At a Glance
- Tasks: Lead a team ensuring cloud security and compliance for secure networks.
- Company: Dynamic organisation focused on cyber security within the UK MOD environment.
- Benefits: Competitive daily rate, flexible working, and opportunities for professional growth.
- Other info: Inclusive workplace valuing diversity and offering support throughout the recruitment process.
- Why this job: Make a real impact in cyber security while working with cutting-edge technologies.
- Qualifications: Experience in cyber security and familiarity with UK MOD standards required.
The predicted salary is between 58500 - 71500 £ per year.
Office Location: Flexible within UK offices
Start Date: ASAP
End Date: 12 - 18 months from start
Pay rate per day: £550 - £680 Inside IR35
Hours per week: 37.5
Active SC Clearance Required
Job Description:
- Oversee and guide a team of consultants from the UK business who are fulfilling our cloud security assurance process for non-core cloud systems.
- Maintain and implement our overall Secure Networks Security Assurance framework, including creation of protocols and processes as required.
- Maintain our secure network approvals including risk assessments, security arguments, and compliance statements against the DCPP Cyber Security Model (plus against other standards and control sets as required).
- Carry out and maintain security assessments for core Secure Networks cloud systems such as Microsoft 365.
- Oversee Secure Networks elements of broader company certification to the Defence Cyber Certification.
- Carry out compliance audits to ensure that the Secure Networks Team, local security contacts, and project teams are carrying out required assurance activities, both in our secure networks and for cloud systems.
- Stay up to date with MOD and other regulatory guidance, and relevant commercial standards such as Microsoft 365 guidance, and incorporate the results into our Secure Networks security assurance approaches.
- Provide security assurance guidance to the Secure Networks Team to review and influence the design and operation of our secure networks.
- Periodically update the risk assessments for our secure networks, communicate implications to relevant stakeholders, and track progress against action items.
- Stay up to date with the threat landscape affecting our secure networks, using a range of sources such as the corporate Threat Intelligence team.
- Track progress made by a range of parties against security action plans.
- Collaborate with, learn from and advise relevant internal stakeholders such as Global Security, Security Points of Contact, the Secure Networks Team, the UK business security managers, Security Controllers, corporate and UK project procurement, HR Vetting, project teams, and individual staff members seeking guidance e.g. for overseas working.
- Liaise with relevant external stakeholders such as MOD CyDR.
- Annually revise and reissue Security Operating Procedures for our secure networks and core Secure Networks cloud systems.
- Support external security-related audits such as ISO27001 and by clients including MOD.
- Oversee authorisations of third parties who will handle information from our secure networks or connect in to them, including both initial approval and ongoing maintenance.
- Assess devices that require connection to our secure networks, for example point cloud scanners.
- Maintain a co-ordinated programme for all security assurance activities to ensure they are delivered in a timely manner.
- Arrange, report to, and provide advice and recommendations to Secure Networks Governance Committee meetings.
- Report into the Office of the Chief Information Security Officer to provide confidence to them that our UK Secure Networks have adequate security assurance.
- Carry out security assurance for key elements of the Secure Networks supply chain (hardware, software, services).
- Create and maintain infrastructure required to move the Security Assurance function from being an individual contact to a comprehensive standalone function, for example a group mailbox, a Team, communications methods, and site(s) for publication of Security Assurance policies, trackers, etc.
Required Skills & Qualifications:
- A 'completer finisher', with an eye for detail.
- Demonstrable experience of working in cyber security in a UK MOD-related environment.
- Strong familiarity with UK MOD security standards such as Def Stan 05-138 versions 3 and 4, the Cyber Security Model, Secure By Design, Industry Security Notices.
- Strong familiarity with UK Government security standards such as 007/SPF, NCSC Cloud Security Principles, NCSC Principles for Using Software as a Service (SaaS) securely, Cyber Essentials, and the CHECK penetration testing scheme.
- Broad familiarity with UK Government physical and personnel security such as NPSA and UKSV.
- Risk assessment using recognised standards such as IS1 and NIST SP800-30.
- Able to express yourself effectively, with a high degree of clarity, in English, especially when justifying and explaining required security measures.
- Able to liaise effectively with a wide range of stakeholders, from senior leaders to technical IT staff.
- Able to prioritise and manage your time to achieve multiple different tasks.
- (Desirable) Familiarity with broader international security standards such as ISO27001, CMMC, and the NIST Cyber Security Framework (especially SP800-30 and SP800-53).
- (Desirable) Familiarity with UK nuclear regulations such as the ONR SyAPs.
- Competent with Microsoft Word, Excel and PowerPoint.
Reasonable Adjustments:
Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients. If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.
Security Assurance Manager employer: Sanderson Government & Defence
As a Python Developer at our company, you will thrive in a dynamic and inclusive work environment that values diversity and fosters collaboration. We offer competitive benefits, opportunities for professional growth, and a culture that encourages innovation and autonomy, all while being part of a team dedicated to delivering exceptional resourcing solutions. Join us in a location that not only supports your career aspirations but also champions respect and equality for all employees.
Contact Details:
Sanderson Government & Defence Recruitment Team
StudySmarter Expert Advice🤫
We think this is how you could land Security Assurance Manager
✨Get Engaged in Cybersecurity Communities
Dive into online forums or local meetups, like OWASP events or Cybersecurity conferences. These spaces are packed with pros who can share insights and might even know about temporary roles at places like Sanderson Government & Defence.
✨Showcase Your Skills Publicly
Link your GitHub or create a series of blogs sharing your knowledge on cybersecurity topics. It’s a great way to demonstrate your expertise and attract attention from hiring managers, especially when they see your passion in action.
✨Stay On Top of Temp Opportunities
Keep an eye on platforms that list temporary positions specifically in tech. Websites focusing on contract roles in cybersecurity can lead straight to employers like Sanderson Government & Defence.
✨Make Contact with Recruiters Specialising in Cybersecurity
Reach out to recruitment agencies that focus on cybersecurity roles. They often have insights into temporary roles before they’re advertised and can put your name forward to companies like Sanderson Government & Defence.
We think you need these skills to ace Security Assurance Manager
Some tips for your application 🫡
Show Off Your Technical Skills:In cybersecurity, it's vital to highlight your skills with relevant tools and technologies. Make sure your CV showcases your experience with firewalls, intrusion detection systems, and any cybersecurity frameworks you've worked with. This gives Sanderson Government & Defence a clear view of your capabilities right off the bat.
Certifications Matter:If you’ve got any cybersecurity certifications, like CompTIA Security+ or CISSP, flaunt them! These not only validate your skills but also show that you’re committed to the field. Add a section to your CV specifically for this, because in a temporary role like this, those credentials can really set you apart.
Tailor Your Cover Letter to the Role:For a temporary position, we want to see your willingness to learn and adapt quickly. Make your cover letter specific to the role at Sanderson Government & Defence; mention why you’re excited about the opportunity and how it fits your career goals. A personal touch can make a big difference!
Don’t Forget the Soft Skills:In cybersecurity, technical skills are crucial, but so are soft skills like teamwork and communication. Make sure to weave examples of how you've collaborated with teams or communicated complex ideas into your application. This shows that you're not just a tech whizz but also a great team player, perfect for a temporary role at Sanderson Government & Defence.
How to prepare for a job interview at Sanderson Government & Defence
✨Brush Up on Technical Skills
Make sure you’re familiar with the latest cybersecurity tools and techniques, like firewalls, intrusion detection systems, and malware analysis. During the interview with Sanderson Government & Defence for the Security Assurance Manager, be prepared to discuss specific scenarios where you tackled security threats or vulnerabilities.
✨Show Your Problem-Solving Prowess
Cybersecurity is all about thinking on your feet. Expect technical questions that require you to demonstrate your problem-solving abilities. You might be presented with a mock security breach scenario, so practising your responses to potential threats can be a game changer!
✨Demonstrate Your Adaptability
As this is a temporary role, showing that you're adaptable and quick to learn is crucial. Talk about times you've picked up new skills or reacted to changing situations quickly. Employers want to know you can hit the ground running and keep things secure during your short stay at Sanderson Government & Defence.
✨Bring Relevant Certifications
If you have any relevant cybersecurity certifications, like CompTIA Security+ or CEH, be sure to mention them. This can really help you stand out during a temporary hiring process, as it showcases your commitment to the field and your readiness to take on the Security Assurance Manager role at Sanderson Government & Defence.