> Markdown version of [/jobs/ext/2304035-cybersecurity-governance-assurance-specialist](https://www.wearedevelopers.com/jobs/ext/2304035-cybersecurity-governance-assurance-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Governance & Assurance Specialist - **Company:** Amaris GROUP SA - **Location:** Greater London, UK - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Cyber Security, Embedded Software, Red Team (Cyber Security), Verification and Validation (Software), Software Vulnerability Management - **Published:** August 30, 2026 - **Apply:** https://www.collegerecruiter.com/job/2815462169-cybersecurity-governance--assurance-specialist ## About the Role * 3+ years of experience within Tier 1 or OEM sectors (on-highway or off-highway) in a cybersecurity role * Demonstrable experience in product cybersecurity assurance, governance, compliance assessment, or cybersecurity audit for embedded or cyber-physical products * Strong working knowledge of ISO/SAE 21434 and ISO 24882, with the ability to translate them into practical internal processes and evidence expectations * Working knowledge of IEC 62443 and supplier assurance requirements * Familiarity with CRA compliance needs, including defined reporting workflows such as Article 14 * Excellent technical writing, communication, and stakeholder management skills, with the ability to present risk clearly and pragmatically * Knowledge or experience of TARA and threat modelling approaches, including review of threat artefacts such as attack trees, is a plus * Background in vulnerability management and post-production monitoring/triage governance is a plus * Experience in cybersecurity requirements engineering and cybersecurity testing (including test evidence expectations) is a plus * Awareness of functional safety interfaces and the security-safety relationship is a plus * Understanding of embedded product environments including ECUs, CAN, J1939, and diagnostics such as UDS is a plus * Familiarity with SBOM concepts and their role in vulnerability monitoring and compliance evidence is a plus * Self-motivated, analytical, and pragmatic, with strong interpersonal skills and a collaborative mindset * Resilient and adaptable, with a drive for continuous improvement and a high standard of technical delivery ## Description * Own and maintain the product cybersecurity governance and assurance framework, aligned with the broader compliance model used across disciplines * Develop and maintain internal standards, templates, checklists, and guidance to enable consistent execution across programmes (e.g., System of Interest definitions, TARA guidance, cybersecurity requirements, testing expectations, and evidence packs) * Create and deliver training and enablement programmes to uplift engineering teams and drive "right first time" compliance Programme Compliance Assessment and Assurance * Plan and execute cybersecurity compliance assessments of product programmes and suppliers, reporting status, risks, and evidence gaps clearly and early * Assess alignment against internal requirements and relevant external standards and regulations, including ISO/SAE 21434, ISO 24882, IEC 62443, and the Cyber Resilience Act (CRA) * Review the adequacy of key cybersecurity work products such as threat modelling/TARA outputs, requirements, architecture evidence, verification and validation strategies, and residual risk statements * Drive closure of findings with stakeholders across systems, embedded software, verification, manufacturing/service, and suppliers Cybersecurity Testing Assurance * Define cybersecurity testing expectations required for compliance evidence, covering coverage scope, methods, reporting, and remediation tracking * Coordinate Red Team and testing activities to ensure outputs support programme assurance and close testing capability gaps, * Establish and assure governance for post-production vulnerability management, including monitoring from suppliers, research findings, Red Team outputs, and PSIRT channels, and routing to affected products * Support readiness for CRA mandatory reporting, including Article 14 reporting workflows and fast-track response for actively exploitable issues * Capture and disseminate lessons learned (e.g., CWE/CVE insights) back into standards, checklists, and training materials ## Related Videos - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Introduction to Responsible AI: Balancing Value and Risk](https://www.wearedevelopers.com/videos/1972-introduction-to-responsible-ai-balancing-value-and-risk) - [Building a hypercar from scratch](https://www.wearedevelopers.com/videos/607-building-a-hypercar-from-scratch) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How software is steering vehicle technology](https://www.wearedevelopers.com/magazine/515-how-software-is-steering-vehicle-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)