Information & Cybersecurity Assurance Manager in Guildford

Information & Cybersecurity Assurance Manager in Guildford

Guildford Full-Time No working from home possible
S

Job Description

Information & Cybersecurity Assurance Manager

/n

/n

Must be able to attain National Security Vetting at SC. DV is desirable, which would require 10 years unbroken residency in the UK.

/n

This is a senior security assurance role within a highly technical and regulated environment, working across cybersecurity, information assurance and Secure by Design.

/n

You'll take ownership of key security workstreams across products, services and major programmes, ensuring security requirements are understood, evidenced and delivered throughout the project lifecycle.

/n

It's a broad role covering security assurance, technical design, certification, risk, penetration testing, supplier security and incident response.

/n

What You'll Be Doing

/n

/n
- Provide assurance against contractual security obligations for product and service deliverables, including ISO 27001, CE+ and DCC.
/n
- Deliver security strategies, policies, management plans, procedures and governance in accordance with relevant frameworks and industry standards.
/n
- Own cybersecurity assurance artefacts and security control requirements across contracted schedules and project milestones.
/n
- Lead certification or contract dependent ITHCs, vulnerability management exercises and external penetration testing, ensuring remediation is completed and verified.
/n
- Review infrastructure, cloud and application designs against Secure by Design principles and perform risk assessments for new technologies and business initiatives.
/n
- Participate in Change Advisory Board (CAB) meetings to provide security assurance.
/n
- Support incident and business continuity response plans and act as part of the incident response team when required.
/n
- Contribute to security working groups, steering boards and Executive and Board level reporting.
/n
- Own Security Aspect Letters and manage third-party supplier security compliance.
/n
- Own security aspects of space licensing throughout the spacecraft lifecycle.
/n
- Manage project-level security budgets and contribute to costing security requirements for future bids.
/n
- Manage security awareness and training in accordance with contractual and certification requirements.
/n

/n

What We're Looking For

/n

This isn't simply an information security governance role. You'll need genuine security assurance experience within defence or a similarly secure environment, with the technical understanding to work effectively with engineering, infrastructure, cloud and security teams.

/n

Essential Requirements

/n

/n
- Either hold, or have held: ChCSP, CISM, CISA, BCS CISMP, or CMIRM certification.
/n
- Membership of a Cybersecurity or Information Risk Management professional body such as, but not limited to, CIISec and IRM.
/n
- Must be able to hold National Security Vetting at SC or above, with a minimum unbroken UK residency of at least 5 years to be eligible to apply for National Security Vetting.
/n

/n

Experience

/n

/n
- Comprehensive and demonstrable experience of working in a Defence Secure by Design programme or project, particularly as a Delivery Team Security Lead, Delivery Team Security Engineer, or Security Assurance Coordinator Role.
/n
- Proven ability to deliver security artefacts including Security Management Plans, Risk Registers and Risk Assessments, Security Requirements Documents, Security Aspects Letters, Threat Models and Vulnerability Assessments, Security Architecture Documents, Compliance & Audit Reports, and Incident & Recovery Plans.
/n
- Experience in the assurance or implementation of information or cybersecurity management systems that have achieved certification to ISO 27001, CE+, or DCC standards.
/n
- Experience facilitating, coordinating and directing ITHCs, including Security Requirements Traceability Matrix or Scoping Documents and prioritisation of remediation effort.
/n
- Proficient technical understanding of information systems at architecture, design and audit level.
/n

/n

Knowledge & Skills

/n

/n
- Strong understanding of information and cybersecurity principles and cybersecurity risk management frameworks.
/n
- Experience delivering and verifying ISO 27001, NIST SP 800-53, CE+, or DCC controls.
/n
- Ability to influence internal stakeholders using data and analysis.
/n
- Able to work independently, follow procedures and recognise appropriate escalation scenarios.
/n
- Good business knowledge with the ability to suggest and analyse "what-if" scenarios.
/n
- Knowledge of the space industry or aerospace communication systems is desirable.
/n
- Must be able to attain National Security Vetting at SC. DV is desirable, which would require 10 years unbroken residency in the UK.
/n

/n

Information & Cybersecurity Assurance Manager in Guildford employer: Standard 8

Join a well-established claimant law firm in the heart of Manchester City Centre, where your role as a Legal Compliance Officer will not only protect the business but also contribute to a culture of proactive risk management. Enjoy a competitive salary, hybrid working options, and a supportive environment that prioritises employee growth through ongoing training and development. With modern offices and a relaxed atmosphere, this is an excellent opportunity for those seeking meaningful and rewarding employment in a dynamic legal setting.

S

Contact Details:

Standard 8 Recruitment Team