Overview
A large, well-established public sector organisation in Manchester is looking for an Operational Security Architect to join their Information Security team on a permanent basis.
This is a broad and genuinely interesting security role blending security architecture, compliance, policy development, risk management and stakeholder engagement. If you want a role where you’re shaping how security is done rather than just maintaining it, this is worth a look.
Responsibilities
- Designing and maintaining security architectures aligned with NCSC guidance and sector best practice.
- Leading internal security audits and contributing to external assurance including Cyber Essentials.
- Writing and maintaining information security policies and standards.
- Conducting risk assessments and managing the security risk register.
- Supporting third-party security risk management.
- Delivering security awareness training across the organisation.
- Working across IT, data protection, legal and operational teams to embed security at every level.
Requirements
- A proven background in an operational security role, Security Architect, Security Analyst or Compliance Lead.
- Strong knowledge of GDPR, ISO 27001, Cyber Essentials Plus and NCSC CAF.
- An industry-recognised certification such as CISSP, CISM, ISO 27001 Lead Implementer or equivalent.
- Experience writing and implementing security policies, conducting audits and working with IT teams to improve controls.
- Familiarity with DevSecOps, SIEM tooling, or higher education / public sector environments is desirable but not essential.
#J-18808-Ljbffr…
