Information & Cybersecurity Assurance Manager

Company: Surrey Satellite Technology
Apply for the Information & Cybersecurity Assurance Manager
Location: Guildford
Job Description:

Overview

In this role you will drive information and cybersecurity assurance across product and service lifecycles, ensuring contractual security obligations and certifications are met. You will own governance, artefacts, and security controls, aligning with Secure by Design and industry standards. You will lead ITHCs, vulnerability testing, and remediation validation, while shaping incident response and business continuity practices. This position supports management reporting, supplier security, and space licensing to enable secure spacecraft operations.

Responsibilities

  • Identify and assure contractual security obligations for product/service deliverables and certifications (ISO 27001, CE+, DCC)
  • Govern and implement governance, policies, strategies, and procedures
  • Manage information and cybersecurity assurance artefacts and security control requirements across contracts
  • Lead ITHCs, vulnerability management, and external penetration testing coordination with remediation verification
  • Review designs and risk assess new technologies for Secure by Design, participate in CAB meetings
  • Support incident response, business continuity, and lessons learned processes
  • Contribute to security governance groups and executive/board reporting
  • Manage Security Aspect Letters and supplier compliance variations
  • Oversee space licensing security requirements for spacecraft lifecycle
  • Accountable for project security budget and accurate costing of security efforts
  • Monitor security awareness and training aligned with contracts or certifications

Key requirements

  • ChCSP, CISM, CISA, BCS CISMP, or CMIRM certification (held or previously held)
  • Membership of cybersecurity or information risk management body (e.g., CIISec, IRM)
  • Ability to obtain National Security Vetting at SC level with 5 years UK residency
  • Experience in Defence Secure by Design programmes
  • Proven delivery of security artefacts (MSPs, Risk Registers, Security Requirements Documents, etc.)
  • Experience with ISO 27001, CE+, or DCC information/cybersecurity management systems
  • Facilitation and coordination of ITHCs, writing SRTMs or Scoping Documents, remediation prioritisation
  • Technical understanding of information systems at architecture/design/audit level
  • Knowledge of cybersecurity principles, risk management frameworks, ISO 27001, NIST SP 800-53, CE+, DCC controls
  • Ability to influence stakeholders with data-driven reasoning
  • Independent working style with compliant procedures and escalation awareness
  • Knowledge of space/aerospace communications desirable
  • UK residency for clearance with SC level; DV desirable (10 years unbroken residency)
  • influencing stakeholders
  • analysis and reasoning with data
  • independent working
  • security governance
  • security artefacts (MSPs, Risk Registers, Threat Models)
  • vulnerability management

…

Posted: September 30th, 2026