Agentic AI security, AI threat modelling, or assurance.
- Direct engagement with CISOs or enterprise risk owners is a plus.
- Familiarity with the UK Cyber Assessment Framework or comparable security guidance.