Overview
We are seeking experienced GRC, Risk & Assurance Consultants to join a consultancy that specializes in delivering high-profile Defence programmes. The successful candidates will work closely with various stakeholders to embed Secure by Design principles, manage cyber security risks, and provide assurance throughout the project lifecycle. This role offers a hybrid working model, allowing for a combination of remote work and 1-2 days of onsite collaboration in Reading.
Responsibilities
- Provide Risk & Assurance support across Cyber Risk initiatives.
- Embed Secure by Design principles throughout the programme and delivery lifecycle.
- Conduct security risk assessments and assurance reviews.
- Identify, assess, document and manage information security risks.
- Maintain Risk registers, treatment plans and Security assurance documentation.
- Develop Security policies, standards and supporting governance documentation.
- Assess security controls and identify assurance gaps and remediation requirements.
- Support security governance forums, risk reviews and assurance activities.
Requirements
- Strong experience within Cyber Security Risk, Assurance, GRC or Information Assurance.
- Practical knowledge and experience of Secure by Design (SbD).
- Good understanding of security controls, governance and assurance processes.
- Familiarity with recognised security frameworks and standards such as NIST, ISO 27001, Cyber Assessment Framework (CAF).
- Ability to review technical solutions from a security risk and assurance perspective.
- Active security clearance.
- Relevant certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor or equivalent are a plus.
- Experience within Defence, Government, or other highly regulated environments is advantageous.