Principal Cyber Risk Management & Assurance Advisor
Rate: Up to £750 per day - Inside IR35
Contract: 6 months
Location: London, Bristol or Manchester
Hybrid: 3 days onsite preferred
Clearance: Active SC Clearance essential
Client: Government Client
We are looking for an experienced Principal Cyber Risk Management & Assurance Advisor to join a major Government Client, supporting complex digital, cloud and technology transformation programmes.
This is a senior-level opportunity requiring someone with strong, practical cyber security risk management experience who can lead risk assessments, provide security assurance and influence key stakeholders across complex technical environments.
Key Responsibilities
Lead cyber and information security risk assessments and assurance across major digital services.
Produce formal risk assessments and risk treatment plans, ensuring risks and controls align with business risk appetite.
Provide assurance across cloud and SaaS environments, including compliance against NCSC Cloud Security Principles.
Support and promote Secure by Design practices across digital delivery.
Provide security architectural advice and support technical and business decision-making.
Engage with senior technical and business stakeholders, presenting risks and recommending appropriate mitigations and controls.
Support security governance, assurance reviews and risk management activities.
Mentor and advise digital teams, helping to strengthen cyber risk capability. Essential Skills & Experience
Strong experience delivering cyber security risk assessments and assurance within large, complex digital environments.
Excellent knowledge of cyber risk management, threat modelling and security architecture.
Strong cloud security experience, ideally including AWS, SaaS environments and cloud governance.
Experience applying cyber security standards, regulatory frameworks and Secure by Design principles.
Proven ability to assess risks, recommend controls and demonstrate tangible security outcomes.
Excellent stakeholder management skills with the ability to influence and advise senior stakeholders.
Strong communication skills, with the ability to translate complex security risks into clear, actionable recommendations.
Experience working within Government, critical infrastructure, financial services or another regulated environment would be advantageous