Overview
In this role you act as the primary trust and security contact for UK Sovereign customers, shaping security posture communications and facilitating trusted engagement. You bridge UK Sovereign security teams and customers, handling questionnaires, audits, and remediation reporting to accelerate deal cycles. You translate technical risk into clear business language and maintain reusable security content. This senior, customer-facing position centers on integrity, transparency, and proactive security governance within a regulated environment.
Responsibilities
- Serve as the main security/contact point for UK Sovereign customers on posture, vulnerabilities and trust documentation
- Coordinate end-to-end responses to security questionnaires (SIG, CAIQ, VSA, MoD/UK government formats)
- Translate technical controls into business language for technical and non-technical stakeholders
- Maintain and update the public trust center and customer-facing security documentation
- Collaborate with engineering to assess security posture and track vulnerability remediation (POA&M)
- Prepare and deliver monthly security status updates to customers
- Oversee remediation activities across teams to meet timelines and compliance
- Audit interpretation and presenting findings to customers in responses
- Gather and translate detailed technical information for stakeholders; participate in security review meetings
- Coordinate inputs from internal teams to validate questionnaire answers and close gaps
Key requirements
- UK citizenship and ability to obtain and maintain SC clearance
- 5+ years in security, GRC, trust, or technical customer-facing role with security questionnaires
- Hands-on experience with SIG, CAIQ, VSA, and bespoke government questionnaires
- Working knowledge of Cyber Essentials Plus, ISO 27001, SOC 2 Type II, and at least one of PCI DSS, GDPR/UK GDPR, HIPAA, or FedRAMP
- Strong technical understanding of security principles, architecture, vulnerability management, and secure SDLC
- Familiarity with cloud infra (AWS, Azure, GCP) and SaaS security models
- Excellent written and verbal communication for diverse stakeholders
- Experience in customer-facing roles with regulated or government customers
- Solid organizational skills to manage high-volume queues and multi-stakeholder deadlines
- Bachelor’s degree in a relevant field or equivalent experience
- Discretion in handling confidential information
- excellent written and verbal communication
- cross-functional collaboration
- proactive and self-motivated
- security principles and architecture
- vulnerability management
- access control, encryption, incident response
…
