> Markdown version of [/jobs/ext/2259039-c004173-cis-security-program-manager-cyber-security-cts-thu-10-apr](https://www.wearedevelopers.com/jobs/ext/2259039-c004173-cis-security-program-manager-cyber-security-cts-thu-10-apr). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # C004173 CIS Security Program Manager (Cyber Security) (CTS) - THU 10 Apr - **Company:** EMW - **Location:** Northwood, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Active Directory, Cluster Analysis, Configuration Management, Cyber Security, Information Technology Consulting, Multi-Factor Authentication, File System Permissions, IPv6, Intrusion Detection and Prevention, Virtual Private Networks (VPN), Windows Search, Windows Servers, Public Key Infrastructure, Virtualization Technology, Software Vulnerability Management, Computer Network Technologies, Firewalls (Computer Science), Information Technology, Patch Management, Nessus, Cts+, Vulnerability Analysis - **Published:** August 26, 2026 - **Apply:** https://www.collegerecruiter.com/job/2815161754-c004173-cis-security-program-manager-cyber-security-cts-thu-10-apr ## About the Role * The candidate must have a currently active NATO COSMIC TOP SECRET security clearance * Familiarity with NATO Security Directives * Experience in managing information assurance or security compliance programs * Experience drafting Standard Operating Procedures and directive policy documents * Familiarity with Microsoft update and patch management systems, IT security frameworks and governance models, and Common Vulnerability Scoring System (CVSS) v3.X or later standards * Familiarity ITIL Version 4 concepts including Configuration Management and Service Asset Management * Experience with Microsoft Windows desktop operating systems; * Experience with Microsoft Windows server operating systems including the following key components such as Active Directory, Group Policy, New Technology File System permissions, Dynamic Host Control Protocol; * Experience with key Information Technology concepts including shared storage, clustering and virtualization; * Familiarity with security and network technologies such as IPv6; Firewalls, Virtual Private Networks, Public Key Infrastructure, Intrusion Detection and Forensic Appliances; * Familiarity with International Organization for Standardization (ISO)/International Electro-technical Commission (IEC) 27001 framework * Assists in developing, sourcing and/or delivering CIS security training to operational partners and unit staff * Prior experience of working in an international environment or organizations comprised of both military and civilian elements ## Description C004173 CIS Security Program Manager (Cyber Security) (CTS) - THU 10 Apr 3 days ago Be among the first 25 applicants Deadline Date: Thursday 10 April 2025 Requirement: CIS Security Program Manager (Cyber Security) Location: Northwood, GB Full Time On-Site: Yes Time On-Site: 100% Total Scope of the request (hours): 836 Required Start Date: 26 May 2025 End Contract Date: 31 December 2025 Required Security Clearance: NATO COSMIC TOP SECRET Duties and Role: * Applies and maintains specific security controls as required by organizational policy and local risk assessments * Drafts and maintains documents supporting security accreditation for CIS in AOR * Drafts and maintains CIS Security policy documents * Liaises with operational partners to ensure security accreditation compliance requirements * Supports investigation of suspected attacks and security breaches * Provides detailed and specific advice regarding the application of their specialism to the organization's planning and operations * Assists in infrequent, limited management of Trellix ePolicy Orchestrator (ePO) and Endpoint Security (ENS) components required by NATO Cyber Security Centre (NCSC) policy on local and remote (deployed) devices in two security domains * Manages endpoint security components on disconnected and standalone devices in AOR * Monitors CIS logs for suspicious or anomalous activity and reports as required * Document routine processes in Standard Operating Procedures * Configures and distributes two-factor authentication devices * Performs trend analysis of routine vulnerability assessments using automated and semi-automated tools, including Nessus Tenable * Provides vulnerability mitigation advice to stakeholders * Supports external service providers in management of local boundary protection and cyber security monitoring infrastructure * Provides CIS Security advice and training, as required * Executes the incident and change management processes in accordance with the Information Technology (IT) Information Library (ITIL) Version 4 framework * Contributes to Asset Configuration Patching and Vulnerability Management activities * Experience in developing, sourcing and/or delivering training * Performs other related duties, as required Specific Working Conditions: Personal Liability and comprehensive insurance required RequirementsSkill, Knowledge & Experience: * The candidate must have a currently active NATO COSMIC TOP SECRET security clearance * Familiarity with NATO Security Directives * Experience in managing information assurance or security compliance programs * Experience drafting Standard Operating Procedures and directive policy documents * Familiarity with Microsoft update and patch management systems, IT security frameworks and governance models, and Common Vulnerability Scoring System (CVSS) v3.X or later standards * Familiarity ITIL Version 4 concepts including Configuration Management and Service Asset Management * Experience with Microsoft Windows desktop operating systems; * Experience with Microsoft Windows server operating systems including the following key components such as Active Directory, Group Policy, New Technology File System permissions, Dynamic Host Control Protocol; * Experience with key Information Technology concepts including shared storage, clustering and virtualization; * Familiarity with security and network technologies such as IPv6; Firewalls, Virtual Private Networks, Public Key Infrastructure, Intrusion Detection and Forensic Appliances; * Familiarity with International Organization for Standardization (ISO)/International Electro-technical Commission (IEC) 27001 framework * Assists in developing, sourcing and/or delivering CIS security training to operational partners and unit staff * Prior experience of working in an international environment or organizations comprised of both military and civilian elements Seniority level Mid-Senior level Employment type Full-time Job function Project Management and Information Technology Industries IT Services and IT Consulting ## Related Videos - [IoT: The road to sustainability](https://www.wearedevelopers.com/videos/557-iot-the-road-to-sustainability) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Top 6 Hackathons for Developers in 2023](https://www.wearedevelopers.com/magazine/263-top-6-hackathons-for-developers-in-2023) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)