- Accreditation Readiness: You will be responsible for ensuring that system solutions are fully prepared for accreditation. This includes leading internal security assessments to evaluate the system’s security status, tracking findings, and ensuring the system are technically and documentation compliant with the requirements of the accrediting authorities.
- Information Assurance & Compliance: You will ensure that project activities align with ISO 27001 and other relevant Information Assurance (IA) frameworks, ensuring that security controls are consistently applied and documented.
- Continuous Security Hygiene: You will proactively monitor and maintain “Security Hygiene” within the projects. This involves the continuous review of security baselines, and ensuring that security patches and configuration updates are handled systematically.
- Engagement through full Project Lifecycle: You will defining security requirements for complex projects, develop secure design solutions, verify & validate against MOD & Government standards
- Risk Management & Mitigation: You will identify security risks and develop robust risk assessments. A key part of your role will be preparing Security Risk Balance Cases (RBC) for incidents that cannot be resolved directly, defining appropriate mitigations via configuration or the operating environment.
- Cybersecurity Engineering: In collaboration with R&D and Design teams, you will define System Hardening baselines and oversee their implementation. You will perform Security Impact Assessments (SIA) for Engineering Change Proposals (ECP) and Change Requests (CR).
- Documentation & Evidence Management: You will create and maintain critical security documentation, including security operating procedures and how-to guides (e.g., for patching, password management, smart card security, and secure enclosure management). You will be responsible for the structured collection of verification evidence.
- Testing & Verification: You will update security test cases and hardening/verification scripts. You will provide essential technical support during penetration testing events and formal security evaluations.
- Stakeholder Coordination: You will act as the central technical point of contact for the customer’s Security Manager, providing the necessary documentation and evidence to facilitate communication with the UK MoD and other national authorities.
#J-18808-Ljbffr…
