Job Description:
Role: Security Assurance Advisor
Location: London / Epsom / Birmingham / Manchester - Any location (Hybrid)
Duration: 12 Months
Day rate: £600 - £700 Inside IR35
We are seeking an experienced Security Assurance Consultant with a strong Governance, Risk & Compliance (GRC) background to support the security assurance and accreditation of secure networks and cloud environments within a UK defence-related setting.
This role will focus on maintaining security approvals, conducting risk assessments, supporting compliance activities, and ensuring alignment with MOD and wider government security standards.
Key Responsibilities
- Support the implementation and continual improvement of secure network security assurance frameworks, processes and procedures.
- Maintain secure network accreditations and approvals, including risk assessments, security cases, compliance statements and supporting evidence.
- Conduct security assessments of core cloud platforms, including Microsoft 365.
- Support compliance with Defence Cyber Certification (DCC) requirements.
- Participate in cloud security assurance activities for both core and non-core cloud systems.
- Conduct compliance audits to ensure assurance activities are being completed across secure networks and cloud services.
- Monitor changes to MOD, government and industry security standards, incorporating requirements into assurance processes.
- Provide security assurance guidance to influence the design, operation and ongoing management of secure environments.
- Maintain and periodically review security risk assessments, communicating findings and tracking remediation activities.
- Monitor emerging cyber threats and assess their impact on secure networks.
- Track and report progress against security action plans.
- Engage with internal and external stakeholders, including security teams, project teams, HR vetting, procurement functions and MOD representatives.
- Support security operating procedure updates and annual reviews.
- Assist with external audits, including ISO 27001 and client-led assessments.
- Oversee the security approval and ongoing assurance of third parties connecting to or handling information from secure networks.
- Assess specialist devices requiring connection to secure networks.
- Maintain a coordinated assurance programme to ensure activities are delivered on time.
- Provide reporting support and assurance metrics as required.
Essential Skills & Experience
- Proven cyber security experience within a UK MOD or defence-related environment.
- Strong understanding of governance, risk management and compliance principles.
- Familiarity with UK MOD security standards, including:
- Def Stan 05-138 (v3 & v4)
- Cyber Security Model (CSM)
- Secure by Design
- Industry Security Notices (ISNs)
- Knowledge of UK Government security standards, including:
- Government Security Policy Framework (SPF)
- NCSC Cloud Security Principles
- NCSC SaaS Security Principles
- Cyber Essentials
- CHECK Penetration Testing Scheme
- Familiarity with UK Government physical and personnel security requirements, including NPSA and UKSV.
- Experience conducting risk assessments using recognised methodologies such as IS1 and NIST SP 800-30.
- Strong written and verbal communication skills, with the ability to clearly justify and explain security requirements.
- Ability to build relationships with both senior stakeholders and technical teams.
- Strong organisational skills with the ability to manage multiple priorities.
- High attention to detail with a proven completer-finisher mindset.
- Competent user of Microsoft Word, Excel and PowerPoint.
Desirable
- Knowledge of ISO 27001, CMMC and the NIST Cyber Security Framework, including SP 800-53.
- Familiarity with UK nuclear security regulations and ONR Security Assessment Principles (SyAPs).
If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website.