Cyber Security Consultant - Third Party Auditor
16 hours ago
Gloucester
Cyber Security Consultant - Third-Party Auditor - £500-£550 per day - Inside IR35 - Hybrid working from a site in Gloucester with regular national travel to supplier sites required. Candidates must be eligible to obtain SC clearance. Our client, one of the UK's largest zero-carbon energy producers, is seeking an experienced Cyber Security Third-Party Auditor to join the Nuclear Services Information Security team. This is a hands-on audit role focused on delivering structured, end-to-end third-party security audits in a highly regulated nuclear environment. The successful candidate will be able to demonstrate clear, practical experience in planning audits, testing controls, validating evidence, forming defensible conclusions, and producing formal audit reports. The Role- You will conduct formal cyber security audits of suppliers, contractors and service providers with access to regulated nuclear systems and sensitive information. Your work will directly inform risk acceptance decisions and regulatory assurance. Key Responsibilities- Audit Delivery (Core Responsibility)- - Plan and scope third-party audits based on risk, regulatory requirements and contractual obligations - Conduct audit walkthroughs and structured control interviews - Test design and operating effectiveness of security controls - Perform sampling and traceability testing across processes and systems - Obtain, validate and challenge audit evidence (e.g. logs, system extracts, configurations, tickets, approvals) - Assess compliance against ISO27001, ISO27017, GDPR, Cyber Essentials Plus and relevant sector frameworks - Identify control weaknesses and determine root causes - Form clear, risk-rated findings with practical recommendations - Produce structured audit reports suitable for senior governance review and regulatory scrutiny - Track and verify remediation actions through to closure Third-Party Security Assurance- - Conduct onboarding and periodic supplier cyber security audits - Evaluate supplier control environments handling nuclear information - Provide defensible assurance statements to internal governance boards - Escalate material risks and recommend approval, conditional approval, or rejection of suppliers Regulatory & Governance Support- - Support regulatory inspections and provide audit evidence where required - Maintain complete audit documentation and audit trail records - Contribute to continuous improvement of audit methodology and assurance practices Knowledge, Skills & Experience- - Practical working knowledge of international standards and information security frameworks (ISO27001, ISO27017, GDPR, Cyber Essentials Plus), including auditing control design and operating effectiveness against these frameworks - Proven experience conducting end-to-end audits or formal assurance reviews within a regulated environment (planning, walkthroughs, control testing, evidence validation, reporting and follow-up) - Experience assessing third-party or supplier environments - Understanding of HMG Security Policy Framework and NCSC/CPNI guidance and how to test compliance through audit evidence - Awareness of information security threats, risks and common control failures - Experience applying risk assessment methodologies (ISO27005, NIST, IRAM2) to support audit scoping and risk-rating of findings - Strong documentation and report writing skills - able to produce structured audit reports containing observations, root cause analysis and defensible conclusions - Ability to challenge stakeholders constructively and obtain sufficient appropriate audit evidence - Excellent written and verbal communication skills - Strong analytical mindset, professional scepticism, attention to detail and persistence Candidates whose experience is limited to policy review, questionnaire completion, risk register management or supporting audits without leading control testing are unlikely to be suitable. Qualifications - Preferred (Audit-Focused): - ISO27001 Lead Auditor or Internal Auditor - CISA, CIA or CRISC - CISSP (with demonstrable audit experience) Also considered (with strong practical audit experience): - CISMP - Security+ - CEH - CCNA Additional Information - Regular National travel required - Candidates must be eligible to obtain SC clearance. TPBN1_UKTJ