Back to all jobs

Senior Consultant, Digital Risk & Cyber Security

Baringa

LondonHybridFull Time5-10 years
Posted 4 hours ago

About Baringa

Baringa is a global consulting firm that partners with leaders to drive change and create value. With deep industry expertise, and enabled by advanced technology, the firm helps clients to deliver with greater confidence and certainty. With over 2,000 people across the UK, Europe, North America, Asia and Australia, the firm combines global insight with local understanding.

The firm works across energy and resources, financial services, government and public sector, consumer products and retail, pharmaceuticals and life sciences, manufacturing, and technology, media and telecoms, with capabilities spanning strategy, transformation and operational excellence – all powered by advanced technology, data, AI and digital innovation.

Clients value Baringa’s collaborative approach and the way its teams integrate seamlessly – all working with a shared understanding of what matters most. The firm is known for its kind, curious experts who listen closely and care deeply about client success as they help clients transform energy markets, modernise financial platforms, expand telecoms and digital networks through advanced data analytics, enable digital services in government, and unlock growth in consumer sectors.

Certified as a Great Place to Work around the world, Baringa has been recognised by the Financial Times in 22 categories of its UK Leading Management Consultants rankings, and by Forbes for four consecutive years as one of the World’s Best Management Consulting Firms.

Our Digital Risk & Cyber practice is scaling fast, and we're looking for experienced consultant who want to build and solve, not just advise.

Our Digital Risk and Cyber (DRC) team helps our clients secure their organisation through innovative and appropriate approaches to security, resilience and privacy. We work with our clients across a range of challenges, from security strategies & operating models, to securing the specific technologies which drive value in their organisations. Our work is organised around two specialisms:

  • Digital Resilience - helping clients meet fast-moving security, resilience and regulatory obligations such as DORA, the UK Cyber Security and Resilience Bill;
  • Digital Trust - helping them govern emerging technology and security risk across AI, cloud and post-quantum cryptography.

We also build security into major business change or transformation programmes and deliver regulatory and standards compliance programmes. Increasingly we don’t just advise: we design, build and stand up the frameworks, operating models and tooling that keep working inside our clients’ operations after we leave.

Our client base spans financial services, energy, commodities, utilities, telecommunications, media, technology, pharmaceuticals, life sciences, retail, manufacturing, and government – offering excellent opportunities to develop your career. Our skilled DRC professionals become trusted advisors, independent by design, with no vendor resale agreements or audit constraints shaping our advice, delivering significant value to our clients.

We are looking for more great individuals to join our DRC practice. New colleagues who are just as passionate about their personal development as they are about digital risk and cyber security. People who bring their own views and perspective based on their own expertise and experience to date.

Our growth ambition, along with our continued ambitious geographic expansion means that we can offer our employees great progression and development across a diverse range of engagements.

What you will be doing

We help our clients become more resilient by supporting them in assessing, planning and executing major changes to their digital risk and cyber security strategy and capabilities. Our team of seasoned professionals support our clients in developing leading strategies, delivering transformative change, and embedding best practice ways of working. Increasingly we don't just advise on problems, we solve them: we design frameworks, build operating models and embed AI into how we deliver.

Often acting as a ‘critical friend’, we bring a communicative, collaborative and pragmatic approach, focused on creating great consulting experiences for our clients. Whether we are helping a CISO define their future change agenda, or delivering cutting-edge cyber security capability, we strike an effective balance between technical expertise, business understanding and interpersonal skills.

At this critical time in the growth of our consulting practice, we are looking for exceptional talent to help bolster our own capabilities and delivery capacity. The right candidate will have the unique opportunity to help build a truly different cyber security consulting business by spending a proportion of their time taking us to new markets and strengthening our position in others.

Your skills and experience

  • A passion to build a career in digital risk and cyber security demonstrated by choice in academic qualifications, self-learning or hobbies and interests
  • Experience in developing and leading business development campaigns
  • Experience of digital and cyber security risk assessments
  • Experience in programme or project delivery
  • Working knowledge of best practice frameworks, for example NIST and ISO 27001
  • Experience with digital risk and cyber security governance design and assurance
  • Ability to take ownership and deliver results in challenging, client-facing environments
  • Excellent communication and presentation skills
  • Strong analytical and problem-solving skills, especially those demonstrated through business process analysis and cyber security delivery
  • Confident in engaging a broad range of stakeholders about digital risk and cyber security - from executives and board members to CISOs and technology professionals
  • Ability to consistently deliver high quality outputs for our clients, enhancing our reputation and generating repeat business
  • Passion for building capability - designing frameworks, operating models and tooling.
  • Fluency in using AI to deliver, compressing high-volume tasks such as regulatory mapping, evidence review, maturity scoring and reporting, and in advising clients on securing and governing AI
  • Awareness of the operational resilience and regulatory agenda, including DORA, the UK Cyber Security and Resilience Bill and NCSC CAF
  • A willingness to build your profile in the market - points of view, speaking and content that open specific client conversations
  • Comfort teaming across sectors and other Baringa capabilities, working as one firm around the client's problem
  • Using AI tooling to deliver consulting services responsibly, and/or building tooling and automation – for example agentic AI, Power BI, Power Apps, risk quantification or digital twins.

Even Better If

  • Certifications in CISSP, ISO27001, NCSC CCP, GCISP, PRINCE2 (or equivalent), AI governance (e.g. AIGP), cloud security (CCSP or CCSK), business continuity and resilience (e.g. BCI), and post-quantum or cryptography credentials
  • Awareness of or experience in one or more of the following: o Strategy and operating model o Supply chain risk o Regulatory requirements, for example GPDR, DPA, DPDI, DORA, NIS o Crisis management o Threat intelligence o Industrial Control Systems (ICS) or Operational Technology (OT) cyber security o Security architecture o Physical / corporate security o Agile security / DevSecOps o AI security and governance, including the EU AI Act

o Post-quantum cryptography and cryptographic agility

o Operational resilience and regulation

What a career at Baringa will give you

Putting People First.

Baringa is a People First company and wellbeing is at the forefront of our culture. We recognise the importance of work-life balance and flexible working and provide our staff amazing benefits. Some of these benefits include:

  • Generous Annual Leave Policy: We recognise everyone needs a well-deserved break. We provide our employees with 5 weeks of annual leave, fully available at the start of each year. In addition to this, we have introduced our 5-Year Recharge benefit which allows all employees an additional 2 weeks of paid leave after 5 years continuous service.
  • Flexible Working: We know that the ‘ideal’ work-life balance will vary from person to person and change at different stages of our working lives. To accommodate this, we have implemented a hybrid working policy and introduced more flexibility around taking unpaid leave.
  • Corporate Responsibility Days: Our world is important to us, so all our employees get 3 every year to help social and environmental causes and increase our impact on the communities that mean the most to us.
  • Wellbeing Fund: We want to encourage all employees to take charge and prioritise their own wellbeing. We’ve introduced our annual People Fund to support this by offering every individual a fund to support and manage their wellbeing through an activity of their choice.
  • Profit Share Scheme: All employees participate in the Baringa Group Profit Share Scheme so everyone has a stake in the company’s success.

Diversity and Inclusion

We are proud to be an Equal Opportunity Employer. We believe that creating an environment where everyone feels a sense of belonging is central to our culture and that diversity is paramount to driving creativity, innovation, and value for our clients and for our people.

An award-winning workplace

You can be a part of our ‘Great Place to Work’ – with our commitment to women and well-being in the workplace for all. Click here to see some of our recent awards and how we’ve achieved this.

Using business as a force for good.

We maintain high standards of environmental performance and transparency, which can be seen through our commitment to Net Zero with our SBTI-verified Scope 1, 2 and 3 emissions reduction targets and our support of the Better Business Act. We report our progress publicly and ensure that we are also externally assessed and scored through organisations like CDP and EcoVadis - helping us to continually identify where we can improve.

We have a long legacy of supporting the communities in which we work, and offer a variety of ways to contribute, by putting people first and creating impact that lasts. Our Corporate Social Responsibility (CSR) agenda is about giving back to the communities in which we live and work by sharing our skills, talent and time. In essence, we aim to empower and encourage everyone in the firm to contribute to the things we care about, and support registered charities and organisations with a clear social or environmental purpose to increase the positive impact they can have.

Join us

All applications received will be reviewed by a member of our Talent Acquisition team. We never rely solely on automated screening or AI tools to make hiring decisions. Your application will be considered for employment without regard to race, ethnicity, religion, gender, gender identity or expression, sexual orientation, nationality, disability, age, faith or social background. We do not filter applications by university background and encourage those who have taken alternative educational and career paths to apply. We would like to actively encourage applications from those who identify with less represented and minority groups. We operate an inclusive recruitment process, ensuring reasonable adjustments where needed. Please contact a member of our Recruitment Team to discuss further.

Baringa Privacy Notices

For Uk & Eu

Your personal data will be retained by Baringa for up to two years, in accordance with our UK Recruitment Privacy Notice / EU Recruitment Privacy Notice, to evaluate your application and meet our legal and reporting obligations. In line with the General Data Protection Regulation (GDPR), you have the right to request access to, rectification, or erasure (subject to legal limitations) of your personal data. For more information, please contact us at [email protected]

For the USA

Your personal data may be retained by Baringa for up to two years, as outlined in our Recruitment Privacy Notice (AMER & APAC), to support the recruitment process and internal reporting requirements. Where applicable, and in accordance with relevant federal and state laws, you may have the right to request access to or correction of your personal information. For further details, please contact [email protected]

For Australia & Singapore

Your personal data will be retained by Baringa for up to two years, in accordance with our Recruitment Privacy Notice (AMER & APAC), to assess your application and meet applicable reporting and legal obligations. In line with the Australian Privacy Act and Singapore’s Personal Data Protection Act (PDPA), you may have rights to access, correct, or request limited deletion of your personal data. For more information, please contact us at [email protected]

Benefits

Generous annual leave policy5-year recharge benefitHybrid working policyCorporate responsibility daysWellbeing fundProfit share scheme