SSTL Information and Cybersecurity Assurance Manager Security & Facilities
Listed on 2026-08-21
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
SSTL Information and Cybersecurity Assurance Manager
Responsible For
Executing a range of cybersecurity and information assurance work streams that contribute to the overall cybersecurity profile of SSTL, including product and service development. Owning the assurance of SSTL information and cybersecurity certifications, contracted information and cybersecurity deliverables, and delivery of Secure by Design in SSTL.
Reports To
Corporate Security Manager
Key Tasks
Identify, understand, and provide assurance against all elements of contractual security obligations for product and service deliverables, as well as information and cybersecurity certifications such as ISO 27001, CE+, and DCC
Ensure the delivery of relevant technical, framework and contract compliant governance, security strategies, policies, management plans, procedures, and processes, as well as supporting the review of organisational security governance in accordance with industry standards
Own the management of information and cybersecurity assurance artefacts and security control requirements against all contracted schedules, ensuring project lifecycle gateway and milestone success
Lead the facilitation of certification or contract dependent ITHCs, coordinate vulnerability management exercises and external penetration testing and ensure remediation actions are completed and verified
Review infrastructure, cloud, and application designs and current implementations against Secure by Design principles and perform risk assessments for new technologies and business initiatives, as well as participate in Change Advisory Board (CAB) meetings to provide security assurance
Support the implementation, delivery, and exercising of incident and business continuity response plans, and contribute to the lessons identified process
Act as a member of the incident response team in the event of a security incident
Contribute to security working groups, security steering boards, Executive and Board level reports, and any other management material as required
Own the management of Security Aspect Letters, compliance with them, and the creation of any flow down variations to suppliers and own the management and monitoring of third‑party supplier compliance
Own the security aspects of space licensing, ensuring all requirements are complete to facilitate the effective delivery and operation of spacecraft throughout their lifecycle
Accountable for the management of project level security budget, and contribute to accurate costing of project level security effort on future bids
Monitor and manage the delivery of security awareness and training in accordance with contractual or certification requirements
Success Criteria
All security aspects of contractual deliverables are successfully delivered in accordance with customer requirements and within timelines and budget
A portfolio of template Secure by Design security artefacts is made available for future use
Information and cybersecurity certification is successfully renewed on time without breaks
Space licencing for existing and new spacecraft is not delayed or hindered due to Security input
Established processes or methodologies, and compliance for technical and cybersecurity infrastructure
PERSON SPECIFICATION (essential requirements)
Qualifications
Either hold, or have held:
ChCSP, CISM, CISA, BCS CISMP, or CMIRM certification
Membership of a Cybersecurity or Information Risk Management professional body such as, but not limited to, CIISec and IRM
Must be able to hold National Security Vetting at SC or above, with a minimum unbroken UK residency of at least 5 years to be eligible to apply for National Security Vetting
Experience
Comprehensive and demonstrable experience of working in a Defence Secure by Design programme or project, particularly as a Delivery Team Security Lead, Delivery Team Security Engineer, or Security Assurance Coordinator Role
Proven ability to deliver security artefacts such as, but not limited to, Security Management Plans, Risk Registers and Risk Assessments, Security Requirements Documents, Security Aspects Letters, Threat Models and Vulnerability Assessments, Security Architecture Documents, Compliance…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: