We are seeking a highly skilled Managing Consultant - Automotive Cyber Security to join our Global Transport practice. This role is pivotal in strengthening and expanding our cyber security capability within the global automotive ecosystem, while also supporting cross-domain engagements in rail, maritime, and aviation as needed.
The ideal candidate will bring deep knowledge of automotive cyber security, connected and software-defined vehicle technologies, operational technology (OT), embedded systems, relevant international cyber security standards and regulations (including ISO/SAE 21434, UNECE R155, UNECE R156, and ISO 26262), penetration testing methodologies, and the broader transport ecosystem. In addition to technical delivery, the individual will play a key role in supporting business development, building client trust, and elevating NCC Group's profile within the automotive sector.
This is a fully remote, client-facing role requiring strong collaboration, communication, and consulting skills.
Key Responsibilities
Technical Delivery & Automotive Cyber Security Expertise
- Act as a subject matter expert (SME) for automotive cyber security across global engagements.
- Lead and deliver complex cyber security assessments across vehicle, engineering, manufacturing, operational technology (OT), and information technology (IT) environments.
- Apply deep knowledge of automotive-specific standards and frameworks, including:
- ISO/SAE 21434 (Road Vehicle Cybersecurity Engineering)
- UNECE R155 (Cyber Security Management System)
- UNECE R156 (Software Update Management System)
- ISO 26262 (Functional Safety)
- Conduct or support penetration testing, vulnerability assessments, architecture reviews, risk assessments, and Threat Analysis and Risk Assessments (TARA) for automotive clients.
- Provide expert interpretation of cyber security requirements for vehicle manufacturers, suppliers, technology providers, and mobility operators.
- Ensure security recommendations are aligned with safety, regulatory, operational, and business requirements throughout the vehicle lifecycle.
Automotive Domain Expertise
- Provide expert understanding of the automotive ecosystem, including:
- Connected vehicles
- Software-defined vehicles (SDVs)
- Electronic Control Units (ECUs)
- In-vehicle networks (CAN, LIN, FlexRay, Automotive Ethernet)
- Telematics and connected services
- Electric vehicle charging infrastructure
- Manufacturing and production environments
- Vehicle development, validation, and homologation processes
- Translate complex automotive engineering and operational knowledge into training and knowledge-sharing activities for internal teams.
- Contribute to the development of internal automotive cyber security capabilities, methodologies, and best practices.
- Maintain awareness of emerging threats, vulnerabilities, regulations, and industry trends affecting the automotive sector.
Business Development & Practice Growth
- Support the identification, creation, and growth of automotive cyber security opportunities globally.
- Help strengthen NCC Group's presence within the automotive sector through:
- Thought leadership activities, including white papers, webinars, and industry events
- Client engagements and pre-sales support
- Collaboration with OEMs, Tier 1 suppliers, mobility providers, and industry bodies
- Collaborate with engagement managers and practice leadership to support the development of automotive-focused service offerings.
- Contribute to bids, proposals, statements of work, and technical scoping activities for prospective customers.
Cross-Domain Support (Multi-Modal Transport)
- Support projects across rail, maritime, and aviation domains where automotive cyber security expertise can add value.
- Maintain awareness of common OT, embedded, and safety-critical technologies across transport sectors.
- Promote knowledge sharing and collaboration across the wider Transport Cyber Security practice.
Client Engagement & Delivery Excellence
- Act as a trusted advisor to clients, providing clear and actionable cyber security recommendations.
- Communicate complex technical concepts in a professional and client-friendly manner.
- Deliver high-quality outputs and maintain strong client satisfaction throughout engagements.
- Build and maintain positive working relationships with clients and key stakeholders.
Skills, Knowledge and Expertise
Technical Experience
- Proven experience in automotive cyber security, ideally within OEMs, Tier 1 suppliers, mobility providers, automotive technology companies, or a cyber security consultancy.
- Strong experience working with and applying:
- ISO/SAE 21434
- UNECE R155
- UNECE R156
- ISO 26262
- Strong understanding of embedded systems, vehicle electronics, automotive communications networks, connected vehicle platforms, and safety-critical environments.
- Practical experience conducting or supporting penetration testing and security assessment activities.
- Experience performing secure architecture reviews, threat modelling, TARA activities, and risk assessments within automotive or transportation environments.
- Familiarity with automotive development lifecycles, software delivery processes, and regulatory compliance requirements.
Domain Knowledge
- In-depth understanding of the automotive ecosystem, including vehicle architectures, connected vehicle platforms, software-defined vehicles, manufacturing environments, supplier ecosystems, and automotive cyber security regulations.
- Direct experience working within or alongside automotive OEMs, Tier 1 suppliers, mobility service providers, or automotive cyber security programmes.
- Understanding of vehicle engineering, safety, validation, and homologation processes.
Soft Skills & Professional Attributes
- Excellent communication skills in both technical and non-technical contexts.
- Strong client-facing and stakeholder management skills.
- Ability to lead workstreams and influence stakeholders at all levels.
- Ability to work collaboratively across geographies, teams, and disciplines.
- Strong consulting mindset with the ability to understand client challenges and provide pragmatic solutions.
- A passion for coaching, mentoring, and knowledge sharing.
Desirable (Not Mandatory)
- Recognised cyber security certifications such as CISSP, GICSP, ISA/IEC 62443 Cyber Security Expert, OSCP, or GIAC certifications.
- Automotive cyber security certifications or formal training relating to ISO/SAE 21434, UNECE R155/R156, or automotive engineering disciplines.
- Experience contributing to industry standards, working groups, or regulatory consultations.
- Background in automotive engineering, systems engineering, functional safety, or vehicle development.
- Knowledge of EV ecosystems, charging infrastructure security, and software-defined vehicle architectures.
Benefits
What do we offer in return?
We have a high-performance culture which is balanced evenly with world-class well-being initiatives and benefits:
- Flexible Working: Balance your work and personal life with our flexible working options.
- Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave.
- Medicash & Critical Illness Scheme
- Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme.
- Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities.
- Green Car Scheme: Drive green and save money with our eco-friendly car scheme.
- Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme.
- Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet.
- Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.
- Work permits
- United Kingdom
- Timezones
- United Kingdom
- Education
- bachelor degree