Security Assurance Manager (Temporary Contract | 12–18 Months)
Location: Flexible across UK offices
Hours: 37.5 hours per week
Security Clearance Required: SC Clearance (or eligibility to obtain)
Start Date: ASAP
My client is seeking an experienced Security Assurance Manager to lead and strengthen security assurance activities across secure networks and cloud environments within a highly regulated UK defence‑related setting. This is a critical interim opportunity for a cyber security professional with deep MOD security expertise to shape assurance frameworks, oversee compliance, and influence secure infrastructure governance.
The Role
As Security Assurance Manager, you will take ownership of security assurance across secure network environments, ensuring compliance with UK MOD and government cyber security standards while overseeing assurance activities for cloud and on‑premise systems.
You will lead governance, risk, and compliance activities, work closely with internal and external stakeholders, and provide strategic assurance guidance to ensure secure systems remain compliant, resilient, and audit‑ready.
Key Responsibilities
- Oversee and guide consultants delivering cloud security assurance for non‑core cloud systems.
- Maintain and enhance the Secure Networks Security Assurance framework, including protocols, standards, and processes.
- Manage secure network approvals, risk assessments, compliance statements, and security arguments aligned to the DCPP Cyber Security Model and related frameworks.
- Conduct and maintain security assessments for core secure cloud systems, including Microsoft 365.
- Support broader certification initiatives including Defence Cyber Certification.
- Carry out compliance audits across secure networks, project teams, and local security contacts.
- Monitor MOD, NCSC, and wider regulatory guidance, incorporating updates into assurance practices.
- Provide assurance input into secure network design, architecture, and operational changes.
- Maintain and periodically update network risk assessments, track mitigation actions, and communicate findings to stakeholders.
- Monitor threat intelligence affecting secure environments and incorporate findings into assurance planning.
- Lead annual review and reissue of security operating procedures.
- Support external audits including ISO27001 and client‑led assessments.
- Oversee third‑party security authorisations for secure network access and data handling.
- Assess devices requiring connection to secure networks.
- Coordinate and manage delivery timelines for all assurance activities.
- Prepare reports, recommendations, and updates for governance committees and senior security leadership.
- Build and improve operational infrastructure for a scalable standalone Security Assurance function.
Required Experience & Skills
- Proven cyber security experience within a UK MOD‑related environment.
- Strong knowledge of:
- Def Stan 05‑138 (v3 and v4)
- MOD Cyber Security Model
- Secure by Design principles
- Industry Security Notices
- Strong understanding of UK Government cyber standards including: NCSC Cloud Security Principles, NCSC SaaS Security Principles, Cyber Essentials, CHECK penetration testing scheme.
- Experience with recognised risk assessment methodologies such as IS1 and NIST SP800‑30.
- Familiarity with UK Government personnel and physical security frameworks including NPSA and UKSV.
- Excellent written and verbal communication skills with the ability to explain complex security requirements clearly.
- Strong stakeholder management skills across technical and senior leadership audiences.
- Highly organised with strong prioritisation and delivery focus.
- Detail‑oriented, proactive, and able to see tasks through to completion.
- Knowledge of ISO27001, CMMC, NIST Cyber Security Framework, and SP800‑53.
- Familiarity with UK nuclear regulatory standards such as ONR SyAPs.
- Experience within large, complex enterprise security environments.
#J-18808-Ljbffr…
