Cyber Security Conaultant
Job Description:
Job Titley Cber Security Principal Consultant
Location UK open
Employment Type Permanent
Reporting toe Director of Consulting
Role Summary
As a Cyber Security Principal Consultant, you will lead complex security engagements across strategy, architecture, risk, and delivery. You’ll work directly with senior stakeholders (CISO/CTO/Board), shape security roadmaps, and provide pragmatic guidance across governance, technical controls, and operational resilience.
This role blends hands-on consulting with client leadership, mentoring, and supporting growth through pre-sales and proposal work
Key Responsibilities
Consulting & Delivery Leadership
Lead end-to-end security consulting engagements (discovery → delivery → assurance).
Translate business requirements into practical security recommendations and designs.
Produce high-quality client deliverables: reports, roadmaps, security strategies, and action plans.
Run stakeholder workshops, technical reviews, and executive briefings.
Cyber Security Strategy & Governance
Design and implement security operating models, policies, and governance frameworks.
Lead risk management activities, including security risk assessments and remediation planning.
Support compliance and assurance initiatives (e.g., ISO 27001, NIST, SOC 2, PCI DSS).
Security Architecture & Controls
Provide security input into cloud transformation and enterprise architecture programmes.
Assess and improve security controls across identity, endpoint, network, data, and logging.
Support secure design reviews for applications, infrastructure, and third-party integrations.
Leadership & Mentoring
Act as a subject matter expert across security domains.
Mentor consultants and support capability development within the team.
Contribute to internal best practice, tooling, and reusable frameworks.
Pre-Sales & Business Development
Support proposal writing, scoping, and client presentations.
Help identify follow-on opportunities and build long-term client relationships.
Provide credible input into effort estimates, project plans, and engagement models.
---
Required Skills & Experience
Strong consulting background delivering cyber security programmes in client environments.
Proven stakeholder management experience up to CISO / CTO / Board level.
Hands-on knowledge of security frameworks such as:
NIST, ISO 27001/27002, CIS Controls, COBIT
Strong understanding across key security domains:
IAM / PAM, cloud security, incident response, SIEM/logging, vulnerability management
Able to lead workshops, produce clear documentation, and manage competing priorities.
Strong analytical thinking and ability to simplify complex risk and technical concepts.
---
Desirable Experience
Cloud security expertise (Azure, AWS, GCP) and modern security tooling.
DevSecOps, CI/CD pipeline security, container/Kubernetes security.
Pen test management, threat modelling, and secure SDLC.
Security programme management and operating model design.
Experience in regulated sectors (finance, government, critical infrastructure).
--
Certifications (Preferred)
CISSP / CISM / CISA
ISO 27001 Lead Implementer / Lead Auditor
CCSP / AWS Security Specialty / Azure Security Engineer
SABSA / TOGAF (security architecture)
---
What Success Looks Like
Clients trust you as a senior advisor and delivery lead.
Engagements are delivered on time, with clear outcomes and measurable risk reduction.
You raise the technical standard of security delivery and uplift junior consultants.
You contribute to winning new work and growing strategic accounts.