SSTL Information and Cybersecurity Assurance Manager Security & Facilities · Guildford ·

Surrey Satellite Technology Ltd.

Guildford

Hybrid

GBP 70,000 - 100,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Surrey Satellite Technology Ltd. seeks an Information and Cybersecurity Assurance Manager to lead security governance and assurance across SSTL product and service delivery.

You will own certification activities, coordinate ITHCs and vulnerability management, and ensure secure design reviews for new technologies, with responsibility for incident response and continuity planning.

Qualifications

  • Experience in Defence Secure by Design programmes or projects.
  • Delivery of Security artefacts such as Security Management Plans, Risk Registers, and Threat Models.
  • Facilitation and direction of ITHCs and prioritisation of remediation work.
  • Experience implementing information/cybersecurity management systems achieving ISO 27001, CE+, or DCC certification.

Responsibilities

  • Identify, understand, and provide assurance against contractual security obligations and certifications.
  • Oversee governance, policies, and security strategies across product and service delivery.
  • Lead the management of assurance artefacts and third‑party supplier compliance.
  • Coordinate vulnerability management, penetration testing, and remediation actions.
  • Review designs for Secure by Design and perform risk assessments for new tech initiatives.
  • Support incident response, business continuity, and lessons‑learned processes.
  • Report security status to executive boards and risk committees.

Skills

Stakeholder influence
Risk analysis

Education

ChCSP
CISM
CISA
BCS CISMP
CMIRM
National Security Vetting SC

Tools

ISO 27001
CE+
DCC

Job description

SSTL Information and Cybersecurity Assurance Manager

Responsible For

Executing a range of cybersecurity and information assurance workstreams that contribute to the overall cybersecurity profile of SSTL, including product and service development. Owning the assurance of SSTL information and cybersecurity certifications, contracted information and cybersecurity deliverables, and delivery of Secure by Design in SSTL.

Reports To

Corporate Security Manager

Key Tasks

Identify, understand, and provide assurance against all elements of contractual security obligations for product and service deliverables, as well as information and cybersecurity certifications such as ISO 27001, CE+, and DCC

Ensure the delivery of relevant technical, framework and contract compliant governance, security strategies, policies, management plans, procedures, and processes, as well as supporting the review of organisational security governance in accordance with industry standards

Own the management of information and cybersecurity assurance artefacts and security control requirements against all contracted schedules, ensuring project lifecycle gateway and milestone success

Lead the facilitation of certification or contract dependent ITHCs, coordinate vulnerability management exercises and external penetration testing and ensure remediation actions are completed and verified

Review infrastructure, cloud, and application designs and current implementations against Secure by Design principles and perform risk assessments for new technologies and business initiatives, as well as participate in Change Advisory Board (CAB) meetings to provide security assurance

Support the implementation, delivery, and exercising of incident and business continuity response plans, and contribute to the lessons identified process

Act as a member of the incident response team in the event of a security incident

Contribute to security working groups, security steering boards, Executive and Board level reports, and any other management material as required

Own the management of Security Aspect Letters, compliance with them, and the creation of any flow down variations to suppliers and own the management and monitoring of third‑party supplier compliance

Own the security aspects of space licensing, ensuring all requirements are complete to facilitate the effective delivery and operation of spacecraft throughout their lifecycle

Accountable for the management of project level security budget, and contribute to accurate costing of project level security effort on future bids

Monitor and manage the delivery of security awareness and training in accordance with contractual or certification requirements

Success Criteria

All security aspects of contractual deliverables are successfully delivered in accordance with customer requirements and within timelines and budget

A portfolio of template Secure by Design security artefacts is made available for future use

Information and cybersecurity certification is successfully renewed on time without breaks

Space licencing for existing and new spacecraft is not delayed or hindered due to Security input

Established processes or methodologies, and compliance for technical and cybersecurity infrastructure

PERSON SPECIFICATION (essential requirements)

Qualifications

Either hold, or have held:

ChCSP, CISM, CISA, BCS CISMP, or CMIRM certification

Membership of a Cybersecurity or Information Risk Management professional body such as, but not limited to, CIISec and IRM

Must be able to hold National Security Vetting at SC or above, with a minimum unbroken UK residency of at least 5 years to be eligible to apply for National Security Vetting

Experience

Comprehensive and demonstrable experience of working in a Defence Secure by Design programme or project, particularly as a Delivery Team Security Lead, Delivery Team Security Engineer, or Security Assurance Coordinator Role

Proven ability to deliver security artefacts such as, but not limited to, Security Management Plans, Risk Registers and Risk Assessments, Security Requirements Documents, Security Aspects Letters, Threat Models and Vulnerability Assessments, Security Architecture Documents, Compliance & Audit Reports, and Incident & Recovery Plans

Experience in the assurance or implementation of information or cybersecurity management systems that have achieved certification to ISO 27001, CE+, or DCC standards

Experience in facilitating, coordinating, and directing ITHCs including, but not limited to, the writing of Security Requirements Traceability Matrix or Scoping Document, as well as the prioritisation of remediation effort

Proficient technical understanding of information systems at an architecture, design, and audit level

Knowledge & Skills

Proven understanding of information and cybersecurity principles, cybersecurity risk management frameworks, and the delivery and verification of ISO 27001, NIST SP 800-53, CE+, or DCC controls

Ability to influence internal stakeholders, using data and analysis to support reasoning

Can work independently, in compliance with procedures, and be able to recognise appropriate escalation scenarios

Good business knowledge to suggest and analyse "what-if" scenarios

Knowledge of space industry or aerospace communication systems is desirable

Must be able to attain National Security Vetting at SC but DV is desirable which would require 10 years unbroken residency in the UK

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information & Cybersecurity Assurance Manager
Information & Cybersecurity Assurance Manager

Standard 8 Recruitment Ltd • Guildford

On-site
GBP 90,000 - 130,000
Information & Cybersecurity Assurance Manager
Information & Cybersecurity Assurance Manager

iO Associates • Guildford

On-site
GBP 85,000 - 115,000
Cybersecurity Assurance Lead: ISO 27001 & Secure by Design
Cybersecurity Assurance Lead: ISO 27001 & Secure by Design

Surrey Satellite Technology Ltd (SSTL) • England

On-site
GBP 90,000 - 120,000
Security Infrastructure Systems Engineer
Security Infrastructure Systems Engineer

Surrey Satellite Technology Ltd. • Wood Street

On-site
GBP 65,000 - 90,000
Security Delivery Lead
Security Delivery Lead

Sanderson Government & Defence • High Wycombe

On-site
GBP 65,000 - 92,000
Security Assurance Manager
Security Assurance Manager

InfoSec People Ltd • Guildford

On-site
GBP 70,000 - 110,000
Information Assurance Engineer Sr Stf - E5
Information Assurance Engineer Sr Stf - E5

Lockheed Martin • East Hagbourne

On-site
GBP 65,000 - 110,000
Security Architect (Outside IR35, DV cleared)
Security Architect (Outside IR35, DV cleared)

LA International • Basingstoke

On-site
GBP 60,000 - 80,000
Information Assurance Engineer Sr Stf - E5
Information Assurance Engineer Sr Stf - E5

Lockheed Martin Corporation • East Hagbourne

On-site
GBP 65,000 - 95,000
Security Assurance Lead - Secure, on-site Hampshire
Security Assurance Lead - Secure, on-site Hampshire

DXC Technology • England

On-site
GBP 55,000 - 75,000