We're looking for a senior consultant to guide cyber controls across software projects and coordinate evidence. You’ll assess application changes, challenge control measures, and help teams meet ISO 27001 and NIST requirements.
What you'll do:
- Build control requirements into projects from the design stage.
- Review application control forms with delivery teams.
- Assess changes and support release go/no-go decisions.
- Collect control evidence from subject matter experts.
- Submit evidence and agree acceptance criteria with reviewers.
- Report control progress and raise issues to IT management.
What you bring:
- Five years of relevant experience in IT production, networks, or technical or functional roles.
- Software development experience and a good understanding of activities.
- Good understanding of NIST and ISO 27001 frameworks.
- Knowledge of network protection and IT risk assessment and management.
- or at C1, and at B2.
- A ’s or , plus relevant experience.
- ISO 27001 or equivalent certification.
- Autonomy, clear communication, sound analysis, and collaborative working.
Nice to have:
- knowledge, including n-tier and client-server.
- Experience applying cyber controls in projects.
What's next?
The people who do well here are the ones who saw themselves in this description. Not because they match every line, but because the mission felt right for them.
We are actively hiring for this position. Applications are reviewed by our team, and matching profiles receive a call to discuss the role in detail.
It takes under a minute to apply. Your email, your CV. That is all we need to start the conversation.

