Security Assurance Lead

Security Assurance Lead

Full-Time 63000 - 77000 £ / year (est.) Home office (partial)
M

At a Glance

  • Tasks: Lead security initiatives and provide consultancy for tech projects in a dynamic environment.
  • Company: Join a forward-thinking organisation focused on sustainability and innovation.
  • Benefits: Enjoy competitive pay, flexible working options, and opportunities for professional growth.
  • Other info: Collaborative culture with opportunities to mentor and develop your skills.
  • Why this job: Make a real impact by embedding security in cutting-edge technology solutions.
  • Qualifications: Experience in cyber security and strong communication skills are essential.

The predicted salary is between 63000 - 77000 £ per year.

Reporting to the Application Security Team Lead and Programme Manager for Sustainability & Business Change (SBC), the Security & Governance Engineer will act as the embedded security contact for the SBC programme, working closely with delivery squads to embed security throughout the design, implementation and operation of technology.

Alongside this core responsibility, you'll support the wider Security Engineering function, helping mature how Information Security engages with delivery teams across Motability Operations.

As part of the Information Security function, you'll be the primary security contact for a portfolio of initiatives across the SBC programme.

You'll provide practical, risk based security guidance that supports programme delivery, helping assess incoming requests, understand its security risk and determine the appropriate level of security engagement and assurance.

Working alongside business analysts, architects, product owners, delivery managers and engineering teams, you'll help define security requirements, influence solution design and make sure security is considered at the right stages of the delivery lifecycle.

The role sits within the Application Security team, which forms part of a wider Information Security function of around 40 security professionals.

You'll work closely with specialists across Application Security, Security Operations, Identity, IT Continuity, Security Architecture and Cloud Security, recognising when specialist expertise is required and bringing the right teams into delivery at the right time.

You'll help teams navigate Information Security effectively while building strong relationships across the business.

You'll also play a role in operating and maturing the Information Security Front Door capability, helping teams engage with Information Security consistently and at the right point in delivery.

You'll help assess incoming demand, understand the level of security risk and coordinate the right level of assurance and specialist support, creating a straightforward and proportionate experience for teams seeking security guidance.

Although security consultancy is at the heart of the role, you'll remain technically engaged throughout delivery.

You'll work alongside engineering teams to understand solutions, identify security risks, support threat modelling and design reviews, and provide practical guidance that helps teams build securely.

Where deeper specialist knowledge is required, you'll work with colleagues across Information Security to bring the right expertise into delivery.

It's well suited to someone who enjoys influencing outcomes through consultancy while remaining close to the technology and the teams building it.

Success in the role will be reflected in the quality of security engagement across the SBC programme, the maturity of the Information Security Front Door, and the consistent application of proportionate, risk based security assurance.

You'll help improve threat modelling and security review practices, ensure security risks are clearly understood and prioritised, and help delivery teams access the right Information Security expertise when they need it.

As the capability grows, you'll also have opportunities to mentor colleagues and contribute to the continued development of our Application Security operating model.

  • Act as the primary Information Security point of contact for a portfolio of projects within the Sustainability & Business Change Programme (SBC), providing security consultancy that enables successful business delivery & security governance.
  • Build trusted relationships with stakeholders across Technology and the wider business, offering clear, risk based security advice throughout the project lifecycle.
  • Support Business Analysts and delivery teams in defining security activities, identifying security requirements and embedding Secure by Design principles from the earliest stages of delivery.
  • Operate and continue improving the Information Security Front Door, helping establish a consistent and effective engagement model for accessing security services across the organisation.
  • Facilitate threat modelling workshops, produce Data Flow Diagrams (DFDs) and carry out structured threat assessments using the STRIDE methodology.
  • Conduct security assurance activities across new and existing services, including architecture and design reviews, configuration assessments, security hardening reviews and production security assessments.
  • Prioritising, designing and then resolving the findings of threat models and security assurance assessments.
  • Coordinate penetration testing activities, review findings with technical teams and ensure remediation plans are agreed, prioritised and tracked.
  • Assess implementation plans, technical designs and solution architectures, providing practical recommendations that balance security, delivery and operational requirements.
  • Work with App Sec, Cloud Sec, platform engineering and delivery teams where initiatives impact products, AWS, Azure services, helping identify app and cloud security considerations and ensuring specialist expertise is engaged where required.
  • Collaborate with Security Operations, Identity, IT Continuity and other Information Security teams to deliver consistent security outcomes across programmes and operational services.
  • Identify, assess and prioritise security risks arising from reviews, threat modelling and assurance activities, ensuring they are managed appropriately through to resolution.
  • Promote security awareness and encourage secure engineering practices, helping delivery teams understand security requirements without creating unnecessary barriers.
  • Contribute to the ongoing improvement of security standards, patterns, guidance and processes, ensuring they remain aligned with industry best practice and organisational objectives.
  • Mentor colleagues where appropriate and help improve the wider Security Business Consulting capability.

About You

You're an experienced cyber security professional who enjoys working with people as much as solving technical problems.

You understand that effective security comes from collaboration, helping delivery teams build secure solutions rather than acting as a gatekeeper.

You're comfortable working with both technical and non-technical stakeholders, translating complex security concepts into clear, practical advice that supports informed decision making.

You have a strong consulting mindset and are comfortable managing multiple initiatives at the same time, balancing business priorities with security risk.

Alongside your consultancy skills, you enjoy staying technically involved and taking opportunities to design and implement security improvements where they make a real difference.

You're naturally curious, collaborative and always looking for ways to improve how security is delivered across the organisation.

You’ll need all of these.

  • Proven experience working in cyber security, with experience in security consulting, application security, product security or security engineering.
  • Experience partnering with delivery teams to provide security guidance throughout project and programme lifecycles.
  • Excellent communication and stakeholder management skills, with the ability to build credibility and influence both technical and business audiences at all levels.
  • The ability to balance competing priorities while working across multiple projects and initiatives.
  • Experience conducting threat modelling, producing Data Flow iagrams and applying methodologies such as STRIDE.
  • Experience carrying out security assurance activities, including solution reviews, security assessments, configuration reviews and security hardening.
  • Experience coordinating penetration testing activities and managing the remediation of identified vulnerabilities.
  • A good understanding of Secure by Design principles and the ability to apply them throughout solution delivery.
  • Experience identifying, assessing and prioritising security risks, providing pragmatic recommendations that align with business objectives and the organisation's risk appetite.
  • Good working knowledge of recognised security frameworks and standards such as NIST or ISO27001, along with industry best practice.
  • Experience working with cloud technologies, particularly AWS and Azure, and a good understanding of cloud native security controls and services.
  • Experience working alongside engineering teams to design and implement security controls and improvements across applications, infrastructure and cloud environments.
  • An understanding of CI/CD pipelines, secure software delivery practices and modern application Œment approaches.
  • A collaborative approach and a “can-do” attitude with a willingness to share knowledge, mentor colleagues and contribute to the continual improvement of the Information Security function.
  • A recognised security certification such as CISSP would be advantageous, although equivalent experience and a commitment to continued professional development are equally valued.
  • #J-18808-Ljbffr

Security Assurance Lead employer: Motability Operations Ltd

Motability Operations is an exceptional employer that prioritises employee growth and development, particularly in the Talent Acquisition Lead role. With a strong focus on building capability within a supportive team environment, employees benefit from structured career progression, comprehensive training, and the opportunity to influence strategic hiring practices. Located in a dynamic setting, the company fosters a culture of inclusivity and collaboration, ensuring that every team member plays a vital role in enhancing the recruitment experience for both candidates and hiring managers.

M

Contact Details:

Motability Operations Ltd Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Security Assurance Lead

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Motability Operations Ltd, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Motability Operations Ltd

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Motability Operations Ltd. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Security Assurance Lead

Cyber Security
Security Consulting
Application Security
Product Security
Security Engineering
Threat Modelling
Data Flow Diagrams (DFDs)

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Motability Operations Ltd insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Motability Operations Ltd that you’re committed to staying ahead in the game.

How to prepare for a job interview at Motability Operations Ltd

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Motability Operations Ltd to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Motability Operations Ltd.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.