Cyber Security Consultant at OB Collective, Greater London, £Contract Rate

Contract Description

OB Collective develops independent verification technology for organisations operating in government, regulated and high-assurance environments. Our work is concerned with establishing reliable evidence about information and automated actions before organisations rely on them.


We’re building a senior technical team for a six-to-twelve-month engagement on a UK public-sector R&D programme focused on the cybersecurity and operational assurance of AI agents. We’re looking for a part-time Senior Cyber Security & Evaluation Specialist – AI Risk to lead the security-risk methodology and provide independent technical challenge throughout the research and evaluation work.


As AI agents gain access to organisational data, credentials, tools, APIs and enterprise systems, organisations need stronger ways to understand the exposure these systems create, assess potential consequences and determine whether existing or proposed controls materially reduce that exposure.


The programme will extend an existing software capability into agentic environments, establish independently verifiable evidence around selected actions and assess how that evidence can support cyber-risk decisions, control evaluation and the measurement of remaining risk.


There is an existing technical capability and a defined research direction. The challenge is to establish what can be demonstrated reliably through controlled testing, distinguish measurable security improvement from unsupported assurance claims and identify the limitations of the evidence available.


You will work alongside senior engineers and security specialists to develop the threat model, risk methodology, research measures, evaluation scenarios and interpretation of results.


This is not a conventional compliance or governance-only position. We need someone with strong applied cybersecurity expertise who can turn operational security concerns into measurable evaluation criteria, challenge technical assumptions and assess whether research conclusions are supported by evidence.


The role is UK-based, outside IR35 and primarily remote, with occasional travel for workshops and technical activity. This is a part-time specialist engagement involving defined blocks of work across the wider programme, with greater involvement during early research design and later security evaluation.


What you’ll do


  • Develop and challenge the threat model for consequential AI-agent actions.
  • Identify credible threat scenarios, security assumptions and important failure conditions.
  • Define practical consequence and exposure categories relevant to CISO and operational security decision-making.
  • Translate research questions into measurable security evaluation criteria.
  • Develop methods for assessing agent permissions, reachable systems and exercised access.
  • Establish evidence-backed approaches to evaluating current exposure, organisational controls and residual risk.
  • Define expert reference judgements and methods for comparing or calibrating security findings.
  • Challenge how incomplete evidence, uncertainty and coverage limitations are represented.
  • Design controlled misuse, failure and adversarial test scenarios.
  • Review experimental methods for validity, reproducibility and potential bias.
  • Work with engineers, independent security testers and operational practitioners.
  • Assess whether mitigations produce a measurable and meaningful reduction in exposure.
  • Help interpret negative, ambiguous or inconclusive research findings.
  • Contribute to final evaluation conclusions, recommendations and technical limitations.


What we’re looking for


  • Significant senior experience in cybersecurity risk, security architecture, threat modelling or technical security evaluation.
  • Strong understanding of enterprise security controls and operational cyber risk.
  • Experience designing, developing or critically reviewing threat models.
  • Experience establishing measurable security assessments, tests or assurance criteria.
  • Ability to distinguish evidence from assertion and challenge technically plausible but unsupported conclusions.
  • Strong understanding of uncertainty, evidence limitations and incomplete observation.
  • Ability to work credibly with senior software engineers, architects and technical researchers.
  • Experience explaining complex technical risk to CISOs or equivalent senior security decision-makers.
  • Strong analytical skills, technical writing and sound independent judgement.


Preferred experience


  • Agentic AI security or the security of autonomous systems.
  • AI threat modelling or assurance.
  • MITRE ATLAS.
  • OWASP guidance for LLM or agent systems.
  • UK Cyber Assessment Framework or comparable security guidance.
  • Independent red-team or adversarial evaluation.
  • Experimental design, benchmarking or applied security research.
  • Government, defence, critical infrastructure or high-assurance environments.
  • Direct engagement with CISOs or enterprise risk owners.