Principal Consultant (Senior Manager) - Cyber
Principal Consultant – Cyber & Operational Resilience
Location: London (Hybrid) | Practice Area: Finance, Risk, Regulatory & Financial Crime | Type: Permanent
Strengthen cyber resilience and safeguard critical operations across financial services
The Role
Capco is seeking experienced Principal Consultants to join our Cyber & Operational Resilience capability within the Finance, Risk, Regulatory & Financial Crime (FRRF) practice. You'll work with senior stakeholders across financial services organisations to design and deliver cyber resilience strategies, implement robust resilience frameworks, and enhance operational resilience capabilities. This role combines strategic advisory with hands-on delivery, helping clients strengthen cyber risk management, meet evolving regulatory expectations, and build resilient operating models. You'll also leverage approved AI tools and AI-enabled ways of working to enhance analysis, improve delivery, and generate data-driven insights while applying responsible AI practices and appropriate human oversight.
What You'll Do
- Deliver cyber and operational resilience transformation programmes aligned to regulatory frameworks such as PRA, DORA, and other global resilience standards, identifying opportunities to leverage AI-enabled workflows and automation.
- Assess and enhance cyber resilience capabilities, including resilience frameworks, operating models, controls, and governance, using AI-enabled analysis where appropriate to strengthen decision-making and operational effectiveness.
- Support third-party and vendor risk assessments, identifying vulnerabilities across supply chains and technology ecosystems while combining AI-enabled insights with expert judgement.
- Design and implement resilience governance, Important Business Services (IBS), Impact Tolerance (ITOL), scenario testing, and reporting frameworks, ensuring robust governance, validation, and oversight where AI-assisted tools are utilised.
- Collaborate with technology teams to support cyber tooling, cloud security initiatives, and control enhancements, identifying opportunities to responsibly apply AI to improve client outcomes.
What We're Looking For
- Experience in cyber resilience, cyber risk, and operational resilience within financial services or management consulting.
- Strong understanding of cyber security frameworks such as NIST and ISO 27001, together with regulatory expectations including PRA and DORA.
- Practical experience delivering resilience testing, control assessments, remediation programmes, and technology-enabled transformation initiatives.