We are actively building diverse teams and welcome applications from everyone.
Role: Data Security Consultant - Cyber
Location: Birmingham (SCC operate hybrid working, which comprises of a mix of office and home working)
Contract Type: Permanent
Salary Package: £90,000 - £110,000 plus large company benefits, a broad flexible benefits scheme, and 2 paid-for volunteering days a year
Hours: 9.00 am – 5.30 pm, Monday – Friday
Interview Process: 2-stage process
Why SCC?
- An inclusive workplace
- Excellent package: solid basic and company benefits
- Hybrid working & core hours in line with role requirements
- Career development and life-long learning opportunities
- Opportunity to join Europe's largest privately-owned IT Company
Role purpose:
We’re looking for a Data Security Consultant with a strong GRC foundation and hands‑on experience with Microsoft Purview to help organisations understand, protect, and govern their data in a pragmatic, business‑aligned way.
This is a client‑facing advisory role. You’ll work with security, risk, compliance, and data stakeholders to design and deliver data security and governance outcomes — not just deploy tools.
You’ll be comfortable operating at the intersection of risk, regulation, data protection, and technology, translating complex requirements into clear, actionable solutions.
Security clearance or the willingness to apply will be required for this role.
Key responsibilities:
Sales Support
- Work with our Cyber Solution Architects to respond to RFI, RFP, and Tenders in areas for Data Security.
- Using your expertise and knowledge consult with customers helping define the scope, identify successful outcomes that conform to required prerequisites.
Subject Matter Expert
- Deliver Data Security Proof of Concepts with Customers and SCC Pathfinders covering Microsoft Purview, Varonis, Pulse, and Vision.
- Maintain up-to-date knowledge of evolving best practices in the field of data security.
- Applying industry best practice frameworks and regulatory considerations when designing and implementing data security controls.
- Participate in one or more of our Subject Matter Expert (SME) groups within the Cyber team.
Delivery
- Implement and maintain data classification, labelling, and governance controls aligned to customer requirements and regulatory obligations.
- Mapping regulatory and GRC requirements (e.g. GDPR, ISO 27001, NIST, data residency, retention) to practical data security controls.
- Conducting data risk assessments, gap analyses, and control reviews across Microsoft 365 and wider data estates.
- Supporting clients with policy design, operating models, and control frameworks for data protection and governance.
- Acting as a trusted advisor, able to challenge constructively and influence senior stakeholders.
- Producing clear, executive‑ready deliverables (risk assessments, recommendations, roadmaps, design documentation).
Solution Enhancements
- Work with our Product Architecture teams to identity areas of technical development of our services.
- Work with our Product Management team to identify opportunities for service enhancements based on customer feedback.
Skills and experience:
Hard Skills
- Deep understanding of Data Security solutions, specifically based on Microsoft and Varonis.
- Understanding of regulations and Frameworks impacting data.
- Understanding of data related organisational policies.
- Ability to translate customer needs into relevant solutions.
- Experience translating risk and compliance requirements into technical controls.
Soft Skills
- Excellent stakeholder communication.
- Consultative and Customer Facing skills.
- Comfortable engaging with technical teams and non‑technical stakeholders.
- Collaboration and Team work.
- Documentation and Attention to Detail.
- Analytical and persuasive abilities.
- Teamwork & cross-functional collaboration.
Language
- Fluent English required.
- Spanish or French would be an advantage but not essential.
Candidate Profile
- University Degree in Cyber Security, Computer Science, or similar (desirable).
- Hands on experience implementing data security controls, ideally in a service provider environment.
- Microsoft Certifications such as SC-200 and SC-401(desirable).
- Evidence of continued professional development within Cyber Security.
- Must be able to obtain the Government and/or Police Security levels required to meet the operational requirements of the role and as per the requirements stipulated in relevant customer contracts.