Cybersecurity Governance & Assurance Specialist
Amaris GROUP SA
Greater London, UK
5 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.collegerecruiter.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source
Tech stack
Cyber Security
Embedded Software
Red Team (Cyber Security)
Verification and Validation (Software)
Software Vulnerability Management
Job description
- Own and maintain the product cybersecurity governance and assurance framework, aligned with the broader compliance model used across disciplines
- Develop and maintain internal standards, templates, checklists, and guidance to enable consistent execution across programmes (e.g., System of Interest definitions, TARA guidance, cybersecurity requirements, testing expectations, and evidence packs)
- Create and deliver training and enablement programmes to uplift engineering teams and drive “right first time” compliance
Programme Compliance Assessment and Assurance
- Plan and execute cybersecurity compliance assessments of product programmes and suppliers, reporting status, risks, and evidence gaps clearly and early
- Assess alignment against internal requirements and relevant external standards and regulations, including ISO/SAE 21434, ISO 24882, IEC 62443, and the Cyber Resilience Act (CRA)
- Review the adequacy of key cybersecurity work products such as threat modelling/TARA outputs, requirements, architecture evidence, verification and validation strategies, and residual risk statements
- Drive closure of findings with stakeholders across systems, embedded software, verification, manufacturing/service, and suppliers
Cybersecurity Testing Assurance
- Define cybersecurity testing expectations required for compliance evidence, covering coverage scope, methods, reporting, and remediation tracking
- Coordinate Red Team and testing activities to ensure outputs support programme assurance and close testing capability gaps, * Establish and assure governance for post-production vulnerability management, including monitoring from suppliers, research findings, Red Team outputs, and PSIRT channels, and routing to affected products
- Support readiness for CRA mandatory reporting, including Article 14 reporting workflows and fast-track response for actively exploitable issues
- Capture and disseminate lessons learned (e.g., CWE/CVE insights) back into standards, checklists, and training materials
Requirements
- 3+ years of experience within Tier 1 or OEM sectors (on-highway or off-highway) in a cybersecurity role
- Demonstrable experience in product cybersecurity assurance, governance, compliance assessment, or cybersecurity audit for embedded or cyber-physical products
- Strong working knowledge of ISO/SAE 21434 and ISO 24882, with the ability to translate them into practical internal processes and evidence expectations
- Working knowledge of IEC 62443 and supplier assurance requirements
- Familiarity with CRA compliance needs, including defined reporting workflows such as Article 14
- Excellent technical writing, communication, and stakeholder management skills, with the ability to present risk clearly and pragmatically
- Knowledge or experience of TARA and threat modelling approaches, including review of threat artefacts such as attack trees, is a plus
- Background in vulnerability management and post-production monitoring/triage governance is a plus
- Experience in cybersecurity requirements engineering and cybersecurity testing (including test evidence expectations) is a plus
- Awareness of functional safety interfaces and the security-safety relationship is a plus
- Understanding of embedded product environments including ECUs, CAN, J1939, and diagnostics such as UDS is a plus
- Familiarity with SBOM concepts and their role in vulnerability monitoring and compliance evidence is a plus
- Self-motivated, analytical, and pragmatic, with strong interpersonal skills and a collaborative mindset
- Resilient and adaptable, with a drive for continuous improvement and a high standard of technical delivery
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.collegerecruiter.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
DC
Daniel Cranney
7 months ago
BB
Benedikt Bischof
Walking Into The Era of Supply Chain Risks
about 4 years ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
over 2 years ago
DC
Daniel Cranney
How software is steering vehicle technology
over 1 year ago
DC
Daniel Cranney
Understanding and Mitigating Common Web Vulnerabilities
over 1 year ago
LM
Luis Minvielle
The 12 Best Jobs for Software Engineers
over 2 years ago