Conduit

ArmstrongAdams

www.nccgroup.com

ArmstrongAdams provides Information risk management solutions.

Open roles
60

Company signals

Score: 60
Stale listings 0% Buzzword-heavy listings 55% New cities (90d) 1 HN mentions (90d) 1 SEC Form D filed never Wikipedia No

Job facts

Location
Hybrid · GBR Cheltenham Jessop House
Workplace
Hybrid
Type
Full-time
Department
Cyber Services and Capabilities
Applications powered by
Pinpoint
Apply to this job

Managing Consultant - Business Resilience

at ArmstrongAdams


Managing Security Consultant – Cyber Business Resilience and Recovery

Location: Cheltenham, Manchester or London - occasional office presence and client site visits

Why this role?

Do you thrive on helping organisations prepare for, withstand, and recover from cyber incidents? At NCC Group, you’ll be part of a team that bridges the gap between cyber operations and business continuity ensuring our clients can respond confidently when disruption strikes. You’ll work across cyber recovery planning, crisis management exercises, and resilience assessments and recovery that protect real-world business outcomes. It’s meaningful, high-impact work that blends strategy, governance, and hands-on resilience engineering.

Key Responsibilities


What you’ll do

  • Build cyber resilience strategies: Design and deliver tailored cyber resilience and recovery frameworks that integrate crisis management, business continuity and IT disaster recovery
  • Assess and improve readiness: Conduct cyber resilience maturity assessments and tabletop exercises; identify and prioritise gaps in recovery capabilities.
  • Design recovery playbooks: Create actionable recovery and communication plans aligned with NIST, ISO 22301, and industry best practice.
  • Test and validate: Lead scenario-based simulations and recovery testing to validate processes, people, and technology readiness.
  • Integrate with security operations: Collaborate with SOC and IR teams to align resilience and recovery capabilities with detection, containment, and response functions.
  • Engage stakeholders: Translate technical findings into clear, business-relevant recommendations; present outcomes to executives and boards.
  • Advise on resilience architecture: Support the design of resilient infrastructure, backup strategies, and cloud recovery configurations.
  • Mentor and contribute: Coach junior consultants and share lessons learned through internal knowledge sessions and reusable playbook templates.
  • Lead service line improvements: develop and collaborate with other stakeholders, e.g., sales and delivery, to introduce further service improvements to the business resilience service line and support sales and business development of new business.


A week in the life (example)

Monday: Lead a cyber resilience workshop with a financial client, mapping recovery priorities to business impact.


Tuesday:
Deliver a tabletop exercise simulating a ransomware event and assess decision-making under pressure.

Wednesday: Draft a recovery framework and supporting playbooks for a multi-cloud environment.

Thursday: Collaborate with the IR and SOC teams to align response and recovery triggers.

Friday: Present a resilience maturity assessment to senior stakeholders and plan next-phase improvements.

Skills, Knowledge and Expertise

  • Strong experience in cyber resilience , business continuity , and disaster recovery consulting, ideally within complex enterprise environments.
  • Practical understanding of crisis management , and cyber recovery operations
  • Familiarity with frameworks and standards such as ISO 22301 , NIST CSF , NIST SP 800-34 , and BS 65000.
  • Proven ability to engage at all levels — from technical recovery teams to C-suite executives.
  • Experience running or facilitating tabletop exercises , war-gaming sessions , or simulation testing.
  • Knowledge of resilience tooling (e.g., backup orchestration, DR automation, configuration baselining).
  • Strong written and verbal communication — able to produce concise reports and deliver persuasive presentations.

Nice-to-haves (not show-stoppers)

  • Exposure to cloud resilience (Azure/AWS/GCP) and hybrid recovery architectures.
  • Experience with Incident response planning and management.
  • Experience with risk management frameworks (ISO 27005, FAIR).
  • Understanding of supply chain resilience and third-party risk.
  • Certifications such as CBCI , ISO 22301 Lead Implementer/Auditor , CISSP , CISM , or CRISC.

Benefits

What do we offer in return?

We have a high-performance culture which is balanced evenly with world-class well-being initiatives and benefits:

  • Flexible Working: Balance your work and personal life with our flexible working options.
  • Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave.
  • Medicash & Critical Illness Scheme
  • Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme.
  • Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities.
  • Green Car Scheme: Drive green and save money with our eco-friendly car scheme.
  • Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme.
  • Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet.
  • Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.