Experis
Cyber Security Consultant
Job Description
Salary: £? - ? per year
Requirements:- We require experience in security incident management, vulnerability management, or cyber governance roles.
- We require a strong understanding of the incident management lifecycle, including detect, respond, and recover.
- We require a strong understanding of the vulnerability lifecycle, including identify, prioritise, remediate, and validate.
- We require experience working in multi-supplier or SIAM environments.
- We require the ability to interpret outputs from SOC and vulnerability tooling without direct ownership.
- We prefer familiarity with NIST CSF, NCSC, or UK Government security guidance.
- We prefer experience in the Defence sector or other highly regulated environments.
- We prefer exposure to audit, assurance, or ISMS processes.
- We prefer ITIL alignment.
- We require MOD SC clearance and sole UK nationality.
- We review and align existing supplier processes for high-severity incident management and vulnerability management.
- We ensure processes are consistent across suppliers and aligned to client policy and regulatory requirements.
- We establish and govern incident severity classification, escalation thresholds, vulnerability prioritisation approaches, and exception and risk acceptance processes.
- We coordinate multiple suppliers to ensure consistent handling of incidents and vulnerabilities.
- We act as the integration point across suppliers, aligning outputs without redesigning underlying processes into a common model.
- We identify and manage gaps in process maturity, coverage, data quality, and compliance with standards.
- We govern the lifecycle of high-severity incidents, including escalation, coordination, communication, and reporting.
- We ensure suppliers detect and escalate incidents appropriately, meet escalation and communication expectations, and maintain structured incident records.
- We define and agree the required level of visibility from SOC outputs without requiring direct tooling access.
- We oversee the vulnerability lifecycle from identification through to closure.
- We ensure vulnerabilities are prioritised consistently using agreed client approaches and tracked through remediation or formal risk acceptance.
- We validate, track, and monitor remediation timelines, SLA adherence, and handling of high-risk vulnerabilities, exceptions, and waivers.
- We identify risks relating to incomplete asset coverage and obsolescent, legacy, or non-patchable systems.
- We define and align evidence requirements for incident and vulnerability management.
- We ensure outputs are consistent across suppliers, traceable to risks and controls, and audit ready.
- We provide assurance that both domains align with ISMS and control requirements.
- We support reporting for major incidents and vulnerability risk and remediation status.
- We support governance forums with clear, evidence-based reporting.
- We establish a transition baseline that enables a clean handover of processes to BAU without redesign.
- Incident Management
- Support
- ITIL
- Security
More:
We are offering a 30/11/2026 contract role paying up to £610 per day via umbrella. The position is hybrid, with locations in Preston, London, or Birmingham in the UK, and a working split of 30% office and 70% home. This is a Defence environment role within our Operational Integrator function, focused on governance and coordination rather than hands-on SOC, incident response, or vulnerability remediation. We are seeking a consultant to support the transition to a multi-supplier SIAM model, standardise incident and vulnerability management processes, and establish an evidence-driven baseline for BAU handover.
last updated 34 week of 2026
Interested in this role?
Submit your application now
How to Apply
About Experis
Experis
Whitehall
IT
Skills & Technologies
Inferred from job description