At a Glance
- Tasks: Lead cybersecurity assurance projects and ensure compliance with industry standards.
- Company: Join a leading aerospace company focused on innovative security solutions.
- Benefits: Competitive salary, professional development, and opportunities for career advancement.
- Other info: Dynamic work environment with a focus on collaboration and innovation.
- Why this job: Make a real impact in cybersecurity while working on exciting space projects.
- Qualifications: Relevant cybersecurity certifications and experience in secure design programmes.
The predicted salary is between 58500 - 71500 £ per year.
Responsible for executing a range of cybersecurity and information assurance workstreams that contribute to the overall cybersecurity profile of SSTL, including product and service development. Owning the assurance of SSTL information and cybersecurity certifications, contracted information and cybersecurity deliverables, and delivery of Secure by Design in SSTL.
Reports To: Corporate Security Manager
Key Tasks:
- Identify, understand, and provide assurance against all elements of contractual security obligations for product and service deliverables, as well as information and cybersecurity certifications such as ISO 27001, CE+, and DCC.
- Ensure the delivery of relevant technical, framework and contract compliant governance, security strategies, policies, management plans, procedures, and processes, as well as supporting the review of organisational security governance in accordance with industry standards.
- Own the management of information and cybersecurity assurance artefacts and security control requirements against all contracted schedules, ensuring project lifecycle gateway and milestone success.
- Lead the facilitation of certification or contract dependent ITHCs, coordinate vulnerability management exercises and external penetration testing and ensure remediation actions are completed and verified.
- Review infrastructure, cloud, and application designs and current implementations against Secure by Design principles and perform risk assessments for new technologies and business initiatives, as well as participate in Change Advisory Board (CAB) meetings to provide security assurance.
- Support the implementation, delivery, and exercising of incident and business continuity response plans, and contribute to the lessons identified process.
- Act as a member of the incident response team in the event of a security incident.
- Contribute to security working groups, security steering boards, Executive and Board level reports, and any other management material as required.
- Own the management of Security Aspect Letters, compliance with them, and the creation of any flow down variations to suppliers and own the management and monitoring of third-party supplier compliance.
- Own the security aspects of space licensing, ensuring all requirements are complete to facilitate the effective delivery and operation of spacecraft throughout their lifecycle.
- Accountable for the management of project level security budget, and contribute to accurate costing of project level security effort on future bids.
- Monitor and manage the delivery of security awareness and training in accordance with contractual or certification requirements.
Success Criteria:
- All security aspects of contractual deliverables are successfully delivered in accordance with customer requirements and within timelines and budget.
- A portfolio of template Secure by Design security artefacts is made available for future use.
- Information and cybersecurity certification is successfully renewed on time without breaks.
- Space licensing for existing and new spacecraft is not delayed or hindered due to Security input.
- Established processes or methodologies, and compliance for technical and cybersecurity infrastructure.
PERSON SPECIFICATION (essential requirements)
Qualifications:
- Either hold, or have held: ChCSP, CISM, CISA, BCS CISMP, or CMIRM certification.
- Membership of a Cybersecurity or Information Risk Management professional body such as, but not limited to, CIISec and IRM.
- Must be able to hold National Security Vetting at SC or above, with a minimum unbroken UK residency of at least 5 years to be eligible to apply for National Security Vetting.
Experience:
- Comprehensive and demonstrable experience of working in a Defence Secure by Design programme or project, particularly as a Delivery Team Security Lead, Delivery Team Security Engineer, or Security Assurance Coordinator Role.
- Proven ability to deliver security artefacts such as, but not limited to, Security Management Plans, Risk Registers and Risk Assessments, Security Requirements Documents, Security Aspects Letters, Threat Models and Vulnerability Assessments, Security Architecture Documents, Compliance & Audit Reports, and Incident & Recovery Plans.
- Experience in the assurance or implementation of information or cybersecurity management systems that have achieved certification to ISO 27001, CE+, or DCC standards.
- Experience in facilitating, coordinating, and directing ITHCs including, but not limited to, the writing of Security Requirements Traceability Matrix or Scoping Document, as well as the prioritisation of remediation effort.
- Proficient technical understanding of information systems at an architecture, design, and audit level.
Knowledge & Skills:
- Proven understanding of information and cybersecurity principles, cybersecurity risk management frameworks, and the delivery and verification of ISO 27001, NIST SP 800-53, CE+, or DCC controls.
- Ability to influence internal stakeholders, using data and analysis to support reasoning.
- Can work independently, in compliance with procedures, and be able to recognise appropriate escalation scenarios.
- Good business knowledge to suggest and analyse “what-if” scenarios.
- Knowledge of space industry or aerospace communication systems is desirable.
- Must be able to attain National Security Vetting at SC but DV is desirable which would require 10 years unbroken residency in the UK.
Information & Cybersecurity Assurance Manager in Guildford employer: Surrey Satellite Technology
As an AIT Integration Engineer with us, you'll be part of a dynamic team dedicated to advancing space exploration. We pride ourselves on fostering a collaborative work culture that values innovation and professional growth, offering opportunities for training and development while working in a state-of-the-art cleanroom environment. Located in a vibrant area, our company not only supports your career aspirations but also encourages a healthy work-life balance, making it an excellent place for those seeking meaningful and rewarding employment.
Contact Details:
Surrey Satellite Technology Recruitment Team
StudySmarter Expert Advice🤫
We think this is how you could land Information & Cybersecurity Assurance Manager in Guildford
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Surrey Satellite Technology, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Surrey Satellite Technology
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Surrey Satellite Technology. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Information & Cybersecurity Assurance Manager in Guildford
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Surrey Satellite Technology insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Surrey Satellite Technology that you’re committed to staying ahead in the game.
How to prepare for a job interview at Surrey Satellite Technology
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Surrey Satellite Technology to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Surrey Satellite Technology.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.