Overview
As Security Manager, you will support NEC’s InfoSec team to deliver security assurances and accreditation for customers. You’ll collaborate with architecture, technology teams and the Data Protection Officer to create and maintain policies, procedures and security documentation. You’ll manage remediation of vulnerabilities, coordinate security testing, and respond to security questionnaires and bids. This hybrid/remote role focuses on improving the security posture while contributing to governance, risk and incident response across NEC. A meaningful opportunity to influence security across multi-tenant environments and customer engagements.
Pay / Benefits
- Above average pension scheme
- Private medical cover for employees
- 25 days holiday (with buy/sell option)
- 4x basic salary life assurance
- Group Pension Plan with up to 8.5% employer contributions
- LinkedIn Learning access for all colleagues
Responsibilities
- Provide tiered responses to customer tenders and assurance questionnaires
- Produce and maintain security assurance documentation for accreditation
- Ensure compliance with security standards, processes, regulations, and best practices
- Coordinate security testing and create remediation plans, driving closure
- Contribute to policy and process documentation; conduct security assessments and audits
- Assist in security incident management and vulnerability management
Key requirements
- Proven experience in an IT security role
- Strong knowledge of cybersecurity frameworks, standards, and regulations
- Understanding of risk management and context-driven assessment
- Experience writing comprehensive responses to security questionnaires or bids
- Focus on delivering business outcomes
- Security clearance to NPPV L3+SC (or ability to obtain)
- BPSS baseline and Disclosure Scotland checks (pre-employment)
- Strong team collaboration
- Excellent verbal and written communication
- Ability to explain security concepts to non-technical stakeholders
- Knowledge of security frameworks and standards (cyber essentials, etc.)
- Experience with security testing processes and reports
- Incident management and remediation tracking
…
