Cybersecurity Assurance Manager - Secure by Design
UK Defence Sector | Guildford
We're recruiting on behalf of a leading organisation for a Security Assurance Manager to own cybersecurity and information assurance across their products, programmes and spacecraft lifecycle.
This is a genuinely broad, senior assurance role - spanning certification (ISO 27001, CE+, DCC), ITHCs, Secure by Design reviews, supplier security, and space licensing assurance. You'll sit across Change Advisory Boards, incident response, and executive-level reporting.
This is the one thing that matters most for this role:
You need to have personally delivered Secure by Design assurance within a Defence programme. Not just an understanding of the framework - hands-on ownership: engaging with system and design owners, running gap analysis against security controls, and taking something through to a real outcome such as Authority to Operate or formal accreditation. If that's not something you've genuinely done, please don't apply - the client has been explicit that there isn't time to build this knowledge up from scratch.
What you'll need:
- Hands-on Secure by Design delivery experience in a Defence programme - as a Delivery Team Security Lead, Delivery Team Security Engineer, or Security Assurance Coordinator
- Hold, or have held, CISM, CISA, BCS CISMP, ChCSP or CMIRM
- Membership of a cybersecurity or information risk body (CIISec, IRM, or similar)
- Eligible for National Security Vetting at SC or above, with 5+ years unbroken UK residency (DV desirable)
- Proven delivery of security artefacts — Security Management Plans, Risk Registers, Security Requirements Documents, RMADS, Threat Models
- Experience coordinating ITHCs, including scoping and remediation prioritisation
- Technical understanding at architecture, design and audit level
Desirable:
Knowledge of the space industry or aerospace communication systems.
If you've owned Secure by Design assurance on a Defence programme and can talk through a specific example of what you delivered and what it achieved, we'd like to hear from you.
