Cyber Security Specialist

Capgemini
Inverness, UK
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Software System Penetration Testing Cloud Computing Security Cyber Security Disaster Recovery Role-Based Access Control Zero Trust Network Access Software Vulnerability Management Vulnerability Analysis

Job description

The Security TDA, Governance Risk, Compliance and Vulnerability Assessment Lead is responsible for leading governance, risk, compliance, vulnerability management assessment, and security design assurance across a complex, multi-technology environment. The role combines GRC operational leadership with cyber technical design, ensuring security-by-design aligned to ISO 27001, Cyber Essentials Plus and architecture standards., * Security Architecture & Cyber TDA Leadership

  • Act as Cyber Technical Design Authority (TDA) for the account
  • Review and approve solution architectures
  • Define security reference architectures and patterns
  • Lead design governance forums
  • Provide security design sign-off and manage exceptions
  • Embed security-by-design in all solutions
  • Advise on IDAM, network, cloud and infrastructure security

Governance, Risk & Compliance (GRC)

  • Develop and maintain security policies aligned to ISO 27001 and Cyber Essentials Plus
  • Manage Security Risk Register, controls, RACI and RBAC model
  • Lead risk identification, assessment, treatment and reporting
  • Support audits and assurance activities
  • Contribute to Disaster Recovery, Business Continuity and security incident management, covering tracking, remediation, RCA, and reporting
  • Conduct assurance activities to validate control effectiveness
  • Produce regular reporting packs covering risk, compliance, audits, and incidents
  • Provide and update relevant Security Training material for account personnel.

Vulnerability Management

  • Review and triage vulnerability scans and penetration test reports
  • Prioritise vulnerabilities based on risk, impact, and contractual obligations
  • Coordinate remediation across technical teams, ensuring clear ownership and timely closure
  • Track vulnerabilities to distinguish new vs. existing issues
  • Provide remediation guidance and consultancy to stakeholders
  • Deliver reporting on remediation progress for internal and client consumption

Requirements

Do you have experience in NIST standards?, * Strong GRC and risk management experience

  • Familiarity with ISO27001, GDPR, NIST, and ITIL
  • Experience as Security Architect or TDA
  • Knowledge of Zero Trust and cloud security
  • Strong stakeholder communication skills
  • Ability to work in a secure, restricted-access environment

Additional Requirements

  • Based on-site in the Highlands
  • Eligibility for BPSS security clearance

We are a Disability Confident Employer

Capgemini is proud to be a Disability Confident Employer (Level 2) under the UK Government’s Disability Confident scheme. As part of our commitment to inclusive recruitment, we will offer an interview to all candidates who:

  • Declare they have a disability, and Meet the minimum essential criteria for the role. *

Benefits & conditions

Flexibility to work your way You will be encouraged to have a positive work-life balance. Our hybrid-first way of working means we embed hybrid working in all that we do and make flexible working arrangements the day-to-day reality for our people. All UK employees are eligible to request flexible working arrangements.

Your wellbeing You’d be joining an accredited Great Place to work for Wellbeing in 2024. Employee wellbeing is vitally important to us as an organisation. We see a healthy and happy workforce a critical component for us to achieve our organisational ambitions. To help support wellbeing we have trained ‘Mental Health Champions’ across each of our business areas, and we have invested in wellbeing apps such as Thrive and Peppy.

Shape your path You will be empowered to explore, innovate, and progress. You will benefit from Capgemini’s ‘learning for life’ mindset, meaning you will have countless training and development opportunities from thinktanks to hackathons, and access to 250,000 courses with numerous external certifications from AWS, Microsoft, Harvard ManageMentor, Cybersecurity qualifications and much more.

Shared energy You’ll be bringing your unique skills and perspectives to the team, inspiring and taking inspiration from your teammates as you unlock value in everything you do. You’ll be joining a professional community of experts, who have got your back and will support you, every step of the way.

About the company

Growing clients’ businesses while building a more sustainable, more inclusive future is a tough ask. When you join Capgemini, you’ll join a thriving company and become part of a collective of free-thinkers, entrepreneurs and industry experts. We find new ways technology can help us reimagine what’s possible. It’s why, together, we seek out opportunities that will transform the world’s leading businesses, and it’s how you’ll gain the experiences and connections you need to shape your future. By learning from each other every day, sharing knowledge, and always pushing yourself to do better, you’ll build the skills you want. You’ll use your skills to help our clients leverage technology to innovate and grow their business. So, it might not always be easy, but making the world a better place rarely is., Capgemini is an AI-powered global business and technology transformation partner, delivering tangible business value. We imagine the future of organisations and make it real with AI, technology and people. With our strong heritage of nearly 60 years, we are a responsible and diverse group of over 420,000 team members in more than 50 countries. We deliver end-to-end services and solutions with our deep industry expertise and strong partner ecosystem, leveraging our capabilities across strategy, technology, design, engineering and business operations. The Group reported 2025 global revenues of €22.5 billion. Make it real www.capgemini.com

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

2:14 min

Crafting an effective disaster recovery and communication plan

Mihaela-Roxana Ghidersa · LIVE

3:17 min

Embedding automated vulnerability analysis within CircleCI workflows

Milecia Mcgregor · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all