This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Cyber Security Consultant - Third-Party Auditor - £500-£550 per day - Inside IR35 - Hybrid working from a site in Gloucester with regular national travel to supplier sites required. Candidates must be eligible to obtain SC clearance. Our client, one of the UK’s largest zero-carbon energy producers, is seeking an experienced Cyber Security Third-Party Auditor to join the Nuclear Services Information Security team. This is a hands-on audit role focused on delivering structured, end-to-end third-party security audits in a highly regulated nuclear environment. The successful candidate will be able to demonstrate clear, practical experience in planning audits, testing controls, validating evidence, forming defensible conclusions, and producing formal audit reports.
Job Responsibility:
Plan and scope third-party audits based on risk, regulatory requirements and contractual obligations
Conduct audit walkthroughs and structured control interviews
Test design and operating effectiveness of security controls
Perform sampling and traceability testing across processes and systems
Obtain, validate and challenge audit evidence (e.g. logs, system extracts, configurations, tickets, approvals)
Assess compliance against ISO27001, ISO27017, GDPR, Cyber Essentials Plus and relevant sector frameworks
Identify control weaknesses and determine root causes
Form clear, risk-rated findings with practical recommendations
Produce structured audit reports suitable for senior governance review and regulatory scrutiny
Track and verify remediation actions through to closure
Conduct onboarding and periodic supplier cyber security audits
Evaluate supplier control environments handling nuclear information
Provide defensible assurance statements to internal governance boards
Escalate material risks and recommend approval, conditional approval, or rejection of suppliers
Support regulatory inspections and provide audit evidence where required
Maintain complete audit documentation and audit trail records
Contribute to continuous improvement of audit methodology and assurance practices
Requirements:
Practical working knowledge of international standards and information security frameworks (ISO27001, ISO27017, GDPR, Cyber Essentials Plus), including auditing control design and operating effectiveness against these frameworks
Proven experience conducting end-to-end audits or formal assurance reviews within a regulated environment (planning, walkthroughs, control testing, evidence validation, reporting and follow-up)
Experience assessing third-party or supplier environments
Understanding of HMG Security Policy Framework and NCSC/CPNI guidance and how to test compliance through audit evidence
Awareness of information security threats, risks and common control failures
Experience applying risk assessment methodologies (ISO27005, NIST, IRAM2) to support audit scoping and risk-rating of findings
Strong documentation and report writing skills - able to produce structured audit reports containing observations, root cause analysis and defensible conclusions
Ability to challenge stakeholders constructively and obtain sufficient appropriate audit evidence
Excellent written and verbal communication skills
Strong analytical mindset, professional scepticism, attention to detail and persistence
Candidates must be eligible to obtain SC clearance