FluidOne
Principal Cyber Security Consultant

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
CSA Cyber, established in 2013, provides cyber consultancy and managed services designed to detect, protect, and educate against modern cyber threats.
The Offensive Security division, established in 2006, predates the company and has played a major role in operationalising penetration testing output within the UK market, acting as early adopters of a platform-based customer experience.
CSA is backed by FluidOne, a market leading connected cloud solutions provider, who provide support and funding firepower for our ambitious growth plans. Our vision is to be the best quality UK cyber security managed service provider.
Our mission is to grow to over £30m revenue over the next 5 years adding to our reputation as the go to experts in our field and providing a full range of cyber services to our clients enabling them to focus on running their businesses.
CSA’s extensive service offering helps businesses understand the cyber threat and the measures they need to put in place to be more cyber secure.
Role Overview:
The Principal Consultant is a senior, CHECK Team Leader-accredited role responsible for leading and taking overall technical and quality responsibility for CHECK-accredited penetration testing engagements, with particular emphasis on Operational Technology (OT), Industrial Control Systems (ICS), and SCADA environments. Reporting to the Penetration Testing Team Lead, the Principal Consultant plans and leads engagement delivery, directs and mentors CHECK Team Members, and acts as the senior technical authority and primary client point of contact for complex or high-risk engagements. The role combines hands-on OT/IT convergence testing expertise with engagement leadership, quality assurance, and client relationship management, and is expected to represent CSA Cyber’s offensive security capability at a senior level, both internally and externally.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Requirements:
- Current CHECK Team Leader status, experience leading CHECK-accredited penetration testing engagements.
- Substantial hands-on experience testing Operational Technology, ICS, or SCADA environments, alongside traditional IT infrastructure, web application, cloud, or mobile testing.
- Proven ability to lead engagement teams, manage client relationships at a senior level, and take overall accountability for technical quality and delivery risk.
- Strong understanding of OT/ICS architectures, the Purdue Model, and the operational and safety constraints of testing live industrial environments.
- Excellent client communication and stakeholder management skills, with the ability to present findings and risk to senior technical and non-technical audiences, including executives.
- Track record producing and quality-assuring written security reports and technical documentation to a clear, consistent, and defensible standard.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Technical Requirements:
- Expert-level proficiency across two or more of the following areas:
- Operational Technology, ICS, and SCADA security assessment (e.g. Modbus, DNP3, BACnet, OPC-UA, Profinet)
- Internal and external IT infrastructure testing
- Cloud security assessment concepts, particularly Azure and/or AWS
- Familiarity with IEC 62443, NIST SP 800-82, and other OT/ICS security standards, and how they map to client risk and compliance requirements.
- Deep working knowledge of relevant frameworks and testing standards such as OWASP, MITRE ATT&CK for ICS, NCSC CHECK scheme methodology, CREST, or equivalent industry guidance.
- Ability to lead complex evidence capture, exploitation, vulnerability validation, and root-cause analysis, including in safety-critical or availability-sensitive environments.
Other Requirements:
- Strong commitment to operational security and good testing hygiene.
- Eligible for SC
- Right to work in the UK.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location