Nicholas Howard is delighted to be working with a highly successful digital transformation consultancy, and we are currently recruiting for a Cyber Security Assurance Manager to join them on a permanent basis. The role will focus on governance, risk an compliance in relation, primarily looking inward at the organisation, but also with potential to support their external clients with these functions.
Our client helps companies drive efficiency and growth by integrating innovative IT solutions with expert delivery. With a global presence and a focus on transformation and digital enablement, they deliver technology and consultancy services across multiple sectors.
The Cyber Security Assurance Manager will be responsible for ensuring their Security Operations Centres (SOC) achieves and maintains internationally recognised security certifications, audit reports, and assurance standards.
This role will focus on delivering and maintaining certifications such as ISO/IEC 27001, SOC2 Type II, Cyber Essentials Plus, CREST SOC accreditation, and sector-specific frameworks (PCI DSS, NCSC CIR/ CHECK), providing customer confidence in our SOC services.
As a key member of the Governance, Risk, and Compliance (GRC) function, the Cyber Security Assurance Manager will lead customer assurance activities, including audit preparation, security compliance queries, and support for security-related RFPs and RFIs. Acting as a trusted point of contact for clients and auditors, the role will showcase their certified security credentials and help build lasting confidence in the credibility of our SOC services on a global scale.
Responsibilities
Certification Delivery & Maintenance:
* Lead the delivery and ongoing maintenance of key SOC-related certifications including SOC 2 Type II, SOC 3, ISO/IEC 27001, Cyber Essentials Plus, and CREST.
* Oversee sector-specific assurance needs such as PCI DSS for cardholder data environments or NCSC CIR/ CHECK where relevant.
* Ensure certifications are renewed on schedule and compliance gaps are proactively addressed.
Security Assurance for SOC Services:
* Embed certification requirements into the SOC’s governance, processes, and operational practices.
* Ensure continuous monitoring, evidence collection, and readiness for internal/external audits.
* Translate security control requirements into operational procedures for SOC teams.
Customer Assurance Engagement:
* Act as primary contact for customer assurance activities relating to SOC services.
* Support client RFIs, RFPs, and audit requests with accurate certification evidence and security documentation.
Required Qualifications and Experience
* Demonstrable experience delivering and maintaining cybersecurity certifications (ISO/IEC 27001, SOC 2 Type II, Cyber Essentials Plus, CREST).
* Strong understanding of SOC & SOC 2 operations and security assurance frameworks.
* Experience in customer-facing assurance activities, including audits, RFIs, and RFPs.
* Knowledge of regulatory and industry frameworks including NIST CSF, GDPR, and UK NCSC guidance.
* Experience liaising with external auditors, regulators, and certification bodies.
Skills
* Strong ability to develop and maintain compliance documentation and audit evidence.
* Excellent communication skills to explain complex security assurance topics to customers, senior leaders, and SOC teams.
* Analytical and detail-oriented, with the ability to identify gaps and design improvements.
* Stakeholder engagement and influencing skills, particularly with technical and commercial teams.
* Organisational skills to manage multiple certifications and assurance projects simultaneously.
The organisation offers strong salaries with excellent potential for career growth, and comprehensive benfits packages. Please register your interest by applying now