> Markdown version of [/jobs/ext/1532932-cyber-security-policy-authoring-specialist-sc-cleared](https://www.wearedevelopers.com/jobs/ext/1532932-cyber-security-policy-authoring-specialist-sc-cleared). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Policy Authoring Specialist - SC Cleared - **Company:** SR2 - **Location:** London, UK (Remote available) - **Salary:** £110,500.0 - £117,000.0 - **Contract:** Contract - **Skills:** Cyber Security, Information Systems, Mobile Security, Data Processing, SC Clearance, Software Version Control - **Published:** July 21, 2026 - **Apply:** https://computerjobs.com/gb/en/mob/job/2C40939F44CAAA6D3A ## About the Role * Strong experience authoring cyber security policies, standards and procedures. * Practical knowledge of the UK NIS Regulations. * Experience working with cyber security control frameworks. * Previous experience developing BYOD or mobile security policies. * Ability to create clear, structured and audit-ready documentation. * Strong stakeholder management and workshop facilitation skills. * Active SC clearance. Desirable Experience * Experience in critical national infrastructure, transport, defence or government environments. * Understanding of operational technology or safety-critical environments. ## Description Cyber Security Policy Authoring Specialist - SC Cleared We are looking for an experienced Cyber Security Policy Authoring Specialist to support a major UK infrastructure programme. You will review, develop and maintain cyber security policies, standards, procedures and supporting documentation, ensuring alignment with the Network and Information Systems (NIS) Regulations 2018, relevant control frameworks and organisational governance requirements. Due to the nature of the role, active SC is required. Key Responsibilities * Author and update cyber security policies, standards and procedures. * Review existing documentation and identify gaps, duplication and inconsistencies. * Map policy requirements to relevant regulatory and security controls. * Develop documentation covering areas such as BYOD, mobile device security, access control, acceptable use, data handling, remote working and third-party security. * Translate technical, regulatory and risk requirements into clear, practical documentation. * Work with security, architecture, engineering, risk and operational stakeholders. * Maintain document governance, version control, ownership and review cycles. * Support assurance, audit and compliance activities. * Produce policy gap analyses, control mappings and supporting evidence. Essential Experience * Strong experience authoring cyber security policies, standards and procedures. * Practical knowledge of the UK NIS Regulations. * Experience working with cyber security control frameworks. * Previous experience developing BYOD or mobile security policies. * Ability to create clear, structured and audit-ready documentation. * Strong stakeholder management and workshop facilitation skills. * Active SC clearance. Desirable Experience * Experience in critical national infrastructure, transport, defence or government environments. * Understanding of operational technology or safety-critical environments. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Policy as [versioned] code - you're doing it wrong](https://www.wearedevelopers.com/videos/532-policy-as-versioned-code-you-re-doing-it-wrong) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)