Senior Cyber Security Consultant - CAF Assurance (x3)
Contract - Outside IR35 | 6 Months (Likely Extension)
Location: Mostly Remote (UK-based with occasional travel)
Clearance: Active SC Clearance Required
Role Overview
We are currently seeking three experienced Senior Cyber Security Consultants to support the delivery of Cyber Assessment Framework (CAF) assurance and cyber resilience work across public sector and critical environment programmes.
This role will involve conducting structured CAF assessments, engaging stakeholders, reviewing evidence, identifying risks, and delivering high-quality assurance outputs aligned to NCSC guidance and best practice. You will be part of a collaborative, high-performing team delivering across multiple assurance engagements.
Key Responsibilities
- Deliver Cyber Assessment Framework (CAF) assurance activities across organisations and critical systems
- Conduct stakeholder workshops, interviews, and evidence reviews to assess cyber resilience maturity
- Support clients in understanding CAF objectives, principles, and outcomes
- Review policies, governance, and technical/operational controls against CAF requirements
- Assess cyber capabilities across:
- Risk management
- Protective security
- Monitoring & logging
- Incident management
- Supply chain security
- Operational resilience
- Produce high-quality outputs including:
- Assessment reports
- Risk findings
- Observations
- Improvement recommendations
- Contribute to assurance documentation, reporting, and delivery artefacts
- Support engagement onboarding, planning, and scheduling
- Collaborate with technical leads and delivery teams to ensure consistent quality
- Drive continuous improvement of CAF methodologies and templates
- Maintain strong stakeholder relationships in complex, fast-paced environments
- Ensure alignment with government security standards and policies
Essential Skills & Experience
- Proven experience delivering cyber security assurance / GRC engagements
- Strong knowledge of the NCSC Cyber Assessment Framework (CAF) or similar frameworks
- Experience facilitating stakeholder interviews and evidence-based assessments
- Ability to analyse both technical and non-technical controls
- Excellent report writing and communication skills
- Experience working within public sector, regulated, or enterprise environments
- Solid understanding of cyber security domains, including:
- Identity & Access Management
- Vulnerability Management
- Incident Response
- SIEM / Monitoring & Logging
- Resilience and business continuity
- Supply chain security
- Ability to manage multiple priorities and deliver under tight deadlines
- Experience working in remote, blended delivery team
If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website.