Cyber Security Assurance Consultant - Contract
Location: Hybrid - London or Manchester
Contract: 6 months
Day Rate: £500 - £525 p/d
IR35: Outside
We're looking for an experienced Cyber Security Risk & Assurance SME to support a major security transformation programme within a complex enterprise environment.
The role sits between cyber security, risk, controls and data, ensuring security metrics and technical evidence provide an accurate and defensible view of control effectiveness and residual risk.
The Role
You'll work with security, risk, data and technology teams to:
- Assess the design and operating effectiveness of cyber controls
- Review security metrics, KRIs/KPIs and underlying evidence
- Translate technical findings into clear residual risk assessments
- Validate security reporting against source data, risk registers, audit findings and incidents
- Identify gaps across controls, data quality and security reporting
- Review data lineage, security telemetry and integrations to challenge data completeness
- Define acceptance criteria and support testing/UAT
- Produce concise assurance findings and recommendations
- Facilitate workshops and challenge technical and senior stakeholders constructively
Essential Experience
We're looking for strong experience across:
- Cyber Security Risk & Assurance/GRC
- Security controls testing and assurance
- Assessing control effectiveness and residual risk
- Cyber metrics, KRIs/KPIs and risk reporting
- Data-driven security assurance
- Investigating conflicting technical evidence
- Working knowledge across several security domains such as vulnerability management, cloud security, IAM, endpoint security, secure development, third-party risk or incident management
- Understanding structured data, APIs, data lineage and security telemetry
- Defining acceptance criteria and supporting testing/UAT
- Strong stakeholder management and workshop facilitation
- Producing clear, defensible assurance and governance reporting
Relevant certifications such as CISSP, CISM, CRISC, CISA or ISO 27001 would be beneficial but aren't essential.
This would suit a hands-on Cyber Risk, Security Assurance, Technology Risk or GRC specialist who can interrogate technical evidence, challenge assumptions and clearly explain what the findings mean from a risk perspective.