Interested? Send us your CV
Submit your CV, and we'll get in touch.
| Job Title | Cyber and Information Assurance Consultant |
|---|---|
| Hours Per Week | 37 |
| Reporting to | Principal Cyber Consultant / Head of Services |
| Location | Remote-first, with attendance at Nexor’s Nottingham office and customer locations as required. Regular UK travel may form part of the role. Occasional international travel may arise. |
| Issue Date | August 2026 |
The Cyber and Information Assurance Consultant supports customers in identifying, assessing and managing cyber security and information assurance risks across complex digital, operational and high-assurance environments. The role combines consultancy, risk assessment, security assurance, governance and stakeholder engagement. Work may span secure information exchange, cross-domain solutions, cloud services, networks, applications, data platforms and operational systems.
The postholder translates security obligations, business needs, threat information and technical evidence into clear risk-based recommendations. The role suits a cyber security, risk, assurance or systems professional seeking broader customer-facing responsibility across defence, government and critical national infrastructure.
Cyber Risk Assessment
Conduct cyber security and information assurance risk assessments.
Identify threats, vulnerabilities, impacts and control requirements.
Develop proportionate risk treatment recommendations.
Maintain cyber risk registers, assumptions, dependencies and residual risk positions.
Support formal risk acceptance and escalation activity.
Provide clear advice to technical and non-technical stakeholders.
Information Assurance
Support assurance of systems, services and information-handling arrangements.
Assess compliance against customer, contractual and regulatory requirements.
Review security documentation, technical evidence and control implementation.
Support security case development and assurance planning.
Contribute to accreditation, authorisation and approval activity.
Maintain traceability between requirements, controls, evidence and risk decisions.
Security Governance
Support development and maintenance of:
Security policies.
Standards.
Procedures.
Governance frameworks.
Assurance plans.
Security management plans.
Additionally:
Contribute to security governance forums and assurance boards.
Track security actions, risks, decisions and evidence.
Support senior ownership and oversight of cyber security risk.
Secure-by-Design Support
Work with architects, engineers and delivery teams to embed security throughout the lifecycle.
Review solution designs for security, privacy, resilience and assurance implications.
Support identification of security requirements and non-functional requirements.
Apply defence-in-depth, least-privilege and Zero Trust principles.
Ensure security considerations form part of design, build, test, deployment and operation.
Threat and Vulnerability Assessment
Assess credible threat scenarios relevant to customer environments.
Review vulnerability information and technical findings.
Support interpretation of penetration test, vulnerability scan and security assessment outputs.
Evaluate exploitability, business impact and operational consequence.
Recommend remediation priorities and compensating controls.
Customer Engagement
Work with:
Customer security teams.
Senior risk owners.
Solution and Security Architects.
Systems Engineers.
Project and Delivery Managers.
Software and Platform Engineers.
Product Teams.
Suppliers and Technology Partners.
Additionally:
Participate in workshops, assurance reviews and customer briefings.
Explain cyber security risks and control recommendations in accessible language.
Build trusted and professional customer relationships.
Continuous Improvement and Professional Development
Maintain awareness of emerging cyber threats, regulation and assurance practice.
Contribute to internal methods, templates and guidance.
Share knowledge across Nexor communities of practice.
Support lessons identified and service improvement activity.
Work towards recognised cyber security and assurance qualifications.
Professional experience in cyber security, information assurance, risk management, systems engineering or a related discipline.
Experience contributing to security assessment or assurance activity.
Experience working within multidisciplinary technical teams.
Experience producing clear and structured security documentation.
Ability to identify and communicate cyber risks.
Ability to interpret technical evidence and control requirements.
Experience engaging with technical and non-technical stakeholders.
Strong interest in defence, government, critical infrastructure or high-assurance systems.
Cyber Security and Assurance
Cyber risk management.
Information assurance.
Security governance.
Security controls.
Threat and vulnerability assessment.
Security lifecycle principles.
Residual risk and risk acceptance.
Assurance evidence and traceability.
Frameworks and Standards
Working knowledge of some of the following:
ISO/IEC 27001.
ISO/IEC 27005.
NCSC Cyber Assessment Framework.
Cyber Essentials.
NIST Cybersecurity Framework.
MOD Defence Standard 05-138.
Government Security Classifications.
Secure-by-Design principles.
Defence, government or critical national infrastructure experience.
Experience within high-assurance or regulated environments.
Exposure to secure information exchange or cross-domain solutions.
Experience supporting accreditation or authority-to-operate processes.
Familiarity with MOD security and assurance practices.
Experience with cloud security assurance.
Experience supporting security architecture reviews.
Knowledge of data protection and privacy impact assessment.
Current SC clearance.
Experience supporting bids, proposals or pre-sales activity.
SFIA Skill | Level | Description |
Information Security (SCTY) | 4 | Application of security controls, risk management and assurance practice |
Information Assurance (INAS) | 4 | Assessment of information risk and assurance evidence |
Risk Management (BURM) | 4 | Identification, assessment and treatment of business and cyber risks |
Security Administration (SCAD) | 3/4 | Support to security procedures and control operation |
Vulnerability Assessment (VUAS) | 3/4 | Assessment and interpretation of vulnerabilities |
Consultancy (CNSL) | 4 | Provision of cyber and assurance advice within defined areas |
Stakeholder Relationship Management (RLMT) | 4 | Productive engagement with customer and technical stakeholders |
Requirements Definition and Management (REQM) | 4 | Definition and traceability of security requirements |
Methods and Tools (METL) | 4 | Application of assurance methods, frameworks and tools |
Compliance Audit (COAU) | 4 | Assessment of compliance against policies, standards and controls |
Essential
A degree, degree apprenticeship or equivalent experience in a relevant discipline, including:
Cyber Security.
Information Security.
Computer Science.
Systems Engineering.
Software Engineering.
Electronic Engineering.
Risk Management.
Mathematics.
Another relevant science, technology or engineering discipline.
Desirable
Progress towards, or interest in obtaining:
CISSP.
CISM.
CRISC.
ISO/IEC 27001 Lead Implementer.
ISO/IEC 27001 Lead Auditor.
NCSC Certified Cyber Professional.
Chartered Cyber Security Professional.
Risk management qualification.
The role provides progression towards:
Senior Cyber and Information Assurance Consultant.
Principal Cyber Consultant.
Security Architect.
Cyber Risk Lead.
Information Assurance Lead.
Security Assurance Manager.
Head of Cyber Assurance.
Development support may include:
Mentoring from senior cyber consultants and architects.
Customer and programme exposure.
Security architecture and assurance training.
Support towards professional certification.
Opportunities to lead defined assurance work packages.
Participation in internal research and service development.
Exposure to bids, pre-sales and consultancy shaping.
Access to cyber and architecture communities of practice.
Success within the role shall be measured through:
Quality and clarity of assurance deliverables.
Effective identification and communication of cyber risks.
Completion of assigned work against customer objectives.
Constructive participation in assurance and design reviews.
Effective management of risks, actions and evidence.
Positive customer and stakeholder feedback.
Growth in assurance and domain competence.
Contribution to successful bids and customer engagements.
Increasing ownership of cyber assurance work packages.
Progress towards relevant professional qualifications.
The role reports to the Head of Services and/or Principal Cyber Consultant.
Day-to-day direction may also come from a Security Architect, Programme Security Lead or Project/Delivery Manager.
Early to mid-career cyber security professional.
Typically suited to candidates with sufficient delivery experience to take ownership of defined cyber risk and assurance activities under senior professional guidance.
Eligibility for UK Security Check clearance.
Compliance with customer and Nexor information-handling requirements.
Compliance with Nexor security, quality and engineering procedures.
Appropriate handling of customer, partner and programme information.
Willingness to work within secure environments where required.
The role holder will be expected to role model and champion the Nexor core values which are: Focus, Adaptable, Respect and Collaboration.
This job description is a guide to the work you may be required to undertake but does not form part of your contract of employment and may change from time to time to reflect changing circumstances.
Interested? Send us your CV
Submit your CV, and we'll get in touch.