> Markdown version of [/jobs/ext/2140550-information-cybersecurity-assurance-manager](https://www.wearedevelopers.com/jobs/ext/2140550-information-cybersecurity-assurance-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information & Cybersecurity Assurance Manager - **Company:** Neweasy - **Location:** Guildford, UK - **Experience:** Expert - **Salary:** £85,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cloud Computing, Cyber Security, Information Systems, Software Vulnerability Management, Vulnerability Analysis - **Published:** August 20, 2026 - **Apply:** https://www.reed.co.uk/jobs/information-cybersecurity-assurance-manager/57258385 ## About the Role Must be able to attain National Security Vetting at SC. DV is desirable, which would require 10 years unbroken residency in the UK., This isn't simply an information security governance role. You'll need genuine security assurance experience within defence or a similarly secure environment, with the technical understanding to work effectively with engineering, infrastructure, cloud and security teams., * Either hold, or have held: ChCSP, CISM, CISA, BCS CISMP, or CMIRM certification. * Membership of a Cybersecurity or Information Risk Management professional body such as, but not limited to, CIISec and IRM. * Must be able to hold National Security Vetting at SC or above, with a minimum unbroken UK residency of at least 5 years to be eligible to apply for National Security Vetting., * Comprehensive and demonstrable experience of working in a Defence Secure by Design programme or project, particularly as a Delivery Team Security Lead, Delivery Team Security Engineer, or Security Assurance Coordinator Role. * Proven ability to deliver security artefacts including Security Management Plans, Risk Registers and Risk Assessments, Security Requirements Documents, Security Aspects Letters, Threat Models and Vulnerability Assessments, Security Architecture Documents, Compliance & Audit Reports, and Incident & Recovery Plans. * Experience in the assurance or implementation of information or cybersecurity management systems that have achieved certification to ISO 27001, CE+, or DCC standards. * Experience facilitating, coordinating and directing ITHCs, including Security Requirements Traceability Matrix or Scoping Documents and prioritisation of remediation effort. * Proficient technical understanding of information systems at architecture, design and audit level. Knowledge & Skills * Strong understanding of information and cybersecurity principles and cybersecurity risk management frameworks. * Experience delivering and verifying ISO 27001, NIST SP 800-53, CE+, or DCC controls. * Ability to influence internal stakeholders using data and analysis. * Able to work independently, follow procedures and recognise appropriate escalation scenarios. * Good business knowledge with the ability to suggest and analyse "what-if" scenarios. * Knowledge of the space industry or aerospace communication systems is desirable. * Must be able to attain National Security Vetting at SC. DV is desirable, which would require 10 years unbroken residency in the UK. ## Description You'll take ownership of key security workstreams across products, services and major programmes, ensuring security requirements are understood, evidenced and delivered throughout the project lifecycle. It's a broad role covering security assurance, technical design, certification, risk, penetration testing, supplier security and incident response. What You'll Be Doing * Provide assurance against contractual security obligations for product and service deliverables, including ISO 27001, CE+ and DCC. * Deliver security strategies, policies, management plans, procedures and governance in accordance with relevant frameworks and industry standards. * Own cybersecurity assurance artefacts and security control requirements across contracted schedules and project milestones. * Lead certification or contract dependent ITHCs, vulnerability management exercises and external penetration testing, ensuring remediation is completed and verified. * Review infrastructure, cloud and application designs against Secure by Design principles and perform risk assessments for new technologies and business initiatives. * Participate in Change Advisory Board (CAB) meetings to provide security assurance. * Support incident and business continuity response plans and act as part of the incident response team when required. * Contribute to security working groups, steering boards and Executive and Board level reporting. * Own Security Aspect Letters and manage third-party supplier security compliance. * Own security aspects of space licensing throughout the spacecraft lifecycle. * Manage project-level security budgets and contribute to costing security requirements for future bids. * Manage security awareness and training in accordance with contractual and certification requirements. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) ## Related Articles - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [UK Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/326-uk-business-culture-and-etiquette) - [Data Engineer Salary UK](https://www.wearedevelopers.com/magazine/253-data-engineer-salary-uk)