Information & Cybersecurity Assurance Manager

Langham Recruitment

Guildford

On-site

GBP 70,000 - 110,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible working policies
32 days annual leave + BH
Annual Company Bonus Scheme
Pension contributions
Life Assurance

Job summary

Langham Recruitment is seeking an Information & Cybersecurity Assurance Manager for Guildford. The role supports corporate security by delivering assurance across product and service deliverables, ensuring Secure by Design and governing certifications like ISO 27001, CE+, and DCC.

The candidate will manage security artefacts, lead CERT/ITHCs, and contribute to executive security reporting, with SC vetting requirements and space industry context.

Qualifications

  • Holder of CISM, CISA, CMIRM or similar certification.
  • Membership in CIISec or IRM or equivalent.
  • National Security Vetting at SC or above with 5 years UK residency.

Responsibilities

  • Identify and assure compliance against contractual security obligations and certifications such as ISO 27001, CE+, and DCC.
  • Govern security strategies, policies, and procedures ensuring alignment with industry standards.
  • Manage information and cybersecurity assurance artefacts and security control requirements across contracted schedules.
  • Lead ITHCs, coordinate penetration testing, and ensure remediation actions are completed and verified.
  • Review designs for Secure by Design, perform risk assessments on new technologies, participate in CAB meetings.

Skills

Security certifications
Vetting eligibility
Frameworks knowledge

Job description

Information & Cybersecurity Assurance Manager | Space / Aerospace | Guildford

Must be able to attain National Security Vetting at SC but DV is desirable which would require 10 years unbroken residency in the UK

Reporting to the Corporate Security Manager the role is responsible for executing a range of cybersecurity and information assurance workstreams that contribute to the overall cybersecurity profile, including product and service development. Owning the assurance of information and cybersecurity certifications, contracted information and cybersecurity deliverables, and delivery of Secure by Design.

Key Tasks
  • Identify, understand, and provide assurance against all elements of contractual security obligations for product and service deliverables, as well as information and cybersecurity certifications such as ISO 27001, CE+, and DCC
  • Ensure the delivery of relevant technical, framework and contract compliant governance, security strategies, policies, management plans, procedures, and processes, as well as supporting the review of organisational security governance in accordance with industry standards
  • Own the management of information and cybersecurity assurance artefacts and security control requirements against all contracted schedules, ensuring project lifecycle gateway and milestone success
  • Lead the facilitation of certification or contract dependent ITHCs, coordinate vulnerability management exercises and external penetration testing and ensure remediation actions are completed and verified
  • Review infrastructure, cloud, and application designs and current implementations against Secure by Design principles and perform risk assessments for new technologies and business initiatives, as well as participate in Change Advisory Board (CAB) meetings to provide security assurance
  • Support the implementation, delivery, and exercising of incident and business continuity response plans, and contribute to the lessons identified process
  • Act as a member of the incident response team in the event of a security incident
  • Contribute to security working groups, security steering boards, Executive and Board level reports, and any other management material as required
  • Own the management of Security Aspect Letters, compliance with them, and the creation of any flow down variations to suppliers and own the management and monitoring of third-party supplier compliance
  • Own the security aspects of space licensing, ensuring all requirements are complete to facilitate the effective delivery and operation of spacecraft throughout their lifecycle
  • Accountable for the management of project level security budget, and contribute to accurate costing of project level security effort on future bids
  • Monitor and manage the delivery of security awareness and training in accordance with contractual or certification requirements
Success Criteria
  • All security aspects of contractual deliverables are successfully delivered in accordance with customer requirements and within timelines and budget
  • A portfolio of template Secure by Design security artefacts is made available for future use
  • Information and cybersecurity certification is successfully renewed on time without breaks
  • Space licencing for existing and new spacecraft is not delayed or hindered due to Security input
  • Established processes or methodologies, and compliance for technical and cybersecurity infrastructure
PERSON SPECIFICATION (essential requirements)
Qualifications
  • Either hold, or have held: ChCSP, CISM, CISA, BCS CISMP, or CMIRM certification
  • Membership of a Cybersecurity or Information Risk Management professional body such as, but not limited to, CIISec and IRM
  • Must be able to hold National Security Vetting at SC or above, with a minimum unbroken UK residency of at least 5 years to be eligible to apply for National Security Vetting
Experience
  • Comprehensive and demonstrable experience of working in a Defence Secure by Design programme or project, particularly as a Delivery Team Security Lead, Delivery Team Security Engineer, or Security Assurance Coordinator Role
  • Proven ability to deliver security artefacts such as, but not limited to, Security Management Plans, Risk Registers and Risk Assessments, Security Requirements Documents, Security Aspects Letters, Threat Models and Vulnerability Assessments, Security Architecture Documents, Compliance & Audit Reports, and Incident & Recovery Plans
  • Experience in the assurance or implementation of information or cybersecurity management systems that have achieved certification to ISO 27001, CE+, or DCC standards
  • Experience in facilitating, coordinating, and directing ITHCs including, but not limited to, the writing of Security Requirements Traceability Matrix or Scoping Document, as well as the prioritisation of remediation effort
  • Proficient technical understanding of information systems at an architecture, design, and audit levelKnowledge & Skills
Knowledge & Skills
  • Proven understanding of information and cybersecurity principles, cybersecurity risk management frameworks, and the delivery and verification of ISO 27001, NIST SP 800-53, CE+, or DCC controls
  • Ability to influence internal stakeholders, using data and analysis to support reasoning
  • Can work independently, in compliance with procedures, and be able to recognise appropriate escalation scenarios
  • Good business knowledge to suggest and analyse “what-if” scenarios
  • Knowledge of space industry or aerospace communication systems is desirable
  • Must be able to attain National Security Vetting at SC but DV is desirable which would require 10 years unbroken residency in the UKBenefits
Benefits
  • Highly competitive Salary dependent on experience
  • Flexible working policies
  • 32 days annual leave + BH
  • Annual Company Bonus Scheme
  • Up to 8% employer pension contribution
  • Life Assurance (6X salary)
  • Private Health Care
  • Enhanced Maternity & Paternity leave
  • Multiple Discount, Memberships schemes
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information & Cybersecurity Assurance Manager
Information & Cybersecurity Assurance Manager

UK Space Jobs • Guildford

On-site
GBP 70,000 - 110,000
Flexible working policies
32 days annual leave
Annual company bonus scheme
+3
Information & Cybersecurity Assurance Manager
Information & Cybersecurity Assurance Manager

Standard 8 Recruitment Ltd • Guildford

On-site
GBP 90,000 - 130,000
Information & Cybersecurity Assurance Manager
Information & Cybersecurity Assurance Manager

iO Associates • Guildford

On-site
GBP 85,000 - 115,000
Information & Cybersecurity Assurance Manager
Information & Cybersecurity Assurance Manager

SURREY IT LIMITED • Guildford

On-site
GBP 70,000 - 100,000
SSTL Information and Cybersecurity Assurance Manager Security & Facilities · Guildford ·
SSTL Information and Cybersecurity Assurance Manager Security & Facilities · Guildford ·

Surrey Satellite Technology Ltd. • Guildford

Hybrid
GBP 70,000 - 100,000
Cyber Security Manager
Cyber Security Manager

InfoSec People Ltd • Guildford

On-site
GBP 70,000 - 110,000
Cybersecurity Assurance Lead – Space Sector & ISO 27001
Cybersecurity Assurance Lead – Space Sector & ISO 27001

UK Space Jobs • Guildford

On-site
GBP 70,000 - 110,000
Flexible working policies
32 days annual leave
Annual company bonus scheme
+3
Security Assurance Manager
Security Assurance Manager

Sanderson Government & Defence • West of England

Hybrid
GBP 26,384,000 - 32,472,000
Security Architect - DV Cleared
Security Architect - DV Cleared

Sanderson Government & Defence • Farnborough

On-site
GBP 70,000 - 85,000
Competitive salary
Private medical insurance
Enhanced pension
+1
Security Assurance Lead
Security Assurance Lead

Cambridge University Press & Assessment • Cambridgeshire and Peterborough

Hybrid
GBP 55,000 - 73,000
28 days leave
Private medical insurance
Permanent Health Insurance
+5