Rodeo
Get started

55 Exec Search

Principal Consultant — Cyber Security, vCISO & Complex GRC

England
£90k – £100k/yr
Posted 1 day ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Principal Consultant — Cyber Security, vCISO & Complex GRC

We’re looking for an experienced Principal Consultant to lead cyber security advisory engagements across the private sector and Critical National Infrastructure (CNI).

This is a senior consulting role for someone who can connect business strategy, regulatory obligations and technical security and translate that understanding into practical advice.

You’ll work with boards, executive teams, security leaders and technology specialists to strengthen cyber resilience in complex organisations.

What you’ll do

Lead vCISO and strategic advisory engagements

  • Act as a trusted adviser to senior leadership, defining security strategies, operating models and prioritised improvement roadmaps.
  • Establish governance, accountability, risk appetite and meaningful board reporting.
  • Guide investment decisions, balancing security, resilience and commercial objectives.
  • Support leadership through security transformation, organisational change and evolving regulatory expectations.

Deliver complex GRC programmes

  • Design and improve governance, risk and assurance frameworks across multiple business units, jurisdictions and technology environments.
  • Integrate cyber risk into enterprise risk management through clear risk scenarios, proportionate assessments and defensible treatment decisions.
  • Translate applicable regulatory, contractual and customer requirements into controls, ownership and evidence.
  • Develop control frameworks that map overlapping obligations, reduce duplication and support consistent assurance.
  • Lead maturity assessments, audit readiness, control effectiveness reviews and remediation programmes.
  • Address third-party and supply-chain risk, policy frameworks, exceptions management and ongoing compliance monitoring.
  • Work across frameworks such as ISO/IEC 27001 and 27002, NIST CSF, NCSC CAF and relevant sector requirements.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Advise private-sector and CNI clients

  • Deliver advice tailored to complex, regulated and operationally critical organisations.
  • Help clients understand their critical services, dependencies and cyber risks.
  • Develop proportionate security and resilience programmes aligned with business priorities and sector expectations.
  • Connect governance and assurance findings with security architecture, technical controls and measurable improvements.
  • Support incident preparedness, business continuity and crisis management planning.

Shape and grow the consultancy

  • Own engagements from discovery and proposal through delivery and executive presentation.
  • Produce clear, evidence-based recommendations tailored to each client’s circumstances.
  • Build lasting client relationships and contribute to proposals and service development.
  • Mentor consultants and maintain high standards of delivery and professional judgement.

What we’re looking for

  • A strong track record in private-sector cyber security consulting, including complex or regulated environments.
  • Experience leading vCISO, security transformation or substantial GRC advisory engagements.
  • Experience working with CNI organisations or services with demanding security and resilience requirements.
  • Aviation industry experience is desirable, particularly in cyber security governance, risk, assurance or resilience across airlines, airports or the wider aviation supply chain.
  • The ability to assess technical evidence, challenge assumptions and communicate risk clearly to senior decision-makers.
  • Commercial awareness, strong engagement management and confidence working with executives and technical specialists.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Professional recognition

We’re particularly interested in candidates who hold UK Cyber Security Council Chartered Cyber Security Professional (ChCSP) status in one or more of these specialisms:

  • Cyber Security Audit and Assurance
  • Cyber Security Governance & Risk Management
  • Secure Systems Architecture & Design

Depth in one specialism, supported by experience across the others, would be valuable.

We also welcome candidates with relevant professional accreditations, including CIISec Full Membership (MCIIS), who can demonstrate progress towards Chartered registration.

Your expertise will help strengthen our consulting capability and support our ambition to meet the requirements of the NCSC Assured Cyber Security Consultancy (ACSC) scheme.

Interested? Send us a direct message with your CV to discuss this confidentially.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

England, United Kingdom

Sign up to applySee more jobs like this