Cyber and Information Assurance Consultant
Listed on 2026-08-16
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant
Cyber and Information Assurance Consultant
Job Title Cyber and Information Assurance Consultant
Hours Per Week 37
Reporting to
Reporting to Principal Cyber Consultant / Head of Services
Location
Location Remote-first, with attendance at Nexor’s Nottingham office and customer locations as required. Regular UK travel may form part of the role. Occasional international travel may arise.
Role PurposeThe Cyber and Information Assurance Consultant supports customers in identifying, assessing and managing cyber security and information assurance risks across complex digital, operational and high‑assurance environments. The role combines consultancy, risk assessment, security assurance, governance and stakeholder engagement. Work may span secure information exchange, cross-domain solutions, cloud services, networks, applications, data platforms and operational systems.
The postholder translates security obligations, business needs, threat information and technical evidence into clear risk‑based recommendations. The role suits a cyber security, risk, assurance or systems professional seeking broader customer‑facing responsibility across defence, government and critical national infrastructure.
Key ResponsibilitiesConduct cyber security and information assurance risk assessments.
Identify threats, vulnerabilities, impacts and control requirements.
Develop proportionate risk treatment recommendations.
Maintain cyber risk registers, assumptions, dependencies and residual risk positions.
Support formal risk acceptance and escalation activity.
Provide clear advice to technical and non-technical stakeholders.
Information Assurance
Support assurance of systems, services and information‑handling arrangements.
Assess compliance against customer, contractual and regulatory requirements.
Review security documentation, technical evidence and control implementation.
Support security case development and assurance planning.
Contribute to accreditation, authorisation and approval activity.
Maintain traceability between requirements, controls, evidence and risk decisions.
Security Governance
Support development and maintenance of:
Security policies.
Standards.
Procedures.
Governance frameworks.
Assurance plans.
Security management plans.
Additionally:
Contribute to security governance forums and assurance boards.
Track security actions, risks, decisions and evidence.
Support senior ownership and oversight of cyber security risk.
Secure‑by‑Design Support
Work with architects, engineers and delivery teams to embed security throughout the lifecycle.
Review solution designs for security, privacy, resilience and assurance implications.
Support identification of security requirements and non‑functional requirements.
Apply defence‑in‑depth, least‑privilege and Zero Trust principles.
Ensure security considerations form part of design, build, test, deployment and operation.
Threat and Vulnerability Assessment
Assess credible threat scenarios relevant to customer environments.
Review vulnerability information and technical findings.
Support interpretation of penetration test, vulnerability scan and security assessment outputs.
Evaluate exploitability, business impact and operational consequence.
Recommend remediation priorities and compensating controls.
Work with:
Customer security teams.
Solution and Security Architects.
Project and Delivery Managers.
Software and Platform Engineers.
Product Teams.
Suppliers and Technology Partners.
Additionally:
Participate in workshops, assurance reviews and customer briefings.
Explain cyber security risks and control recommendations in accessible language.
Build trusted and professional customer relationships.
Continuous Improvement and Professional Development
Maintain awareness of emerging cyber threats, regulation and assurance practice.
Contribute to internal methods, templates and guidance.
Share knowledge across Nexor communities of practice.
Support lessons identified and service improvement activity.
Work towards recognised cyber security and assurance qualifications.
Professional experience in cyber security, information assurance, risk management, systems engineering or a related discipline.
Experience contributing to security…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: