Key Responsibilities as a Security Assurance Lead
- Provide independent security assurance across programme workstreams, projects and suppliers.
- Review and challenge security designs, technical artefacts and implementation approaches to ensure secure-by-design and secure-by-default principles are followed.
- Assess compliance with government security policies, industry standards and programme security frameworks.
- Identify, assess and manage security risks, ensuring appropriate mitigation and escalation where required.
- Build strong relationships with programme teams, suppliers and senior stakeholders, acting as a trusted security advisor.
- Provide pragmatic security guidance that balances risk, operational requirements and delivery objectives.
- Support security accreditation, authority-to-operate activities and programme release gates.
- Review significant security incidents and contribute to lessons learned and continuous improvement activities.
- Monitor remediation activities relating to vulnerabilities, incidents and audit findings.
- Produce high-quality security assurance reports, risk assessments and documentation for senior decision-makers.
- Conduct supplier and third-party security assurance reviews to ensure compliance with contractual and programme security requirements.
Experience You'll Need as a Security Assurance Lead
- Proven experience as a Security Assurance Lead, Security Assurance Manager or Security Accreditor.
- Experience delivering security assurance across large, complex transformation programmes involving multiple suppliers and stakeholders.
- Strong knowledge of government security policies and frameworks, including Secure by Design, NCSC guidance and related standards.
- Experience conducting security assessments, audits and assurance reviews.
- Experience reviewing technical security architectures and providing constructive challenge to delivery teams.
- Strong understanding of security governance, risk management and compliance.
- SFIA Level 5 capability or equivalent experience.
- Experience within telecommunications, mobile network operators, critical national infrastructure or emergency services.
- Knowledge of 4G/5G Core Networks, Radio Access Networks (RAN), IMS, OSS/BSS platforms and network virtualisation (NFV/SDN).
- Understanding of Zero Trust architecture, identity security, encryption, SIEM, SOC integration and network segmentation.
- Professional certifications such as CISSP, CISM, CCSP, CRISC, ISO 27001, NCSC CCP, TOGAF, SABSA or AWS Security.
- Experience working within highly regulated public sector or government environments.
What's on Offer
- Up to £600 per day Inside IR35.
- Hybrid working with two days onsite each week in London.
- Opportunity to work on a high-profile, nationally significant transformation programme.
- Collaborative environment alongside experienced cyber security and technology specialists.
- Initial contract with strong potential for extension.
Miscellaneous
- Active SC Clearance is required for this role. Candidates should have clearance that has been used within a UK Government department within the last 12 months. Candidates who do not fully meet this requirement may still be considered, subject to client approval and sponsorship.