Cyber Exercising Consultant, £500 per day inside IR35
6 months initially
London & Remote Working
Bench IT require an experienced Cyber Exercising Consultant to join a large organisation financial services organisation starting ASAP. The purpose of the role is to provide support in planning, coordinating and delivering the EMEA cyber resilience exercising programme. The successful candidate will support the maturation of the Cyber Exercising capability by embedding the new Exercising Toolkit and updated Exercising Methodology into day-to-day delivery, ensuring exercises are consistently planned, documented, executed and evidenced.
Please note this role is working in a hybrid model 2-3 days per week onsite in London.
Skills and Experience
- Strong knowledge of working within Cyber Exercising, Scenario testing and Playbook validation
- Experience in cyber resilience programmes - supporting or delivering cyber exercises, tabletop exercises, scenario tests, playbook validation, incident simulations or operational resilience testing.
- Good knowledge and understanding of cyber exercises, incident response, crisis management, operational resilience and scenario testing in a regulated environment, preferably Financial Services.
- Support the planning, coordination, facilitation and documentation of cyber exercising across EMEA, ensuring activity is delivered to agreed scope, timetable and quality expectations.
- Manage exercise life cycles, including objectives, stakeholder mapping, planning meetings, scenario design, inject development, facilitation, debriefs, reporting and action tracking.
- Embed and promote consistent use of the Exercising Toolkit and updated Exercising Methodology, providing guidance and practical support to stakeholders and local offices adopting the materials.
- Support alignment with Operational Resilience scenario testing, including mapping cyber scenarios to Important Business Services, impact tolerances, operational dependencies, decision points and recovery expectations.
- Develop and maintain exercise artefacts
- Identify local Cyber Exercising/resilience needs, build local delivery capability, adapt scenarios for local requirements, and promote consistent standards across the region.
- Strong stakeholder management and communication skills
- Contribute to continuous improvement of the cyber resilience exercising capability
- Understanding of relevant regulatory expectations and frameworks, including DORA, UK Operational Resilience, CBEST principles, NIST, ISO 27001 and MITRE ATT&CK.
- Formal security certification is desirable (CISM, CISSP, CRISC, ISO 22301, CBCI, MBCI)