Principal Cyber Risk Management Advisor (SC Cleared)
19 hours ago
London
Principal Cyber Risk Management & Assurance Advisor (SC Cleared) Duration: 3 Months initially Location: London & remote (Hybrid) Rate: £750 per day IR35 Status: Inside Start: ASAP A Cyber Risk Management & Assurance Advisor (SC Cleared) is required for our Government client to lead on their cyber and information security risk management, assurance and architectural advisory for major applications and digital services during alpha, beta and early live phases. You will deliver critical security assessments and IT Health Checks, providing expert assurance across portfolio projects, with a focus on SaaS tooling compliance against NCSC cloud security principles. Facilitate and oversee Security Working Groups throughout all key development and deployment stages, ensuring risks are tracked, logged, and reported to the Head of Cyber Risk and Assurance, with actionable recommendations provided. Produce formal risk assessments and risk treatment plans (RTPs) for all digital services and associated tooling, ensuring robust protection in accordance with business risk appetite. Develop, review, and advise on Secure by Design policies/practices, including safe use of AI, secure coding, and regulatory compliance frameworks (e.g., OWASP, DPIA, GovAssure). Coordinate cross-platform activities and enable secure delivery of new digital services, including supporting incident management and continuous improvement of live service security practices. Routinely provide monthly (and ad-hoc) risk briefings to senior leaders, evidencing assurance, identifying risks outside tolerance, mapping exposure, and recommending mitigations and controls. Mentor and train digital service teams and wider Information Security staff, sharing best practices and building internal capability for risk assessment and management. Support implementation and ongoing usage of risk management tooling, ensuring all details are uploaded promptly and appropriately. Engage proactively with senior internal and external stakeholders, promoting security culture and enabling confident delivery aligned with organisational priorities. Also to engage in future line management activities as the team grows Essential Skills & Experience required: As the Principal Cyber Risk Management & Assurance Advisor (SC Cleared) you will possess the following: Demonstrable experience delivering high-quality, detailed cyber security risk assessments and assurance in large, fast moving, complex digital environments, ideally government or critical infrastructure. In-depth understanding of cyber risk management, threat modelling, security architectural advice, and formal IT Health Checks, including experience with SaaS environments and cloud security principles. Experience interpreting and applying relevant cyber security standards, regulatory frameworks, and secure by design principles within a multi-disciplinary digital team. Track record of building cross-functional relationships and leading multi-platform security initiatives, with the ability to brief, influence, and advise senior stakeholders. Experience mentoring, coaching, or enabling capability-building in others. Ability to assess the implications and risks of emerging technologies (such as AI, SaaS, cloud services) and proactively recommend security interventions. Also to possess experience in any of the below: Artificial intelligence Large language models Mobile Applications Security Principles Secure by Design Knowledge of secure by design CISP qualifications CAF Assessment knowledge Mobile application knowledge OWASP knowledge DPIA Govassure Certes IT Service Solutions welcome applications from all sections of the community and from people with diverse experience and backgrounds To apply for this role please email your CV to Joanne Stanley: Certes Computing (and all of its subsidiary companies) is committed to promoting equality and diversity in its business operations. TPBN1_UKTJ