At a Glance
- Tasks: Lead a team to enhance cyber security across all IT systems and infrastructure.
- Company: Join a forward-thinking organisation dedicated to protecting data and systems.
- Benefits: Competitive salary, professional development, and a chance to shape security strategies.
- Other info: Dynamic work environment with opportunities for continuous improvement and growth.
- Why this job: Make a real impact in cyber security while advancing your career in a managerial role.
- Qualifications: Degree in Computing and experience in IT security leadership required.
The predicted salary is between 63000 - 77000 £ per year.
Must be able to obtain SC Clearance.
We are seeking an experienced, hands‑on IT Security Manager to lead a small in‑house team responsible for strengthening and maintaining the organisation’s cyber security posture across all IT systems, services and infrastructure. You will manage the implementation of security controls, ensure compliance with industry and governance standards and best practice, oversee risk management activities, and support the secure operation of cloud, network and application environments.
This role is well suited to a seasoned IT Security Engineer with strong practical experience who is ready to progress into a managerial position.
Key Purpose of Job
To act as a trusted advisor to IT leadership and technical teams, providing strategic direction, technical expertise and operational oversight to protect the organisation’s data, systems and users. The role combines technical leadership with day‑to‑day operational management, covering all aspects of IT security. It also requires driving continuous improvement through regular risk assessments and proactive mitigation activities.
Key Tasks
- Lead, mentor, and support a small cybersecurity and infrastructure security team, fostering a collaborative and high-performing environment.
- Assist with the creation, management, and tracking of the IT security budget, ensuring effective prioritisation of security investments and resources.
- Provide practical technical leadership and remain hands-on in operational security activities where required.
- Develop team capability through coaching, knowledge sharing, training, and process improvement initiatives.
- Develop, maintain, and execute the organisation’s IT security strategy, policies, and standards.
- Help establish and mature team procedures, standards, documentation, and operational best practices.
- Act as a senior escalation point for complex security and infrastructure security issues.
- Ensure alignment with frameworks such as ISO 27001, NIST, CIS Controls, and relevant regulatory requirements (e.g., GDPR), as well as shareholder directives.
- Advise senior stakeholders on cyber threats, emerging risks, and security investment priorities.
- Oversee day‑to‑day security operations including monitoring, threat response, vulnerability management, and incident handling.
- Ensure the organisation’s SIEM, EDR, firewalls and other security tools are well‑configured and maintained.
- Work closely with infrastructure, engineering, and operational teams to embed security best practices into technical solutions and processes.
- Manage relationships with managed security service providers and other security vendors.
- Ensure secure configuration and monitoring of cloud platforms (Azure, AWS) and hybrid infrastructure.
- Review and approve changes to networks, systems and architecture from a security perspective.
- Promote secure development practices across software engineering teams.
- Oversee vulnerability remediation and work closely with developers to resolve identified risks.
- Conduct regular risk assessments and ensure appropriate risk treatment plans are in place.
- Maintain relationships and good working practises with the wider Protective Security team.
- Manage relationships with business teams to understand their workflows and identify areas where security can be embedded. Create and implement security protocols and guidelines tailored to their business processes.
- Ensure all projects identify and address security requirements and follow Secure by Design principles.
- Oversee cyber security audits, compliance initiatives and certification efforts.
- Maintain security documentation, registers and evidence repositories for audit readiness.
- Lead the response to cyber incidents and coordinate with technical teams to contain and remediate threats.
- Ensure good threat intelligence sources for the latest security threats and mitigation strategies.
- Maintain and continuously improve incident response playbooks, disaster recovery plans and continuity strategies.
- Deliver lessons‑learned reviews and drive improvements to prevent recurrence.
- Deliver security awareness training and foster a strong security culture across the organisation.
- Provide security guidance to IT teams, project managers and senior leadership team.
- Communicate technical risks in clear, business‑friendly language.
PERSON SPECIFICATION (essential requirements)
Qualifications
- Degree in Computing or equivalent.
- CISSP, CISM, CCSP, CRISC, CEH, or similar (desirable).
- Cloud security certifications such as AZ‑500 or AWS Security Specialty (desirable).
Experience
- Proven experience in an IT security leadership or management role.
- Strong background in cyber security operations, cloud security and enterprise IT systems.
- Hands‑on experience with security tools such as SIEM (Splunk), EDR, vulnerability scanners and cloud security platforms.
- Experience with ISO 27001 compliance.
- Experience in Risk Management.
Knowledge & Skills
- Cloud security (Azure/AWS).
- Identity & access management, MFA, RBAC, PAM.
- Network and endpoint security.
- Threat detection, incident response and vulnerability management.
- Secure development and DevSecOps principles.
- Knowledge of Splunk ES would be an advantage.
- Strong communication and stakeholder management abilities.
- Ability to work collaboratively with both technical and non‑technical teams.
- Analytical thinking and a pragmatic approach to balancing risk with business needs.
IT Security Manager in Guildford employer: Surrey Satellite Technology
As an IT Security Manager at our organisation, you will thrive in a dynamic and supportive work culture that prioritises employee growth and development. We offer competitive benefits, including opportunities for continuous learning and professional advancement, all while working in a collaborative environment that values innovation and security excellence. Located in a vibrant area, our company is committed to fostering a strong security culture and providing the resources necessary for you to make a meaningful impact on our cyber security posture.
Contact Details:
Surrey Satellite Technology Recruitment Team
StudySmarter Expert Advice🤫
We think this is how you could land IT Security Manager in Guildford
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Surrey Satellite Technology, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Surrey Satellite Technology
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Surrey Satellite Technology. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace IT Security Manager in Guildford
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Surrey Satellite Technology insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Surrey Satellite Technology that you’re committed to staying ahead in the game.
How to prepare for a job interview at Surrey Satellite Technology
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Surrey Satellite Technology to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Surrey Satellite Technology.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.