This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
To lead the organisation’s security assurance and standards capability. The role ensures that security controls are evidence‑led, audit‑ready and credible for customers and defence work, including Cyber Essentials Plus, IASME Defence Cyber Certification (DCC) and MoD supply‑chain requirements. The post holder will also strengthen network security capability across the function. To support the creation of security related policy, aligned with regulatory adherence, and assure the technical aspects of information protection and compliance.
Job Responsibility:
Own the interpretation and day‑to‑day operation of relevant standards and assurance frameworks (Defence, CE/CE+)
Maintain an evidence library and control narratives suitable for customer audits and formal assessments
Lead responses to customer security audit requests and new business Security Assurance Questionnaires (SAQs), working closely with technical colleagues
Strengthen the organisation’s network security assurance capability: challenge designs, validate controls, and support secure integration into enterprise facilities
Coordinate internal assurance activities supporting annual Cyber Essentials Plus including readiness reviews, remediation tracking and evidence pack quality
Support incident response governance: ensure playbooks, communications templates and post‑incident learning are maintained
Contribute to the cyber security communications channel: support awareness campaigns, targeted briefings and lessons‑learned messaging
Support the maintenance of ITSM, and address security governance and design related tickets
Play an active role in maintaining & contributing to Security related Dev Ops
Requirements:
Proven experience in information security assurance, governance or audit‑facing security roles
Strong understanding of network security principles and the ability to challenge and validate technical designs
Led enterprise classification approach, technically and assured