Information Assurance/Technical Security Specialist

Thales Group
Crawley, United Kingdom
4 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English

Job location

Crawley, United Kingdom

Tech stack

Amazon Web Services (AWS)
Azure
Software as a Service
Cloud Computing
Cloud Computing Security
Information Systems
Computer Networks
Data Security
Infrastructure as a Service (IaaS)
Microsoft Office
Oracle Applications
Platform as a Service (PAAS)
Software Security

Job description

THALES are looking to hire an Information Assurance/Technical Security Specialist to provide technical security advice and guidance on the efficient and effective secure through-life management of systems related to the use, processing, storage, and transmission of Thales information or data. This includes but is not limited to the technical oversight of the physical, technical, and administrative security controls to conduct these tasks. Reporting to the Thales UK Deputy CISO, the Information Assurance/Technical Security role involves the identification of applicable technical security requirements and their associated cost-effective security controls as well as through-life continual security assurance of Thales IS environments throughout their design, implementation, transition into service, and operational lifespans. Location Crawley / Doncaster but will consider other Thales locations. What will you deliver? *Technical Security: Support Thales UK in ensuring all IS/IT technical security measures are implemented, enhanced and developed where necessary, to ensure successful and timely security assurance via on-going through-life continual assurance and compliance programmes. *Technical Security Point of Contact (PoC): Provide a central PoC for all IS/IT technical security matters and concerns, supporting delivery teams and businesses throughout project lifecycles. *Change management: Conduct security reviews of internal/ externally connected platform related changes ensuring Security risks, impacts and mitigations are managed appropriately. *Cloud Security: provide security guidance around the secure deployment and usage of Thales adopted public cloud infrastructure and/or SaaS services (e.g., Azure) in compliance with government security guidelines, Thales's policy and industry accepted "good practices" for security. *Compliance & Governance: ensure Thales on-premises and cloud environments comply with government policies, such as Cyber Essentials, DefStan 05-138, UK GDPR, NCSC guidelines and other applicable contractual and regulatory frameworks. *Evidence Continual Security Assurance: Creation, Maintenance and Review of all IS/IT technical security documentation, policy and procedures associated with Thales' IS/IT networks, systems and applications, as per Customer (primarily HMG UK MOD) and Thales Group policy and mandatory requirements. *Incident Response: Be responsible for the reporting, investigation and analysis of security incidents and potential breaches within classified environments, working with the Thales UK Incident management team to ensure identified issues are resolved quickly. *IS/IT Squad Engagement: Develop security requirements, epics and stories, along with guidance & governance to squads to ensure data protection and data security are included in the scope of new and existing IS/IT Squad activities, initiatives and projects.

Requirements

*Able to effectively communicate highly technical security concepts, implementations, and issues, both verbally and in writing to management, clients and staff at all levels. *Able to interpret detailed system design documentation, identifying potential security risks and recommend mitigations containing levels of security appropriate to the associated risk levels. *Able to interpret security standards and derive solution specific security requirements from these and assess solutions against these standards for compliance for both new and changes to existing systems/applications. *Able to provide analytical advice on the security implications of new and existing systems and for all proposed changes to said systems. *Ability to provide technical security advice to business areas when required and to provide technical security input to the security risk registers. *Demonstrable understanding of security across the full stack of information systems, (network, infrastructure and applications) both on-premises and cloud-hosted (MS Azure, Oracle, AWS; PaaS, IaaS and SaaS).

*Demonstrable experience of applying security principles within an agile delivery framework. *Evidential experience as subject matter expert in the evaluation and implementation of technical security products and solutions for Public or Private sector organisations. *Evidential experience in the identification, assessment and management of technical security risks, developing risk mitigation strategies, and tracking residual risk throughout the risk lifecycle. Demonstrable experience of managing assurance and/or compliance activities associated with a defined security standard (ISO 27001, Def-Stan 05-138, NIST SP 800-, NIST CSF). *Experience developing security assurance frameworks and governance models. *Experience in performing formal risk assessments and production of security reporting artefacts within both on-premises and cloud-based environments. *Evidential experience as subject matter expert in the evaluation and implementation of technical security products for MS Office 365, Azure cloud based Public or Private sector organisations.

Benefits & conditions

On offer is a competitive salary and benefits package

*Performance Related Bonus *Half day every Friday, usually finishing around 13:00pm *Hybrid Working *Pension Scheme *28 days annual leave (Plus Bank Holidays) *Life Cover *24/7 Employee Assistance Program and access to mental wellbeing app *Employee discount shopping schemes on major brands and retailers *Gym membership discounts

Apply for this position