Cyber Security Assurance Specialist

Cyber Security Assurance Specialist

Temporary 50000 - 60000 £ / year (est.) Home office (partial)
Public Sector Resourcing, managed by AMS

At a Glance

  • Tasks: Conduct cyber security risk assessments and provide secure-by-design assurance across digital projects.
  • Company: Join UKAEA, a leader in sustainable fusion energy and innovative digital solutions.
  • Benefits: Competitive pay, hybrid work model, and opportunities for professional growth.
  • Why this job: Make a real impact on cyber security in cutting-edge technology environments.
  • Qualifications: Experience in cyber security architecture, risk assessment, and compliance frameworks.
  • Other info: Dynamic role with strong stakeholder engagement and excellent career advancement potential.

The predicted salary is between 50000 - 60000 £ per year.

On behalf of UKAEA (UK Atomic Energy Authority) we are looking for a Cyber Security Assurance Specialist (INSIDE IR35) for an 8-month contract based Hybrid in the Abingdon, Oxford office.

Overall Purpose: UKAEA's mission is to lead the delivery of sustainable fusion energy and maximise scientific and economic impact. The Computing Division underpins this mission by delivering secure, scalable, and innovative digital solutions. The Cyber Security Assurance Specialist plays a pivotal role in advancing UKAEA's hybrid digital estate, encompassing enterprise IT, operational technology (OT), and research platforms. This role sits within the Information & Cyber Security Group and provides subject matter expertise in security architecture, cyber risk governance, and assurance frameworks.

Responsibilities include:

  • Conducting cyber security risk assessments across IT, cloud and OT environments, including the evaluation of significant technical and architectural changes (e.g network reconfiguration and application onboarding).
  • Providing secure-by-design assurance and guidance to digital projects across cloud, infrastructure and application initiatives.
  • Maintaining, updating and governing the cyber security risk register.
  • Representing Cyber Security within governance forums and cyber design / architecture authorities.
  • Leading internal technical assurance reviews aligned to Gov Assure, CAF and ISO 27001, including documentation of evidence gathering and remediation plans.
  • Supporting compliance activities and audit evidence packs for Gov Assure, CAF, Cyber Essentials (CE/CE+) and ISO 27001.
  • Maintaining traceability of security controls to relevant frameworks (e.g NIST, NCSC and Cyber Essentials).
  • Evaluating suppliers and third-party services against internal and external cyber risk and assurance criteria.
  • Developing, updating and maintaining security standards and documentation, including threat modelling, vulnerability management and control guidance.
  • Working with IT and platform teams to co-author, test and maintain secure configuration standards and playbooks (e.g SaaS, Azure services, Entra ID, Linux, Microsoft 365 and OT upgrades).
  • Contributing to the adoption of Zero Trust principles within platform and service design.
  • Producing technical assurance reports, delivering knowledge-sharing sessions, and supporting cyber input across IT, research and OT programmes.

Essential qualifications include:

  • Demonstrable experience reviewing or contributing to secure infrastructure or cloud architecture designs.
  • Proven experience with risk assessment methodologies and maintaining enterprise risk registers.
  • Working knowledge of risk assessment methodologies (e.g. ISO 31000, FAIR, OWASP risk rating).
  • Strong understanding of Gov Assure, CAF, ISO 27001, Cyber Essentials, and NIST frameworks.
  • Experience conducting or supporting security audits and implementing remediation plans.
  • Proficiency in assessing and securing platforms such as Entra ID (Azure AD), Microsoft 365 E5, Azure IaaS/PaaS, Windows/Linux/Unix.
  • Strong knowledge of security tooling such as SIEM, endpoint detection (EDR/XDR), and vulnerability management platforms.
  • Hands-on experience with policy development, access control models (RBAC, ABAC), and logging standards.
  • Experience supporting assurance activities or government-mandated reviews (e.g. GovAssure, Secure by Design).
  • Knowledge of Incident Management, Vulnerability Assessments, SIEM & SOC Systems.
  • Familiarity with ITSM workflows and change control procedures.
  • Experience designing or reviewing secure software supply chain and CI/CD security.
  • Ability to interpret CVEs, CVSS scores, and threat intelligence feeds.
  • Strong stakeholder engagement and communication skills with an ability to produce technical reports and articulate risk to non-specialists.

SC Clearance is an essential requirement for this role, as a minimum you must be willing & eligible to undergo checks. Please note, due to the exceptional requirements of this position (short-term nature of this role and speed at which we require a postholder in situ) preference may be given to candidates who meet all of the essential criteria and hold active security clearance.

Desirable qualifications include:

  • A degree in Cybersecurity, Information Technology, or a STEM subject (or equivalent experience).
  • Security Assurance certifications such as CCP, SIRA.
  • Security certifications such as CISSP, SSCP, CISM, CRISC, CCSP, SABSA, or SANS GIAC (GSEC, GCCC, GCPM).

Cyber Security Assurance Specialist employer: Public Sector Resourcing, managed by AMS

UKAEA is an exceptional employer, offering a dynamic work environment in Abingdon, Oxford, where innovation meets sustainability. As a Cyber Security Assurance Specialist, you will be part of a mission-driven team dedicated to advancing secure digital solutions for fusion energy, with ample opportunities for professional growth and development. The hybrid work model promotes flexibility, while the collaborative culture fosters engagement and knowledge sharing, making it an ideal place for those seeking meaningful and impactful careers in cyber security.
Public Sector Resourcing, managed by AMS

Contact Detail:

Public Sector Resourcing, managed by AMS Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Cyber Security Assurance Specialist

✨Tip Number 1

Network like a pro! Attend industry events, webinars, and meetups to connect with professionals in cyber security. Don't be shy—introduce yourself and chat about your passion for secure systems. You never know who might have the inside scoop on job openings!

✨Tip Number 2

Show off your skills! Create a portfolio showcasing your projects, risk assessments, or any security frameworks you've worked with. This is your chance to demonstrate your expertise in cyber security assurance and make a lasting impression on potential employers.

✨Tip Number 3

Prepare for interviews by brushing up on common questions related to cyber security frameworks like ISO 27001 and Gov Assure. Be ready to discuss your hands-on experience with risk management and vulnerability assessments. Confidence is key, so practice makes perfect!

✨Tip Number 4

Apply through our website! We’ve got loads of opportunities that might just be the perfect fit for you. Plus, applying directly can sometimes give you an edge over other candidates. So, don’t wait—get your application in and let’s secure the future together!

We think you need these skills to ace Cyber Security Assurance Specialist

Cyber Security Risk Assessments
Security Architecture
Risk Management
Vulnerability Management
ISO 27001
Gov Assure
Cyber Essentials
NIST Frameworks
Technical Assurance Reviews
Secure-by-Design Principles
Stakeholder Engagement
Communication Skills
Security Tooling (SIEM, EDR/XDR)
Policy Development
Incident Management

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the Cyber Security Assurance Specialist role. Highlight relevant experience and skills that match the job description, especially around risk assessments and security frameworks.

Craft a Compelling Cover Letter: Your cover letter should tell us why you're the perfect fit for this role. Share specific examples of your past work in cyber security and how it aligns with UKAEA's mission and values.

Showcase Your Technical Skills: Don’t forget to mention your hands-on experience with security tools and methodologies. We want to see your proficiency in areas like SIEM, vulnerability management, and secure architecture design.

Apply Through Our Website: For the best chance of success, apply directly through our website. This ensures your application gets to the right people quickly and efficiently, so we can start reviewing your awesome qualifications!

How to prepare for a job interview at Public Sector Resourcing, managed by AMS

✨Know Your Cyber Security Frameworks

Familiarise yourself with key frameworks like Gov Assure, CAF, ISO 27001, and Cyber Essentials. Be ready to discuss how you've applied these in past roles, as this will show your understanding of the standards UKAEA expects.

✨Demonstrate Risk Assessment Skills

Prepare to talk about your experience with risk assessment methodologies such as ISO 31000 or FAIR. Have specific examples ready where you conducted assessments or maintained risk registers, as this is crucial for the role.

✨Showcase Technical Proficiency

Brush up on your knowledge of security tooling like SIEM and vulnerability management platforms. Be prepared to discuss your hands-on experience with platforms like Azure and Microsoft 365, as technical depth is essential for this position.

✨Engage Stakeholders Effectively

Highlight your communication skills by preparing examples of how you've engaged with stakeholders in previous roles. Being able to articulate complex cyber security concepts to non-specialists will be a big plus during your interview.

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>