About the Role
This client-facing consulting role focuses on enhancing cyber security capabilities across people, process, and technology. You will collaborate with senior stakeholders and technical teams to assess current capabilities, identify improvement areas, and design practical solutions for Vulnerability Management and Security Operations, primarily within modern cloud and enterprise IT environments.
Responsibilities
- Lead discovery activities to understand current Vulnerability Management and Security Operations capabilities.
- Assess existing processes, procedures, and policies, identifying opportunities to improve operational effectiveness and cyber resilience.
- Review and enhance Vulnerability Management operating models, governance, and day-to-day operational processes.
- Review and improve Security Operations (SOC) processes, procedures, policies, and operational workflows.
- Design practical, scalable improvements that align with client objectives and existing technologies.
- Lead the design and implementation of strategic improvements, influencing stakeholders and driving the successful adoption of new operating models, processes, and controls.
- Establish and maintain trusted advisor relationships with technical, operational, and executive stakeholders, providing authoritative guidance and influencing decision-making.
- Lead workshops, planning sessions, and design activities with operational teams and executive stakeholders, shaping strategy and securing alignment on transformation initiatives.
- Provide leadership, mentoring, and quality assurance across consulting workstreams, taking accountability for successful delivery and junior consultant development.
- Take ownership of reporting, delivery governance, and risk management activities, ensuring stakeholders are informed and business objectives align with delivery outcomes.
- Work across complex hybrid technology environments including cloud platforms, enterprise infrastructure, and modern digital services.
Requirements
- Significant experience delivering Vulnerability Management improvements from process, procedure, and policy perspectives.
- Significant experience delivering Vulnerability Management improvements from operational delivery and implementation.
- Experience improving Security Operations (SOC) capabilities, including operating models, processes, procedures, governance, policy, and operational effectiveness.
- Previous consulting experience across multiple clients or organisations.
- Exceptional stakeholder management and influencing skills, with experience advising and challenging technical teams, operational security functions, senior leadership, and executive stakeholders.
- Experience leading discovery and assessment engagements, translating findings into strategic roadmaps, business cases, and prioritised improvement plans.
- Strong planning, facilitation, and organisational skills.
- Experience working within complex cloud and enterprise IT environments.
- Ability to operate at both strategic and tactical levels, taking ownership of outcomes while providing authoritative advice and direction.
- Excellent written, verbal, and presentation skills.
- Experience within UK Government or other highly regulated environments (Desirable).
- Knowledge of Microsoft Defender Vulnerability Management, Qualys, Tenable, or Rapid7 (Desirable).
- Experience with Microsoft Sentinel or similar Security Operations platforms (Desirable).
- Familiarity with security frameworks such as NCSC Cyber Assessment Framework (CAF), NIST Cybersecurity Framework, CIS Controls, or ISO/IEC 27001 (Desirable).
- Must have or be willing to undergo Security Clearance.
- Must be able to complete a Baseline Personnel Security Standard.
Skills
- Vulnerability Management
- Security Operations (SOC)
- Stakeholder Management
- Influencing
- Discovery and Assessment
- Strategic Roadmaps
- Business Cases
- Improvement Plans
- Planning
- Facilitation
- Organisation
- Cloud Environments
- Enterprise IT Environments
- Strategic Thinking
- Tactical Thinking
- Written Communication
- Verbal Communication
- Presentation Skills
- Microsoft Defender Vulnerability Management (Desirable)
- Qualys (Desirable)
- Tenable (Desirable)
- Rapid7 (Desirable)
- Microsoft Sentinel (Desirable)
- NCSC Cyber Assessment Framework (CAF) (Desirable)
- NIST Cybersecurity Framework (Desirable)
- CIS Controls (Desirable)
- ISO/IEC 27001 (Desirable)
Location
- UK
Work Type
- Client-facing
- Consulting
- Hybrid Working
- Home Working
- Part Time
Experience Level
- Senior
- Consulting
Benefits
- Autonomy to develop and grow skills and experience
- Part of exciting project work making a difference in society
- Strong, inspiring, and thought-provoking leadership
- Supportive and collaborative environment
- Development opportunities including LinkedIn Learning, management development programme, and training
- 24/7 confidential employee assistance programme
- Flexible working options including home working and part time
- Social events
- Commitment to charitable causes
- 25 days of annual leave plus bank holidays
- Option to buy 10 extra days of leave annually
- 2 paid days per year for volunteering
- Salary Exchange Scheme pension with 4% employer contribution and 5% employee contribution
- Life Assurance of 4 times base salary
- Non-contributory Private Medical Insurance (spouse and dependants included)
- Non-contributory Worldwide Travel Insurance (spouse and dependants included)
- Enhanced Maternity and Paternity Pay
- Season ticket loan
- Cycle to work scheme
About the Company
- Established in 1990, Methods partners with UK central government departments and agencies to transform public sector operations.
- Their mission is to improve and safeguard public-facing services by applying digital thinking with a citizen-centric approach.
- Methods differentiates itself through a human touch and a customer-centric value system, focusing on delivering what is right for clients.
- They are experts in delivering secure, resilient cyber and information services, helping reduce risk and vulnerabilities from cyber-attacks.
- They help organisations improve processes such as threat management by building identity management programmes and establishing prevention, detection, and response capabilities.
