> Markdown version of [/jobs/ext/347756-cyber-security-specialist](https://www.wearedevelopers.com/jobs/ext/347756-cyber-security-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Specialist - **Company:** Capgemini - **Location:** Inverness, UK - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cloud Computing Security, Cyber Security, Disaster Recovery, Role-Based Access Control, Zero Trust Network Access, Software Vulnerability Management, Vulnerability Analysis - **Published:** June 20, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=a6ff433ea372ee0b ## About the Role Do you have experience in NIST standards?, * Strong GRC and risk management experience * Familiarity with ISO27001, GDPR, NIST, and ITIL * Experience as Security Architect or TDA * Knowledge of Zero Trust and cloud security * Strong stakeholder communication skills * Ability to work in a secure, restricted-access environment Additional Requirements * Based on-site in the Highlands * Eligibility for BPSS security clearance We are a Disability Confident Employer Capgemini is proud to be a Disability Confident Employer (Level 2) under the UK Government's Disability Confident scheme. As part of our commitment to inclusive recruitment, we will offer an interview to all candidates who: * Declare they have a disability, and Meet the minimum essential criteria for the role. * ## Description The Security TDA, Governance Risk, Compliance and Vulnerability Assessment Lead is responsible for leading governance, risk, compliance, vulnerability management assessment, and security design assurance across a complex, multi-technology environment. The role combines GRC operational leadership with cyber technical design, ensuring security-by-design aligned to ISO 27001, Cyber Essentials Plus and architecture standards., * Security Architecture & Cyber TDA Leadership * Act as Cyber Technical Design Authority (TDA) for the account * Review and approve solution architectures * Define security reference architectures and patterns * Lead design governance forums * Provide security design sign-off and manage exceptions * Embed security-by-design in all solutions * Advise on IDAM, network, cloud and infrastructure security Governance, Risk & Compliance (GRC) * Develop and maintain security policies aligned to ISO 27001 and Cyber Essentials Plus * Manage Security Risk Register, controls, RACI and RBAC model * Lead risk identification, assessment, treatment and reporting * Support audits and assurance activities * Contribute to Disaster Recovery, Business Continuity and security incident management, covering tracking, remediation, RCA, and reporting * Conduct assurance activities to validate control effectiveness * Produce regular reporting packs covering risk, compliance, audits, and incidents * Provide and update relevant Security Training material for account personnel. Vulnerability Management * Review and triage vulnerability scans and penetration test reports * Prioritise vulnerabilities based on risk, impact, and contractual obligations * Coordinate remediation across technical teams, ensuring clear ownership and timely closure * Track vulnerabilities to distinguish new vs. existing issues * Provide remediation guidance and consultancy to stakeholders * Deliver reporting on remediation progress for internal and client consumption ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Convincing Product teams to Adopt Gitops in a Large Org](https://www.wearedevelopers.com/videos/1936-convincing-product-teams-to-adopt-gitops-in-a-large-org) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) ## Related Articles - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [UK Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/326-uk-business-culture-and-etiquette) - [Best Companies to Work For in The UK: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/186-best-companies-to-work-for-in-the-uk-top-25-companies-in-2023) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Data Engineer Salary UK](https://www.wearedevelopers.com/magazine/253-data-engineer-salary-uk)