Principal Cyber Assurance Advisor (OT/Technical Arch./Supply Chain)
We are recruiting on behalf of a client in the nuclear / Critical National Infrastructure (CNI) sector for a Cyber Assurance Principal Advisor to lead the delivery of second-line cyber assurance across key domains including OT, technical architecture, and supply chain. This role ensures cyber security controls are effectively assessed, risks are independently evaluated, and assurance activities are aligned with organisational priorities. You will oversee a team of advisors, manage assurance planning and execution, and act as a key liaison between assurance, operational teams, and senior stakeholders. If you are considering sending an application, make sure to hit the apply button below after reading through the entire description.
What you'll do
Deliver second-line assurance activities across either OT, technical architecture, or supply chain domains (these are individual Principal-level roles)
Conduct control effectiveness reviews, risk-based assessments, and thematic assurance activities
Provide expert input into the development of assurance frameworks, methodologies, and reporting
Collaborate with first-line teams and third-line audit to ensure comprehensive assurance coverage
Produce assurance reports and dashboards for governance forums and regulatory stakeholders
Support regulatory inspections and audits, including evidence collation and response coordination
Track and verify remediation of assurance findings and contribute to lessons learned
Maintain awareness of emerging threats, technologies, and regulatory expectations to inform assurance planning
Lead, mentor, and develop a team of cyber assurance advisors to build capability and consistency
Promote a culture of cyber risk awareness and accountability across the organisation
What we're looking for
Strong experience in cyber assurance, audit, risk management, or control testing within a regulated environment
In-depth understanding of cyber security frameworks (e.g., NCSC CAF, ISO 27001, NIST CSF, NIST 800-53)
Domain-specific knowledge in at least one of: OT, technical architecture, or supply chain security
Strong analytical, reporting, and stakeholder engagement skills
Degree or equivalent experience in cyber security, engineering, xehkeey or a related field
Relevant certifications (e.g., CISA, CISSP, ISO 27001 Lead Auditor, GIAC, CRISC)
Desirable: Experience in the nuclear or CNI sector; familiarity with ONR SyAPs, NISR 2003, and HMG SPF; experience with assurance automation or continuous control monitoring; knowledge of risk-based assurance methodologies and tooling
What's on offer
Annual bonus of up to 15%, made up of company and personal performance
Attractive defined contribution pension scheme – company matches up to 13.5% for a 7% employee contribution
30 days annual leave + bank holidays, plus ability to purchase an extra 2.5 days per year
Ability to carry over 10 days annual leave each financial year
What you'll do
Deliver second-line assurance activities across either OT, technical architecture, or supply chain domains (these are individual Principal-level roles)
Conduct control effectiveness reviews, risk-based assessments, and thematic assurance activities
Provide expert input into the development of assurance frameworks, methodologies, and reporting
Collaborate with first-line teams and third-line audit to ensure comprehensive assurance coverage
Produce assurance reports and dashboards for governance forums and regulatory stakeholders
Support regulatory inspections and audits, including evidence collation and response coordination
Track and verify remediation of assurance findings and contribute to lessons learned
Maintain awareness of emerging threats, technologies, and regulatory expectations to inform assurance planning
Lead, mentor, and develop a team of cyber assurance advisors to build capability and consistency
Promote a culture of cyber risk awareness and accountability across the organisation
What we're looking for
Strong experience in cyber assurance, audit, risk management, or control testing within a regulated environment
In-depth understanding of cyber security frameworks (e.g., NCSC CAF, ISO 27001, NIST CSF, NIST 800-53)
Domain-specific knowledge in at least one of: OT, technical architecture, or supply chain security
Strong analytical, reporting, and stakeholder engagement skills
Degree or equivalent experience in cyber security, engineering, xehkeey or a related field
Relevant certifications (e.g., CISA, CISSP, ISO 27001 Lead Auditor, GIAC, CRISC)
Desirable: Experience in the nuclear or CNI sector; familiarity with ONR SyAPs, NISR 2003, and HMG SPF; experience with assurance automation or continuous control monitoring; knowledge of risk-based assurance methodologies and tooling
What's on offer
Annual bonus of up to 15%, made up of company and personal performance
Attractive defined contribution pension scheme – company matches up to 13.5% for a 7% employee contribution
30 days annual leave + bank holidays, plus ability to purchase an extra 2.5 days per year
Ability to carry over 10 days annual leave each financial year