Waystone
Consultant - Cyber Consulting Services

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Waystone
Waystone is a leading asset-servicing solutions provider of institutional governance, administration, risk and compliance services to financial institutions. With over 25 years’ experience and a comprehensive range of specialist services to its name, Waystone helps our clients structure, operate and grow through our expertise, innovation and digitisation, backed by the operational scale to support global expansion.
Summary
To deliver and support cyber consulting engagements for internal and external Waystone clients, including technical security assessments, cloud and Microsoft 365 reviews, vulnerability management, third-party risk, policy and governance support, client reporting, proposal development, and mentoring of junior team members.
Essential Duties and Responsibilities
- Lead and support cyber security assessments for external and internal clients, including penetration testing coordination, vulnerability assessment, cloud security review and security architecture review activities.
- Manage customer vulnerability management services, including Edgescan portal oversight, vulnerability validation, client notifications, remediation tracking and management reporting.
- Support Microsoft 365, Azure and AWS security assessments using appropriate tooling, scripts and manual review techniques, including analysis of configuration risks and control gaps.
- Carry out third-party/vendor security risk assessments using OneTrust and other approved methodologies for both Waystone and external client environments.
- Design, coordinate and report on phishing simulations and cyber awareness activities for multiple clients, including practical recommendations for user and control improvement.
- Develop and maintain client engagement materials, including reports, presentations, executive summaries, dashboards, whitepapers and technical recommendations.
- Prepare and customise cybersecurity proposals, tender responses and statements of work, ensuring scope, effort, assumptions, exclusions and delivery approach are clearly documented.
- Contribute to governance, risk and compliance activities, including ISO 27001, NIST, DORA, policy reviews, control mapping, assurance assessments and remediation plans.
- Design and facilitate tabletop, incident response and crisis management exercises, including scenario development, workshop facilitation, evidence capture and after-action reporting.
- Operate and support cyber tooling and managed service processes including Red Sift, Bolster, Edgescan, KnowBe4, OneTrust and domain impersonation monitoring services such as CyberInt.
- Support internal team development through knowledge sharing, peer review, mentoring of interns/junior colleagues, development of reusable templates and improvement of delivery methodologies.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Requirements


Get help with your application
Your very own career expert that helps elevate your application to the next level.
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below represent the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Education
- Holds a Master's degree in Cybersecurity, Information Security, Computer Science, or an equivalent qualification.
Experience
- Possesses a minimum of three years of experience in a dedicated Cyber Consulting or Information Security role.
- Strong hands-on experience delivering cyber security assessments, design reviews and technical assurance engagements for public and private sector clients.
- Hands-on experience using the Edgescan Continuous Vulnerability Scanning tool, including triage, reporting, remediation tracking and client communications.
- Experience conducting Microsoft 365 security assessments using tools such as SCuBA, Inspect365, ORCA and PowerShell-based review scripts.
- Proficient in conducting Azure and AWS cloud security reviews using manual assessment techniques and tools such as Prowler, ScoutSuite, CloudMapper and Steampipe.
- Experience supporting penetration testing engagements across web applications, APIs, infrastructure and cloud-hosted environments.
- Strong knowledge of key cyber security standards and frameworks including NIST, ISO 27001/27002, OWASP, CIS Benchmarks and relevant regulatory expectations.
- Knowledge of the EU Digital Operational Resilience Act (DORA) and understanding of technology risk and resilience obligations for regulated financial services clients.
- Highly skilled in formulating cyber security policies, procedures, standards, executive reports and strategic proposals.
- Proven ability to create client-specific cybersecurity proposals, tender responses, scopes of work and commercial delivery assumptions.
- Strong background in designing, revising and improving internal policies, operating procedures and governance frameworks to enhance security posture.
- Demonstrated expertise in developing and implementing governance frameworks, control assessments and compliance strategies.
- Experienced in designing and executing tabletop, incident response and crisis simulation exercises for senior stakeholders.
- Hands-on experience with third-party risk management and risk assessments using the OneTrust portal or equivalent platforms.
- Hands-on experience with domain impersonation detection and monitoring tools such as OnDOMAIN, Red Sift or equivalent brand protection platforms.
- Familiarity with endpoint security solutions, email security controls, Data Loss Prevention (DLP), vulnerability remediation and cyber hygiene practices.
- Proficient in Microsoft Word, Excel and PowerPoint, with the ability to produce high-quality, client-ready reports, trackers and presentations.
- Ability to translate complex technical findings into clear business risk, practical recommendations and executive-level communications.
- Takes ownership and responsibility for own actions, performance, client delivery and continued professional development.
- Effectively manages own workflow, time and priorities with minimal oversight while supporting colleagues and mentoring junior team members.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location