Cyber Security Conaultant

  • -
  • Full-Time
  • Remote
  • 48,000-68,000 GBP / Year

Job Description:

Job Titley Cber Security Principal Consultant

Location UK open 

Employment Type Permanent

Reporting toe Director of Consulting


Role Summary

As a Cyber Security Principal Consultant, you will lead complex security engagements across strategy, architecture, risk, and delivery. You’ll work directly with senior stakeholders (CISO/CTO/Board), shape security roadmaps, and provide pragmatic guidance across governance, technical controls, and operational resilience.


This role blends hands-on consulting with client leadership, mentoring, and supporting growth through pre-sales and proposal work


Key Responsibilities

Consulting & Delivery Leadership

Lead end-to-end security consulting engagements (discovery → delivery → assurance).

Translate business requirements into practical security recommendations and designs.

Produce high-quality client deliverables: reports, roadmaps, security strategies, and action plans.

Run stakeholder workshops, technical reviews, and executive briefings.

Cyber Security Strategy & Governance

Design and implement security operating models, policies, and governance frameworks.

Lead risk management activities, including security risk assessments and remediation planning.

Support compliance and assurance initiatives (e.g., ISO 27001, NIST, SOC 2, PCI DSS).

Security Architecture & Controls

Provide security input into cloud transformation and enterprise architecture programmes.

Assess and improve security controls across identity, endpoint, network, data, and logging.

Support secure design reviews for applications, infrastructure, and third-party integrations.

Leadership & Mentoring

Act as a subject matter expert across security domains.

Mentor consultants and support capability development within the team.

Contribute to internal best practice, tooling, and reusable frameworks.

Pre-Sales & Business Development

Support proposal writing, scoping, and client presentations.

Help identify follow-on opportunities and build long-term client relationships.


Provide credible input into effort estimates, project plans, and engagement models.

---

Required Skills & Experience

Strong consulting background delivering cyber security programmes in client environments.

Proven stakeholder management experience up to CISO / CTO / Board level.

Hands-on knowledge of security frameworks such as:

NIST, ISO 27001/27002, CIS Controls, COBIT

Strong understanding across key security domains:

IAM / PAM, cloud security, incident response, SIEM/logging, vulnerability management

Able to lead workshops, produce clear documentation, and manage competing priorities.

Strong analytical thinking and ability to simplify complex risk and technical concepts.

---

Desirable Experience

Cloud security expertise (Azure, AWS, GCP) and modern security tooling.

DevSecOps, CI/CD pipeline security, container/Kubernetes security.

Pen test management, threat modelling, and secure SDLC.

Security programme management and operating model design.

Experience in regulated sectors (finance, government, critical infrastructure).

--

Certifications (Preferred)

CISSP / CISM / CISA

ISO 27001 Lead Implementer / Lead Auditor

CCSP / AWS Security Specialty / Azure Security Engineer

SABSA / TOGAF (security architecture)

---

What Success Looks Like

Clients trust you as a senior advisor and delivery lead.

Engagements are delivered on time, with clear outcomes and measurable risk reduction.

You raise the technical standard of security delivery and uplift junior consultants.

You contribute to winning new work and growing strategic accounts.