Rodeo
Get started

ISR Recruitment

Cyber Security Assurance Specialist (DSPT / CAF)

United Kingdom
Posted about 19 hours ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Cyber Security Assurance and Maturity Lead Consultant for DSPT & CAF

6-month contract
Remote Working (UK)
Outside IR35
Market Rates

The Opportunity:

Our consultancy client is partnered with a major UK Government Agency and are seeking an experienced DSPT & Cyber Assessment Framework (CAF) Assurance Specialist to provide specialist assurance across a significant data security and cyber resilience programme. The organisation is currently undertaking a programme focused on compliance with the Data Security and Protection Toolkit (DSPT) and the NCSC Cyber Assessment Framework (CAF). The programme is developing proposals, controls and actions to address identified gaps.

The requirement now is for an experienced assurance professional who can independently assess whether those proposals and actions are appropriate, effective and delivering the intended improvement in organisational maturity; providing an evidence-based view of the current state, assess the effectiveness of remediation activity, identify remaining gaps and help ensure that improvement plans translate into sustainable security and data protection outcomes.

You'll be a credible assurance professional comfortable with reviewing evidence, challenging proposed solutions and determining whether controls are actually operating effectively; equally comfortable discussing cyber risk with technical specialists and presenting clear, concise assurance findings to senior programme and organisational stakeholders. Previous experience of DSPT and CAF within NHS, healthcare or Government environments is highly desirable.

Skills and Experience:

Essential

  • Significant professional experience in cyber security, information assurance, security governance, risk or compliance, with demonstrable experience assessing organisational maturity against security or data protection frameworks.
  • Practical experience working with the Data Security and Protection Toolkit (DSPT) and working with the NCSC Cyber Assessment Framework (CAF).
  • Experience undertaking assurance, audit, assessment or independent review activity within NHS, healthcare, Government or another highly regulated environment, reviewing evidence and determining whether controls and remediation activity are genuinely effective.
  • Strong understanding of cyber security governance, risk management and control frameworks.
  • Ability to translate framework requirements into practical assurance questions, evidence requirements and measurable outcomes, with strong analytical skills and the ability to identify gaps, risks, weaknesses and dependencies.
  • Excellent stakeholder management skills, including the confidence to challenge senior stakeholders constructively, producing clear assurance reports, recommendations, action plans and executive-level briefings.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Desirable

  • Experience working within the NHS, DHSC, UK Government or Government Arm's Length Bodies.
  • Previous experience acting as an independent DSPT assessor or assurance provider.
  • Experience with CAF-aligned DSPT assessments.
  • Knowledge of NHS information governance and data protection requirements.
  • Experience with ISO 27001, NIST, Cyber Essentials / Cyber Essentials Plus or similar security frameworks.
  • Experience with risk and control frameworks, audit methodologies or maturity models.
  • Experience supporting cyber transformation, remediation or organisational improvement programmes.

Role and Responsibilities:

  • Provide independent assurance across DSPT and CAF-related activities, proposals and remediation plans.
  • Assess the organisation's current maturity against relevant DSPT and CAF requirements.
  • Review existing assessments, evidence, controls, improvement plans and supporting documentation.
  • Evaluate whether proposed actions are appropriately designed to address identified risks and gaps.
  • Assess whether completed actions and controls are operating effectively and producing the intended outcomes.
  • Identify weaknesses, residual risks, dependencies and areas requiring further remediation.
  • Provide clear, evidence-based assurance findings and recommendations to senior stakeholders.
  • Challenge assumptions and proposed approaches where evidence does not demonstrate sufficient assurance.
  • Support the development and maintenance of maturity assessments, assurance plans, action plans and evidence repositories.
  • Map findings and recommendations against relevant DSPT and CAF outcomes, principles and indicators of good practice.
  • Work closely with Cyber Security, Information Governance, Data Protection, Risk, Compliance and Programme teams.
  • Support the establishment of appropriate measures and evidence to demonstrate sustainable improvement.
  • Contribute to governance forums, assurance reviews and senior-level reporting.
  • Help ensure that improvements are embedded into business-as-usual processes rather than treated solely as point-in-time compliance activity.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

NB: The successful candidate will be required to undergo a basic level of security clearance before undertaking the assignment (one to two weeks’ lead-time).

Applications:

To learn more about this newly created opportunity consulting as a Cyber Security Assurance and Maturity Lead Consultant for an initial 6-month temporary engagement, operating on a remote-working basis; please call and speak with Edward Laing here at ISR Recruitment on 07436 071 872 or please send through a copy of your latest online profile and/or CV (edward@isr.uk.com) for an immediate call back in the strictest confidence.

If you have substantial hands-on experience in DSPT and CAF Assurance and can provide an independent view of organisational maturity, control effectiveness and remediation progress; please contact Edward here at ISR to learn more about our client and how they are leading the way in developing the next generation of technical solutions through innovation and transformational technology.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Cyber Security Assurance
DSPT
NCSC Cyber Assessment Framework
Information Assurance
Security Governance
Risk Management
Compliance
Audit
Stakeholder Management
Gap Analysis
Remediation Planning
Data Protection
ISO 27001
NIST
Cyber Essentials
Maturity Assessment

Location

United Kingdom

Sign up to applySee more jobs like this