Principal Cyber Security Risk & Audit Consultant at an IT Services Consultancy partnering with public and private sectors. Driving cyber security audits and risk management frameworks for operational resilience.
Responsibilities
Methods is a £100M+ IT Services Consultancy who has partnered with a range of central government departments and agencies to transform the way the public sector operates in the UK.
Established over 30 years ago and UK-based, we apply our skills in transformation, delivery, and collaboration from across the Methods Group, to create end-to-end business and technical solutions that are people-centred, safe, and designed for the future.
Our human touch sets us apart from other consultancies, system integrators and software houses - with people, technology, and data at the heart of who we are, we believe in creating value and sustainability through everything we do for our clients, staff, communities, and the planet.
We support our clients in the success of their projects while working collaboratively to share skill sets and solve problems.
At Methods we have fun while working hard; we are not afraid of making mistakes and learning from them.
Predominantly focused on the public-sector, Methods is now building a significant private sector client portfolio.
We are seeking a Principal Cyber Security Risk & Audit Consultant to join our growing team. This role is ideal for a professional with a strong background in cyber security, risk management, and internal audit.
Requirements
Lead and execute cyber security audits, ensuring compliance with regulatory and industry standards.
Develop and maintain risk management frameworks, aligning with best practices such as ISO 27001, NIST, and GDPR.
Collaborate with stakeholders to identify and mitigate cyber risks across digital and operational infrastructures.
Provide expert guidance on cyber risk governance, resilience, and assurance strategies.
Assess third-party risk management practices and conduct security audits on suppliers and partners.
Work closely with CISOs, IT, and compliance teams to drive a proactive security culture.
Report findings and recommendations to senior leadership, ensuring risk mitigation strategies are effectively implemented.
Candidates must have one of the following qualifications or be willing to work towards them:
ChCSP in the Audit and Assurance (specialism) – Chartered status with the UK Cyber Security Council (CSC)
PriCSP in the Audit and Assurance (specialism) – Principal level with the CSC, with a commitment to attaining Chartered status
CMIIA – Chartered Member of the Institute of Internal Auditors, with willingness to work towards ChCSP
CISA – ISACA Certified Information Systems Auditor, with willingness to work towards ChCSP
QiCA – Institute of Internal Auditors Qualification in Computer Auditing, with willingness to work towards ChCSP
Additional professional certifications of interest include:
IRM Chartered Risk Manager certification
ISACA certifications such as CISM, CRISC, CGEIT
CISSP (Certified Information Systems Security Professional)
Proven experience in cyber security risk management and audit, ideally within regulated industries
Strong knowledge of security frameworks, including ISO 27001, NIST, CIS Controls, and GDPR compliance
Ability to conduct security assessments, risk analyses, and internal audits
Familiarity with security tooling and governance platforms (e.g., SIEM, GRC platforms)
Excellent communication skills with the ability to influence senior stakeholders
A proactive mindset with the ability to work independently and as part of a team
Benefits
Autonomy to develop and grow your skills and experience
Be part of exciting project work that is making a difference in society
Strong, inspiring and thought-provoking leadership
A supportive and collaborative environment
access to LinkedIn Learning, a management development programme, and training
24/7 confidential employee assistance programme
including home working and part time
office parties, breakfast Tuesdays, monthly pizza Thursdays, Thirsty Thursdays, and commitment to charitable causes
25 days of annual leave a year, plus bank holidays, with the option to buy 5 extra days each year
2 paid days per year to volunteer in our local communities or within a charity organisation
Salary Exchange Scheme with 4% employer contribution and 5% employee contribution
based on company and individual performance
of 4 times base salary
which is non-contributory (spouse and dependants included)
which is non-contributory (spouse and dependants included)
Certified Mobility Consultant managing sales and customer relationships for MobilityWork. Influencing market presence and adapting offerings by understanding competition.
Senior Transformation Consultant driving project performance for Highmark Health. Engaging with clients to enhance business operations across healthcare sectors.
Enterprise Change Management Consultant at Elevance Health overseeing change management for business initiatives. Collaborating across teams to ensure user adoption and effective transformation strategies.
New Patient Consultant assisting families to initiate their fertility journey at CCRM. Acting as a liaison between patients and healthcare providers during the onboarding process.
Consultant(e) en stratégie et transformation chez Stanwell. Développement d'écosystèmes de start - ups et accompagnement des transformations stratégiques des entreprises.
Client Relationship Consultant engaging with customers to provide financial counsel and support. Building relationships through communication and understanding banking needs to foster client trust.
Building Consultant managing domestic and commercial subsidence claims in London/Southeast. Role involves diagnosis, mitigation, and effective repair techniques as part of the Subsidence Services Division.
Consultant helping public sector clients achieve financial goals through Euna Budget Pro software solutions. Engage in various client projects centered on business process optimization and implementation.
Senior Solution Consultant driving consultative prospect engagements in the legal sector. Responsible for technical evaluations and solutions with enterprise software platforms.
Consultant responsible for implementing ERP solutions at Proalpha for medical technology clients. Analyzing processes and optimizing business models, with flexible working options.