Security Engineering Consultant

Company: NCC Group
Apply for the Security Engineering Consultant
Location: Cheltenham
Job Description:

Overview

Role: Security Engineering Consultant

Location: Manchester, Cheltenham, London – Hybrid

We are hiring for a Security Engineering consultancy role focused on assisting clients with Security Improvement, Remediation and Transformation programmes. The role involves assessing client security needs, delivering technical security improvements, and guiding design and implementation of cyber controls. The C&I Security Engineering practice works with NCC Group clients to deliver prioritised programs of security improvements in collaboration with security audit, Incident Response, Penetration and Red Teams.

Key Responsibilities

  • Acting as a technical cyber authority for clients.
  • Ensuring that a client security posture is materially improved over the engagement.
  • Assessing pre-existing risk and security information (incidents, red team findings, penetration tests, security audits) and augmenting with additional security reviews where appropriate.
  • Providing technical input for work plans and project costings; contributing to prioritisation and planning throughout a project.
  • Creating technical content for project documents.
  • Collaborating with project managers on project status, resource allocation and project risk (preferably using Agile approaches).
  • Working closely with NCC Group colleagues, client and third-party technical staff to deliver prioritised improvements at pace, including hands-on delivery where required.
  • Reviewing improvements delivered to ensure they achieve the expected risk mitigations.
  • Engaging with appropriate resources to ensure all relevant factors are considered and addressed.
  • Championing the Security Engineering practice across NCC Group and acting as a conduit to additional NCC services as needed by a client.

Skills, Knowledge and Expertise

Minimum Requirements

  • Clear knowledge of cyber security principles and the understanding of an attack chain lifecycle (not essential to come from a pure cyber security background).
  • Understanding of cyber security frameworks (e.g., NIST, CIS, MITRE).
  • Ability to interpret security reports and recommend appropriate mitigations.
  • Well-rounded knowledge of IT roles and responsibilities supporting security (network engineering, infrastructure engineering, information security management, IT compliance).
  • Knowledge of modern Windows, Active Directory, Entra ID and Microsoft 365.
  • Knowledge of Azure, AWS, GCP basics and advantages.
  • Ability to work collaboratively with team members.
  • Clear, accurate documentation skills.

Desirable Requirements

  • Recognised expertise or qualification in IT information security management or IT compliance.
  • Experience in an Agile environment and/or service management organisation.
  • Experience with Windows, Active Directory, Entra ID (Azure AD) and Microsoft 365; Azure, AWS, GCP.
  • DevOps, CI/CD, software development and testing, Infrastructure as Code.
  • Blue team, network defence, protective monitoring engineering.
  • Cyber security qualification such as CISSP or CISM.
  • Experience to recognised standards (PCI-DSS, ISO27001, ISAE 3402 SOC) and in consultancy.
  • Agile certification.

Additional Attributes (Advantageous)

  • Technical certifications in relevant technologies.
  • Cyber security qualification such as CEH.
  • Knowledge of MITRE ATT&CK and mapping to key controls in other frameworks.
  • Experience in solution architecture and design.
  • Agile certification.

Behaviours

  • Client-Focused: Prioritises client needs and drives satisfaction and success.
  • Collaborates as “One NCC”: Works with all departments to achieve shared objectives.
  • Adds Value: Goes beyond minimum requirements to enhance customer success.
  • Enables and Empowers: Provides tools and support for the team to thrive.
  • Personal Responsibility: Owns actions and outcomes, acknowledging both successes and areas for improvement.
  • Communicates Openly and Respectfully: Shares information transparently while respecting stakeholders.
  • Open Mindset: Welcomes new ideas and adapts to feedback.
  • Growth and Development: Seeks opportunities for personal and organisational growth.
  • Analytical Thinking: Uses a systematic approach to resolve issues.

Benefits

  • Flexible working options.
  • Generous holiday allowance: 25 days plus bank holidays, with option to buy up to 5 additional days.
  • Medicash & Critical Illness Scheme.
  • Pension, Life Assurance, and Share Save Scheme.
  • Community & Volunteering programmes.
  • Green Car Scheme and Cycle to Work.
  • Special Time Off for personal milestones and family planning support.

#J-18808-Ljbffr…

Posted: April 17th, 2026