GRC Consultant

GRC / Risk & Assurance Consultants – Secure by Design (MOD)

Multiple Contract Roles available

Circa £600/day | Outside IR35 | Hybrid – Reading (1–2 days onsite)

We are looking for experienced GRC, Risk & Assurance Consultants to to join a specialist consultancy delivering a major Defence programme in Reading.

As a consultancy they work extensively with UK Government and Defence organisations, supporting the transformation of their operations, digital infrastructure and security capabilities. They are currently leading a number of high-profile cyber risk programmes, helping embed effective security risk management and assurance across complex digital and technology environments.

As part of this engagement, you will work closely with security, architecture, engineering, delivery and governance stakeholders to embed Secure by Design principles, identify and manage cyber security risks, and provide assurance throughout the delivery lifecycle.

WHAT WILL YOU DO?

  • Provide Risk & Assurance support across Cyber Risk initiatives.
  • Embed Secure by Design principles throughout the programme and delivery lifecycle.
  • Conduct security risk assessments and assurance reviews.
  • Identify, assess, document and manage information security risks.
  • Maintain Risk registers, treatment plans and Security assurance documentation.
  • Develop Security policies, standards and supporting governance documentation.
  • Assess security controls and identify assurance gaps and remediation requirements.
  • Work closely with security architects, technical teams, programme stakeholders and assurance functions.
  • Support security governance forums, risk reviews and assurance activities.
  • Gather and assess evidence to demonstrate that security requirements and controls have been implemented effectively.

WHAT YOU NEED TO BE SUCCESFUL?

  • Strong experience within Cyber Security Risk, Assurance, GRC or Information Assurance.
  • Practical knowledge and experience of Secure by Design (SbD).
  • Strong security risk assessment and risk management experience.
  • Good understanding of security controls, governance and assurance processes.
  • Familiarity with recognised security frameworks and standards such as NIST, ISO 27001, Cyber Assessment Framework (CAF)
  • Ability to review technical solutions from a security risk and assurance perspective.
  • Strong stakeholder management skills with the ability to engage effectively with technical teams, architects, delivery teams and senior stakeholders.
  • Active security clearance

NICE TO HAVE, BUT NOT ESSENTIAL

  • Previous experience within Defence, Government, Critical National Infrastructure or other highly regulated environments.
  • Previous experience with UK Government security principles, guidance and assurance approaches.
  • Relevant certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor or equivalent.

WHAT IS ON THE OFFER?

  • Contract: Outside IR35
  • Day Rate: CIRCA £600 per day
  • Location: Reading / Hybrid working
  • Onsite Requirement: Typically visits 1–2 days per week
  • Contract Duration: until the end of the year, with probability to extend through 2027

If you are currently available, approaching the end of a contract, or interested in discussing your next assignment, please apply or get in touch to discuss the opportunity.

Job Details

Company
identifi Global Resources
Location
Reading, Berkshire, UK
Hybrid / Remote Options
Posted