Overview
In this role you will provide expert cyber security support on a high-profile Ministry of Defence programme from Farnborough. You will work with a cross-functional team to keep complex systems secure, compliant and resilient throughout their lifecycle. You’ll produce security documentation, advise on policy changes, and lead awareness across the programme. This is a chance to influence security posture in a critical national defence context and collaborate with leading industry specialists.
Responsibilities
- Maintain security risk assessments and Secure by Design documentation for ongoing assurance
- Manage Codes of Connection and ensure ongoing compliance and approval
- Assess changes to MOD and HMG security policies and advise on programme implications
- Support the Security Manager by preparing security reports and coordinating quarterly Security Working Groups
- Monitor MODCERTs and vulnerability sources, guiding patching and remediation
- Produce and maintain technical security and cryptographic management documentation
- Design and deliver cyber security awareness and training across the programme
- Provide expert security advice on System Change Requests and associated risks
Key requirements
- Proven experience in information or cyber security within a Ministry of Defence environment
- Strong understanding and application of the NIST Cybersecurity Framework or equivalent
- Broad knowledge of IT security architecture, threats, vulnerabilities and mitigations
- Experience producing security risk assessments, security assurance activities and through-life risk management
- Experience managing IT Health Checks, interpreting findings and developing Risk Treatment Plans
- Excellent communication and stakeholder management skills across multidisciplinary teams
- Strong organisational skills with ability to manage priorities and work independently
- Cyber Council Chartered Professional status, a legacy CESG/Cyber Security Professional or equivalent experience
- Current DV Clearance
- excellent communication
- stakeholder management
- ability to work across multidisciplinary teams
- NIST Cybersecurity Framework
- security risk assessments
- security assurance activities
…
