Skip to main content
AfterDuty

Cyber Security Consultant - Inside IR35 - SC

Sanderson Government & Defence · London, Greater London

Salary
£550 – £600 a dayEstimated
Type
Contract
Posted
9 days ago

Overview

Your incident command and multi-agency coordination experience directly supports governing supplier security incident processes.

About this role

Role Title: Cyber Security Consultant - Incident and Vulnerability Management

*Clearance:*SC Cleared

*Length:*Initial contract to 30/11/2026

Pay rate: 581.75-599.65£ per day, 77.56-79.95£ per hour

Status: Inside IR35

Role Summary

The Security Incident & Vulnerability Management Consultant operates within the Operational Integrator (OI) function to support the transition to a multi-supplier (SIAM) model within a Defence environment.

The role focuses on understanding, aligning and governing existing high-severity security incident management (S3/S4) and vulnerability management processes across suppliers. Ensuring a consistent, risk-based approach in line with client policy and regulatory requirements, supported by appropriate evidence.

The outcome is a coherent, evidence-driven view of security risk, covering both active incidents and underlying vulnerabilities, with processes standardised and ready for BAU handover.

This is a governance and coordination role, not a hands-on SOC, incident response, or vulnerability remediation function.

Key Responsibilities

Governance & Process Alignment

  • Review and align existing supplier processes for:

o High-severity incident management (S3/S4)

o Vulnerability management, across suppliers from existing processes

  • Ensure processes are:

o Consistent across suppliers

o Aligned to client policy and regulatory requirements

  • Establish and govern:

o Incident severity classification and escalation thresholds

o Vulnerability prioritisation approaches (e.g. CVSS, KEV, EPSS)

o Exception and risk acceptance processes

Supplier Coordination (SIAM Model)

  • Coordinate multiple suppliers to ensure consistent handling of incidents and vulnerabilities
  • Act as the integration point across suppliers, aligning outputs without redesigning underlying processes into a common model
  • Identify and manage gaps in process maturity, coverage, data quality and Compliance with standards

Incident Management (S3/S4 Focus)

  • Govern the lifecycle of high-severity incidents, including escalation, coordination, communication and reporting
  • Ensure suppliers:

o Detect and escalate incidents appropriately

o Meet defined escalation and communication expectations

o Maintain structured incident records

  • Define and agree the required level of visibility from SOC outputs, without requiring direct tooling access

Vulnerability Management (SOC-led)

  • Oversee the vulnerability lifecycle from identification through to closure
  • Ensure vulnerabilities are:

o Prioritised consistently using agreed Client approaches

o Tracked through remediation or formal risk acceptance

  • Validate, track and monitor:

o Remediation timelines and SLA adherence

o Handling of high risk vulnerabilities, exceptions and waivers

  • Identify risks relating to:

o Incomplete asset coverage

o Obsolescent, legacy or non-patchable systems

Evidence & Assurance

  • Define and align evidence requirements for both:

o Incident management (event, escalation, response, closure)

o Vulnerability management (identify, track, remediate, validate)

  • Ensure outputs are:

o Consistent across suppliers

o Traceable to risks and controls

o Audit ready

  • Provide assurance that both domains align with ISMS and control requirements

Reporting & Transition Support

  • Support domain-specific reporting for:

o Major incidents (S3/S4)

o Vulnerability risk and remediation status

  • Support governance forums with clear, evidence-based reporting
  • Establish a transition baseline that enables a clean handover of processes to BAU without redesign

Key Skills & Experience

Essential

  • Experience in security incident management, vulnerability management, or cyber governance roles
  • Strong understanding of:

o Incident management lifecycle (detect, respond, recover)

o Vulnerability lifecycle (identify, prioritise, remediate, validate)

  • Experience working in multi-supplier or SIAM environments
  • Ability to interpret outputs from SOC and vulnerability tooling without direct ownership

Desirable

  • Familiarity with NIST CSF, NCSC or UK Government security guidance
  • Experience in Defence sector or highly regulated environments
  • Exposure to audit, assurance or ISMS processes
  • ITIL alignment

Reasonable Adjustments

Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients.

If you need any help or adjustments during the recruitment process for any reason,**please let us know when you apply or talk to the recruiters directly so we can support you.*

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background

  • Police experience explicitly valued
  • Incident command & response
  • Working to legislation & regulation

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Full-time

    Your investigative mindset and evidence-handling discipline from policing transfer directly to digital forensics and incident response.

    Posted 3 days ago

  • Full-time

    £61,440 – £69,120Estimated

    Your risk assessment and analytical skills from policing transfer directly to cyber assurance.

    Posted 5 days ago

  • Director - Risk Management

    SHI International · London

    Full-time

    Your threat assessment and multi-agency command experience directly transfer to building enterprise risk frameworks and governance.

    Posted 5 days ago

  • GRC Manager - 6 month FTC

    Trayport · London

    Full-time

    Your experience managing risk, policy, and regulatory compliance under frameworks like PACE transfers directly to GRC.

    Posted 5 days ago