Cyber Security Specialist
Cyber Asset Intelligence Consultant (Axonius)
Day rate: £500 outside IR35
Location: United Kingdom
Working pattern: Remote
Duration: 6 months initially, with scope to extend
I'm supporting a growing cyber security consultancy that is looking to hire a Cyber Asset Intelligence Consultant to take ownership of the asset data layer and turn it into intelligence the business can act on.
This is a delivery role inside a large, complex, Microsoft-centric estate. The platform is already in place. What is needed is someone to make the data trustworthy, then make it useful: building the queries, tags and dashboards that let security and business stakeholders see what they actually own, how well it is covered, and where the risk genuinely sits.
The role
You will own the translation of asset data into asset intelligence and business value, delivering:
- A high-confidence, categorised enterprise asset inventory
- A formalised confidence and visibility classification model
- Visibility metrics and security control coverage dashboards, initially EDR-focused
- Risk-Based Vulnerability Management integrated with remediation workflows
- Structured Shadow IT risk identification and governance
- CMDB gap analysis and controlled ServiceNow synchronisation
- Asset enrichment feeding into the SecOps platform to strengthen investigations
Day to day, this will involve:
- Interrogating the data presented in Axonius, working with user groups and vendors to understand it, and using that to drive advanced filtering and improve confidence in and efficacy of the data
- Analysing high-confidence data on an ongoing basis to identify new trends and insights, then translating those into cyber security and business intelligence dashboards, working closely with the people who consume them
- Owning the creation of queries, tags and dashboards that support live business requirements
- Acting as product SME and first line service support for service consumers building and using their own queries and dashboards
- Liaising with service consumers and business owners to understand evolving requirements for cyber and business insight
- Supporting the design and build of additional dashboards, queries and reports
- Liaising with architecture, engineering and the vendor to stay ahead of product roadmap and feature development
- Building, maintaining and reporting on service assurance and metrics
The split is roughly four days hands-on to one day of stakeholder engagement. You will be client-facing and running your own engagements without supervision, so credibility as a trusted advisor in front of both technical and non-technical stakeholders matters as much as the technical work itself.
What they are looking for
- Hands-on delivery experience with security technologies, working hand in hand with business and operational stakeholders to drive optimal value from them
- A broad understanding of IT and security technologies and the data those tools produce, and how to turn that data into asset insight and intelligence
- Demonstrable evidence of getting up the curve quickly on unfamiliar products
- Strong hands-on experience across several of the following:
- Endpoint management, for example Intune
- Network security and management, for example Cisco, Fortigate, Forescout, SolarWinds
- Cloud and cloud security platforms, for example Azure, AWS, GCP, Wiz
- Identity platforms, for example Entra, Okta
- Vulnerability management tooling, for example Rapid7, Qualys
- EDR, for example Defender, CrowdStrike
- SIEM, for example Sentinel, Splunk
- Comfort in a Microsoft-heavy environment, particularly the Defender stack across endpoint, cloud and identity
- Enough cloud infrastructure literacy to understand how design decisions shape what is possible with the data. You will not be designing cloud infrastructure here, but you will need to read it and work with the consequences
- The ability to translate technical detail for senior and non-technical stakeholders and deliver real value from it
The ideal candidate will also have
The strongest people for this will have navigated the tricky problems rather than simply operated the tooling:
- Vulnerability management: sensible asset grouping and tagging based on genuine business priority rather than tool defaults
- EDR: working out why detection and response rules are not firing
- SIEM: resolving competing signals from devices and making defensible decisions about which to trust
Beyond that:
- Direct experience of the Axonius product and personnel in a delivery capacity is the ideal. Axonius SME support will be provided, so experience of a comparable cyber asset attack surface management or asset intelligence platform is a strong substitute
- A background in the deep technical build work: standing up vulnerability management programmes, telemetry pipelines or SecOps tooling from the ground up
- Architecture-level experience. Several of the strongest candidates for this will have come through an architect route rather than an analyst one
This would suit someone who has been there and done that in a deep technical role, enjoys being handed a messy data estate and making it trustworthy, and wants to own client relationships directly rather than deliver from behind someone else.
Please message me directly if you would like to discuss the role.