Security Delivery Lead
Listed on 2026-10-08
-
Security
Cybersecurity, Information Security & Data Protection, Security Management & Operations -
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Job Description:
DXC Technology is committed to building diverse, inclusive teams. We welcome applications from all backgrounds and particularly encourage interest from women, underrepresented groups, and neurodivergent candidates. We offer reasonable adjustments throughout the hiring process and are dedicated to creating a supportive, accessible environment for everyone.
Security Delivery Lead
Location:
Farnborough (onsite 5 days per week) Due to the nature of the work and the customers we support, the successful candidate must be eligible to meet UK Government and contractual personnel security requirements, including the applicable residency requirements for the role, and have the right to work in the United Kingdom. Some roles may also be subject to nationality requirements where these are necessary to meet UK Government or contractual security obligation
The Security Delivery Lead is the senior security subject matter expert (SME) accountable for the development, implementation, and maintenance of the security assurance regime across the service. This role owns the security policies, procedures, and governance framework that underpin the Contractor's compliance with client security requirements, accreditation obligations, and defence security standards.
This is a leadership and accountability role — not a technical implementation role. The Security Delivery Lead is responsible for ensuring the organisation's overall defence security posture is maintained, evidenced, and continuously improved. The role is the single point of accountability for security assurance, accreditation support, risk governance, and policy compliance across the service delivery lifecycle.
Key Responsibilities Security Assurance Regime- Develop, implement, and maintain the security assurance regime for the service — defining the framework, processes, activities, and evidence requirements that demonstrate ongoing security compliance.
- Establish and own the security assurance schedule — ensuring assurance activities are planned, executed, evidenced, and reported on a recurring basis.
- Define and maintain the security assurance evidence framework — specifying what evidence is required, how it is collected, where it is stored, and how it is presented to accreditation authorities and client security teams.
- Act as the Contractor's primary point of contact for all security accreditation matters — engaging with the client's Security Accreditation Authority, Information Asset Owners, and Senior Information Risk Owners (SIROs).
- Support the accreditation lifecycle.
- Maintain a register of all accreditation conditions, caveats, and risk acceptances — tracking compliance and closure.
- Develop, maintain, and enforce security policies and procedures that ensure the Contractor's compliance.
- Conduct regular policy reviews to ensure currency with evolving client requirements, regulatory changes, and threat landscape developments.
- Manage policy exceptions and deviations through a formal process — ensuring exceptions are risk-assessed, time-bound, approved, and tracked.
- Establish and maintain the security risk governance framework for the service — defining how security risks are identified, assessed, recorded, escalated, treated, and reported.
- Own and maintain the security risk register.
- Chair or participate in security risk governance forums — presenting risk posture, emerging threats, and treatment progress to senior leadership and client stakeholders.
- Ensure the Contractor's ongoing compliance with all applicable security policies, standards, regulations, and contractual obligations.
- Develop and maintain a…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).