At a Glance
- Tasks: Conduct risk assessments and provide secure design guidance for digital projects.
- Company: Join a government client focused on cyber security assurance.
- Benefits: Competitive hourly rate, hybrid work model, and potential contract extension.
- Other info: Opportunity for career growth in a dynamic and supportive environment.
- Why this job: Make a real impact in cyber security while working with cutting-edge technologies.
- Qualifications: Experience in secure infrastructure design and risk assessment methodologies required.
The predicted salary is between 45 - 55 £ per hour.
We are currently looking for a Cyber Security Assurance Specialist for our government client. This role is hybrid, based between working 3 days per week on site in Abingdon Oxfordshire and the remainder of the week working remotely. There is no further flexibility with the on-site requirement. The contract for this position is until December 2026, with potential to extend, operating inside IR35.
Security Clearance: eligible for Security Check ("SC Clearance")
Essential skills/experience required:
- Demonstrable experience in designing and implementing secure infrastructure or cloud architectures.
- Proven experience with risk assessment methodologies and maintaining enterprise risk registers.
- Working knowledge of risk assessment methodologies (e.g. ISO 31000, FAIR, OWASP risk rating).
- Strong understanding of Gov Assure, CAF, ISO 27001, Cyber Essentials, and NIST frameworks.
- Experience conducting or supporting security audits and implementing remediation plans.
- Proficiency in assessing and securing platforms such as Entra ID (Azure AD), Microsoft 365 E5, Azure IaaS/PaaS, Windows/Linux/Unix.
- Strong knowledge of security tooling such as SIEM, endpoint detection (EDR/XDR), and vulnerability management platforms.
- Hands-on experience with policy development, access control models and logging standards.
- Experience supporting assurance activities or government-mandated reviews (e.g. GovAssure, Secure by Design).
- Knowledge of Incident Management, Vulnerability Assessments, SIEM & SOC Systems.
- Familiarity with ITSM workflows and change control procedures.
- Experience designing or reviewing secure software supply chain and CI/CD security.
- Ability to interpret CVEs, CVSS scores, and threat intelligence feeds.
- Strong stakeholder engagement and communication skills with an ability to produce technical reports and articulate risk to non-specialists.
- Excellent written and verbal communication skills with the ability to present to senior stakeholders.
Role / Responsibilities:
- Conduct technical risk assessments on IT/OT/cloud systems.
- Provide secure design guidance to digital projects (cloud/infra/app).
- Maintain and update the security risk register quarterly.
- Evaluate 2 critical technical changes for architectural risk (e.g., network reconfig, app onboarding).
- Document evidence gathering and remediation planning for Secure-by-design, CAF and GovAssure.
- Conduct internal technical assurance reviews aligned to GovAssure/CAF/ISO27001 domains.
- Maintain traceability of security controls to frameworks (NIST, CE+, NCSC).
- Evaluate Suppliers against internal and external risk criteria for Assurance.
- Contribute to the adoption of Zero Trust principles in platform design.
- Provide secure-by-design input into infrastructure/cloud/app initiatives.
- Define security control templates for new deployments (e.g., SaaS, Azure service, OT upgrade).
- Deliver knowledge sessions to technical teams (secure config, threats, compliance).
- Develop secure configuration guidance for platforms (e.g. Entra ID, Linux, M365).
- Represent Cyber Security in architecture/design authorities.
- Produce and maintain technical security reports for assurance cycles.
- Support compliance audit evidence packs (GovAssure/CAF, CE+, ISO 27001).
- Develop or update security standard documents (e.g. threat modelling, vulnerability mgmt).
- Support cyber input for IT, research or OT programmes.
- Work with IT teams to co-author and test secure configuration standards and playbooks.
- Support security policy application in hybrid cloud, infra, and app settings.
- Support audit and compliance activities with reporting and evidence gathering.
If you are interested in the above role, please click Apply Now and send a CV for quick review. Should you require reasonable adjustments at any point during the recruitment process or if there is a better way for us to communicate, please do let us know.
Cyber Security Assurance Specialist in Oxford employer: Circle Recruitment
Contact Detail:
Circle Recruitment Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Cyber Security Assurance Specialist in Oxford
✨Tip Number 1
Network like a pro! Reach out to your connections in the cyber security field, attend industry events, and join relevant online forums. The more people you know, the better your chances of landing that Cyber Security Assurance Specialist role.
✨Tip Number 2
Show off your skills! Prepare a portfolio or case studies showcasing your experience with risk assessments and secure infrastructure designs. This will help you stand out during interviews and demonstrate your expertise.
✨Tip Number 3
Practice makes perfect! Conduct mock interviews with friends or use online platforms to refine your responses. Focus on articulating your knowledge of frameworks like ISO 27001 and NIST, as well as your experience with security audits.
✨Tip Number 4
Apply through our website! We make it easy for you to submit your application directly, ensuring it gets the attention it deserves. Plus, keep an eye on our job board for new opportunities that match your skills.
We think you need these skills to ace Cyber Security Assurance Specialist in Oxford
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Cyber Security Assurance Specialist role. Highlight your experience with risk assessment methodologies and security frameworks like ISO 27001 and NIST. We want to see how your skills match what we're looking for!
Showcase Your Experience: When writing your application, don't just list your skills—show us how you've used them in real-world scenarios. Talk about specific projects where you designed secure infrastructures or conducted security audits. This helps us see your practical experience.
Be Clear and Concise: We appreciate clarity! Use straightforward language and avoid jargon where possible. Make it easy for us to understand your qualifications and experiences. Remember, we want to know how you can contribute to our team!
Apply Through Our Website: Don't forget to apply through our website! It’s the quickest way for us to review your application. Plus, if you have any questions or need adjustments during the process, reaching out through our site makes it easier for us to help you.
How to prepare for a job interview at Circle Recruitment
✨Know Your Frameworks
Make sure you brush up on the key frameworks mentioned in the job description, like ISO 27001 and NIST. Being able to discuss how you've applied these in past roles will show your expertise and understanding of the field.
✨Prepare for Technical Questions
Expect to dive deep into technical discussions about risk assessment methodologies and secure infrastructure design. Practise explaining complex concepts in simple terms, as you'll need to communicate effectively with non-specialists.
✨Showcase Your Stakeholder Engagement Skills
Highlight your experience in engaging with stakeholders and producing technical reports. Be ready to share examples of how you've communicated risks and security measures to different audiences, especially senior stakeholders.
✨Demonstrate Your Hands-On Experience
Be prepared to discuss your hands-on experience with security tooling and incident management. Share specific examples of how you've implemented security measures or conducted audits, as this will demonstrate your practical knowledge and problem-solving skills.