NexGen Associates
Risk & Governance Consultant

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Risk & Governance Consultant
Salary: £50,000 - £60,000 depending on level of experience
Location: Cheltenham (Hybrid)
You must have a minimum of SC clearance to be eligible for this role.
NexGen Associates is working with a leading technical defence consultancy. Our client is looking to take on a Service Leaver or Veteran to fill their Risk & Governance Consultant role. They are a veteran-friendly company and will support and guide you through your transitioning process.
Main Responsibilities:
The successful candidate will be a knowledgeable, enthusiastic, and conscientious individual who has the relevant qualifications, certifications, and experience in line with the level of consultant you are applying for. You will work on a range of client-facing projects, large and small, but will also be expected to contribute to winning new business and managing delivery. To be successful in this role, you need to have the ability to work on multiple projects and with many stakeholders concurrently. Your key responsibilities will encompass the following:
- Provide security advice and guidance for clients in ‘business as usual’, technical refresh, and new project environments.
- Identify and establish good security governance to meet client business requirements.
- Identify client risks within client operational environments and determine appropriate remediation based on business risk appetite that protects information assets from loss, misuse, leakage, or corruption.
- Perform compliance activity on client systems and business processes to assess the levels of CS&IA controls and identify gaps to address.
- Create or review client policies and procedures to meet corporate and regulatory requirements.
- Build successful working relationships with team members, key customers, and stakeholders that improves the value of the services being performed.
- Work in partnership with clients to implement controls in pragmatic ways that deliver investment value and support business operations.
- Mentor others within the team in a technical and consultancy capacity.
- Proactively assist the Head of Services in the strategy and growth of the BU.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
The Ideal Candidate:
The ideal candidate will meet the majority or all of the following (in line with the level of consultant you are applying for):
- Willingness to frequently work at secure government facilities (minimum 3 days/week for periods of time).
- Experience of delivering technical Risk & Governance consultancy within a Defence environment, or other UK Government sectors.
- Ability to provide technical assurance, risk management, and solutions within complex scenarios.
- Ability to conduct, deliver, and maintain technical security risk assessments using established or novel approaches.
- Excellent verbal and written communication skills.
- High proficiency in all Microsoft Office applications.
- Ability to work on multiple projects and tasks concurrently, successfully balancing business and client priorities.
- Ability to provide high-quality work under pressure that delivers security outcomes to tight deadlines and manage client-stakeholder expectations.
- Ability to work effectively both individually and as a senior team member in a multi-disciplined organization.
- Ability to coordinate and manage multi-disciplined resources, including technical specialists, while providing coherent reporting to non-technical business stakeholders.
- Ability to provide threat detection and monitoring technologies and services.
- Ability to produce incident response plans and coordinate desktop incident response exercises.
- Broad knowledge and application of common bodies, standards, frameworks, guidelines, and legislation, including:
- HMG/NCSC Information Assurance Policies, Standards, and Guidelines
- Cross-government security accreditation and secure by design processes
- JSP440 (plus other standard MoD IA methods)
- DCPP’s Cyber Security Model
- List X, List N
- Cyber Essentials
- Office for Nuclear Regulation (ONR) Security Assessment Principles (SyAPs)
- NIST
- GDPR, DPA, Computer Misuse Act, Official Secrets Act
- NIS-D
- Flexibility to travel and work throughout the UK.
- Ambition to work in a challenging and rewarding role that provides real benefit to clients.
- A proactive interest in maintaining and enhancing technical and consultancy skills.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Professional Qualifications, Certifications, and Security Clearances:
- Full Member of CIISec and/or UK Cyber Security Council (Security and Information Risk Advisor, Auditor, or Security Architect) or the agreement and ability to achieve such certification within 6 months of employment.
- Holder of current key security industry certifications such as COMPTIA Security +, CISSP, CISM, and ISO 270001
- CS&IA associated degree-level education (desirable)
- Current high-level security clearance and ability to maintain it.
Our client is a Defence Employer Recognition Scheme Gold Award winner.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills