Cyber Security Consultant
About the Role
We are seeking an experienced Cyber Security Consultant to join a growing cyber security practice. This role is ideal for a well-rounded cyber professional who enjoys working directly with clients, providing strategic advice, and delivering practical security improvements.
You will act as a trusted advisor to a portfolio of clients, helping them identify risks, improve security maturity, achieve compliance objectives, and strengthen their overall cyber resilience.
Key Responsibilities
- Conduct cyber security risk assessments and gap analyses
- Perform security maturity reviews and provide actionable recommendations
- Deliver assessments against frameworks including ISO 27001, NIST, CIS Controls, and Cyber Essentials/Cyber Essentials Plus
- Support clients with governance, risk, and compliance (GRC) initiatives
- Review vulnerability assessment and penetration testing findings, providing remediation guidance
- Advise clients on security strategy, governance, policies, and best practices
- Assist organisations in improving their cloud security posture
- Prepare and present reports to technical and non-technical stakeholders
- Manage multiple client engagements simultaneously while maintaining high service levels
- Build strong customer relationships and act as a trusted cyber security advisor
- Support pre-sales activities, workshops, and client proposals when required
- Stay up to date with emerging threats, technologies, and industry best practices
Essential Experience
- Experience in a Cyber Security Consultancy, MSSP, MSP, or Security Advisory environment
- Proven ability to manage multiple client engagements simultaneously
- Strong stakeholder management and client-facing skills
- Experience engaging with business owners, senior leadership teams, and decision-makers
- Ability to communicate technical concepts to non-technical audiences
- Experience working with SME and mid-market organisations
- Strong consultative approach with excellent problem-solving abilities
Technical Knowledge
Strong understanding of:
- Risk Assessments
- Security Maturity Reviews
- Vulnerability Management
- Governance, Risk & Compliance (GRC)
- Cyber Essentials & Cyber Essentials Plus
- ISO 27001
- NIST Framework
- CIS Controls
- Cloud Security
- Security Improvement Programmes
- Penetration Testing Remediation
Desirable Skills
- Knowledge of Microsoft Security technologies and cloud-native security solutions
- Experience supporting security strategy development
- Commercial awareness and ability to support pre-sales activities
- Experience producing executive-level reports and recommendations
- Comfortable operating in both technical and business-focused environments
Certifications
The following certifications are desirable:
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- CEH (Certified Ethical Hacker)
- ISO 27001 Lead Implementer, Lead Auditor, or equivalent