Information & Cybersecurity Assurance Manager

Neweasy
Guildford, UK
1 day ago
Apply on www.reed.co.uk
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
ÂŁ85,000.0
Working hours
Regular working hours
Job source

Tech stack

Software System Penetration Testing Cloud Computing Cyber Security Information Systems Software Vulnerability Management Vulnerability Analysis

Job description

You’ll take ownership of key security workstreams across products, services and major programmes, ensuring security requirements are understood, evidenced and delivered throughout the project lifecycle.

It’s a broad role covering security assurance, technical design, certification, risk, penetration testing, supplier security and incident response. What You’ll Be Doing

  • Provide assurance against contractual security obligations for product and service deliverables, including ISO 27001, CE+ and DCC.
  • Deliver security strategies, policies, management plans, procedures and governance in accordance with relevant frameworks and industry standards.
  • Own cybersecurity assurance artefacts and security control requirements across contracted schedules and project milestones.
  • Lead certification or contract dependent ITHCs, vulnerability management exercises and external penetration testing, ensuring remediation is completed and verified.
  • Review infrastructure, cloud and application designs against Secure by Design principles and perform risk assessments for new technologies and business initiatives.
  • Participate in Change Advisory Board (CAB) meetings to provide security assurance.
  • Support incident and business continuity response plans and act as part of the incident response team when required.
  • Contribute to security working groups, steering boards and Executive and Board level reporting.
  • Own Security Aspect Letters and manage third-party supplier security compliance.
  • Own security aspects of space licensing throughout the spacecraft lifecycle.
  • Manage project-level security budgets and contribute to costing security requirements for future bids.
  • Manage security awareness and training in accordance with contractual and certification requirements.

Requirements

Must be able to attain National Security Vetting at SC. DV is desirable, which would require 10 years unbroken residency in the UK., This isn’t simply an information security governance role. You’ll need genuine security assurance experience within defence or a similarly secure environment, with the technical understanding to work effectively with engineering, infrastructure, cloud and security teams., * Either hold, or have held: ChCSP, CISM, CISA, BCS CISMP, or CMIRM certification.

  • Membership of a Cybersecurity or Information Risk Management professional body such as, but not limited to, CIISec and IRM.
  • Must be able to hold National Security Vetting at SC or above, with a minimum unbroken UK residency of at least 5 years to be eligible to apply for National Security Vetting., * Comprehensive and demonstrable experience of working in a Defence Secure by Design programme or project, particularly as a Delivery Team Security Lead, Delivery Team Security Engineer, or Security Assurance Coordinator Role.
  • Proven ability to deliver security artefacts including Security Management Plans, Risk Registers and Risk Assessments, Security Requirements Documents, Security Aspects Letters, Threat Models and Vulnerability Assessments, Security Architecture Documents, Compliance & Audit Reports, and Incident & Recovery Plans.
  • Experience in the assurance or implementation of information or cybersecurity management systems that have achieved certification to ISO 27001, CE+, or DCC standards.
  • Experience facilitating, coordinating and directing ITHCs, including Security Requirements Traceability Matrix or Scoping Documents and prioritisation of remediation effort.
  • Proficient technical understanding of information systems at architecture, design and audit level.

Knowledge & Skills

  • Strong understanding of information and cybersecurity principles and cybersecurity risk management frameworks.
  • Experience delivering and verifying ISO 27001, NIST SP 800-53, CE+, or DCC controls.
  • Ability to influence internal stakeholders using data and analysis.
  • Able to work independently, follow procedures and recognise appropriate escalation scenarios.
  • Good business knowledge with the ability to suggest and analyse “what-if” scenarios.
  • Knowledge of the space industry or aerospace communication systems is desirable.
  • Must be able to attain National Security Vetting at SC. DV is desirable, which would require 10 years unbroken residency in the UK.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.reed.co.uk
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell ¡ World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman ¡ World Congress 2022

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo ¡ World Congress 2024

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira ¡ Coffee With Developers

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger ¡ LIVE

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder ¡ LIVE

Videos

See all

Related articles

See all