Skip to main content
G

Information & Cybersecurity Assurance Manager

Guildford
1 hour ago
Full-time
On-site
Guildford, Surrey
Security
Information & Cybersecurity Assurance Manager

Role Overview

The Information & Cybersecurity Assurance Manager will be responsible for delivering a range of cybersecurity and information assurance workstreams that contribute to the organisation’s overall cybersecurity profile, including product and service development.

The role will own the assurance of information and cybersecurity certifications, contracted cybersecurity deliverables, and the delivery of Secure by Design principles across the organisation.

Key Responsibilities:

Identify, understand, and provide assurance against contractual security obligations for product and service deliverables, as well as information and cybersecurity certifications such as ISO 27001, CE+ and DCC.
Ensure the delivery of technically and contractually compliant governance, security strategies, policies, management plans, procedures and processes in accordance with relevant industry standards.
Support the review and development of organisational security governance.
Own the management of information and cybersecurity assurance artefacts and security control requirements across contracted project schedules, ensuring successful delivery through project lifecycle gateways and milestones.
Lead and facilitate certification or contract-dependent ITHCs, coordinate vulnerability management exercises and external penetration testing, and ensure remediation actions are completed and verified.
Review infrastructure, cloud and application designs and implementations against Secure by Design principles.
Perform security risk assessments for new technologies and business initiatives.
Participate in Change Advisory Board (CAB) meetings, providing security assurance and guidance.
Support the implementation, delivery and exercising of incident response and business continuity plans, contributing to lessons-learned activities.
Act as a member of the incident response team during security incidents.
Contribute to security working groups, security steering boards, executive-level reporting and management information.
Own the management of Security Aspect Letters, ensuring compliance and creating appropriate flow-down variations for suppliers and internal teams.
Own the management and monitoring of third-party supplier security compliance.
Own the security aspects of space licensing, ensuring all requirements are completed to facilitate the effective delivery and operation of spacecraft throughout their lifecycle.
Manage project-level security budgets and contribute to accurate costing of security activities for future bids.
Monitor and manage the delivery of security awareness and training in accordance with contractual and certification requirements.

Success Criteria:

All security aspects of contractual deliverables are successfully delivered in accordance with customer requirements, timelines and budget.
A portfolio of reusable Secure by Design security artefacts is developed and maintained.
Information and cybersecurity certifications are successfully renewed on time without interruption.
Security requirements associated with spacecraft licensing are completed without delaying programme delivery or spacecraft operations.
Established processes, methodologies and compliance frameworks are maintained for technical and cybersecurity infrastructure.

Essential Requirements:

Qualifications

Candidates should hold, or have previously held, one or more of the following certifications:

* ChCSP

* CISM

* CISA

* BCS CISMP

* CMIRM

Membership of a recognised Cybersecurity or Information Risk Management professional body, such as CIISec or IRM, is desirable.

Candidates must be eligible to attain UK National Security Vetting at SC level or above, requiring a minimum of 5 years of continuous UK residency for eligibility.

Experience:

Comprehensive and demonstrable experience working within a Defence Secure by Design programme or project.
Experience in roles such as Delivery Team Security Lead, Delivery Team Security Engineer, Security Assurance Coordinator, or equivalent.

Proven experience delivering security artefacts, including:

* Security Management Plans

* Risk Registers

* Risk Assessments

* Security Requirements Documents

* Security Aspect Letters

* Threat Models

* Vulnerability Assessments

* Security Architecture Documents

* Compliance and Audit Reports

* Incident and Recovery Plans

Experience assuring or implementing information and cybersecurity management systems achieving certification against standards such as ISO 27001, CE+ or DCC.
Experience facilitating, coordinating and directing Independent Third-Party Health Checks (ITHCs).
Experience producing Security Requirements Traceability Matrices, scoping documents and prioritising remediation activities.
Strong technical understanding of information systems at architecture, design and audit level.

Knowledge & Skills:

Strong understanding of information and cybersecurity principles.
Knowledge of cybersecurity risk management frameworks and the delivery and verification of controls against standards such as:

* ISO 27001

* NIST SP 800-53

* CE+

* DCC

Ability to influence internal stakeholders using data, analysis and evidence to support recommendations.
Ability to work independently while following established procedures and recognising appropriate escalation requirements.
Strong commercial and business awareness, with the ability to assess "what-if" scenarios and their potential security implications.
Knowledge of the space industry or aerospace communications systems is desirable.
Ability to attain UK National Security Vetting at SC level, with DV clearance desirable. DV eligibility generally requires 10 years of continuous UK residency