Consultant - Cyber Consulting Services
Indexed description
Summary: To deliver and support cyber consulting engagements for internal and external Waystone clients, including technical security assessments, cloud and Microsoft 365 reviews, vulnerability management, third-party risk, policy and governance support, client reporting, proposal development, and mentoring of junior team members.
Essential Duties And Responsibilities
- Lead and support cyber security assessments for external and internal clients, including penetration testing coordination, vulnerability assessment, cloud security review and security architecture review activities.
- Manage customer vulnerability management services, including Edgescan portal oversight, vulnerability validation, client notifications, remediation tracking and management reporting.
- Support Microsoft 365, Azure and AWS security assessments using appropriate tooling, scripts and manual review techniques, including analysis of configuration risks and control gaps.
- Carry out third-party/vendor security risk assessments using OneTrust and other approved methodologies for both Waystone and external client environments.
- Design, coordinate and report on phishing simulations and cyber awareness activities for multiple clients, including practical recommendations for user and control improvement.
- Develop and maintain client engagement materials, including reports, presentations, executive summaries, dashboards, whitepapers and technical recommendations.
- Prepare and customise cybersecurity proposals, tender responses and statements of work, ensuring scope, effort, assumptions, exclusions and delivery approach are clearly documented.
- Contribute to governance, risk and compliance activities, including ISO 27001, NIST, DORA, policy reviews, control mapping, assurance assessments and remediation plans.
- Design and facilitate tabletop, incident response and crisis management exercises, including scenario development, workshop facilitation, evidence capture and after-action reporting.
- Operate and support cyber tooling and managed service processes including Red Sift, Bolster, Edgescan, KnowBe4, OneTrust and domain impersonation monitoring services such as CyberInt.
- Support internal team development through knowledge sharing, peer review, mentoring of interns/junior colleagues, development of reusable templates and improvement of delivery methodologies.
Education
- Holds a Master's degree in Cybersecurity, Information Security, Computer Science, or an equivalent qualification.
- Possesses a minimum of three years of experience in a dedicated Cyber Consulting or Information Security role.
- Strong hands-on experience delivering cyber security assessments, design reviews and technical assurance engagements for public and private sector clients.
- Hands-on experience using the Edgescan Continuous Vulnerability Scanning tool, including triage, reporting, remediation tracking and client communications.
- Experience conducting Microsoft 365 security assessments using tools such as SCuBA, Inspect365, ORCA and PowerShell-based review scripts.
- Proficient in conducting Azure and AWS cloud security reviews using manual assessment techniques and tools such as Prowler, ScoutSuite, CloudMapper and Steampipe.
- Experience supporting penetration testing engagements across web applications, APIs, infrastructure and cloud-hosted environments.
- Strong knowledge of key cyber security standards and frameworks including NIST, ISO 27001/27002, OWASP, CIS Benchmarks and relevant regulatory expectations.
- Knowledge of the EU Digital Operational Resilience Act (DORA) and understanding of technology risk and resilience obligations for regulated financial services clients.
- Highly skilled in formulating cyber security policies, procedures, standards, executive reports and strategic proposals.
- Proven ability to create client-specific cybersecurity proposals, tender responses, scopes of work and commercial delivery assumptions.
- Strong background in designing, revising and improving internal policies, operating procedures and governance frameworks to enhance security posture.
- Demonstrated expertise in developing and implementing governance frameworks, control assessments and compliance strategies.
- Experienced in designing and executing tabletop, incident response and crisis simulation exercises for senior stakeholders.
- Hands-on experience with third-party risk management and risk assessments using the OneTrust portal or equivalent platforms.
- Hands-on experience with domain impersonation detection and monitoring tools such as OnDOMAIN, Red Sift or equivalent brand protection platforms.
- Familiarity with endpoint security solutions, email security controls, Data Loss Prevention (DLP), vulnerability remediation and cyber hygiene practices.
- Proficient in Microsoft Word, Excel and PowerPoint, with the ability to produce high-quality, client-ready reports, trackers and presentations.
- Ability to translate complex technical findings into clear business risk, practical recommendations and executive-level communications.
- Takes ownership and responsibility for own actions, performance, client delivery and continued professional development.
- Effectively manages own workflow, time and priorities with minimal oversight while supporting colleagues and mentoring junior team members.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search