Security Lead- DV Cleared- Outside IR35
Listed on 2026-06-14
-
IT/Tech
Cybersecurity, IT Consultant, Security Manager, Information Security
Security Lead- DV Cleared-Contract Outside IR35
Maidenhead, United Kingdom | Posted on 26/05/2026
VE3 is a technology and business consultancy focused on delivering end‑to‑end technology solutions and products. We have successfully serviced enterprises across multiple markets, including the public and private sectors. Our services span all aspects of business, providing a holistic approach to managing an organization. We are committed to providing technical innovations and tools that empower organizations with critical information to facilitate decision‑making that results in business transformation through cost savings and increased operational efficiency.
Our commitment to quality is adopted throughout the organization and sets the foundation for delivering our full suite of capabilities.
Role
Security Lead – DV Cleared (Contract Outside IR35)
Engagement
UK Public Sector — Oracle ERP Managed Service
Duration
Length of the managed service contract
Location
UK only. Hybrid with attendance at client locations across the UK. Some client secure‑area work required
Security clearance
DV (Developed Vetting) and UK Nationality — MANDATORY. Pre‑cleared candidates strongly preferred
Reports to
Account / Engagement Director
Key interfaces
Client security lead, client Information & Security function, client Security Operations Centre, internal Service Delivery Manager, Incident Manager, third‑party software vendor
The Security Lead is our accountable security owner for the managed service. The role leads on, and has day‑to‑day operational responsibility for, service security — working in collaboration with the client's Information & Security function, the client Security Operations Centre (SOC), the internal delivery team, and the third‑party software vendor.
This is a contractually‑named DV‑cleared key role and is a PASS/FAIL requirement under the Conditions of Participation.
ContextThe service processes HR, Finance and Project data including OFFICIAL‑SENSITIVE personal and financial data of UK civil servants and locally‑engaged staff across a large international footprint. The contractual security regime spans UK Government security policy, NCSC HMG IAS5, GDPR/DPA 2018, PCI‑DSS where applicable, and the client's Cyber Security Incident Response Plan. The SOC is operated 24×7 by the client and the Supplier is required to integrate, report into and support it.
KeyAccountabilities Day‑to‑day security leadership
- Lead and own day‑to‑day operational responsibility for service security across OPERATE and DEVELOP.
- Advise the client on security status and matters; identify and address risks; continuously maintain and improve the security posture.
- Act as the authoritative security voice in the client's Design Authority and Enterprise Architecture forums for security‑impacting changes.
- Own the clearance pipeline: ensure all Supplier staff who hold, process or discuss client data are SC‑cleared UK Nationals as a minimum, and that the named DV roles plus all 'full administrator' staff are DV‑cleared UK Nationals.
- Manage client‑sponsored SC and DV applications from the start of Transition, conducting reasonable diligence checks in advance.
- Oversee joiner/mover/leaver, privileged access management (PAM), role‑based access control (RBAC), and the monthly audit report on RBAC and environment access.
- Provide the required reports to the client SOC in agreed format and frequency.
- Support the SOC in resolving security incidents; document security use cases with the SOC; implement, maintain and support those SOC infrastructure components hosted within the cloud infrastructure.
- Co‑ordinate response to security incidents with the client's Cyber Security Incident Response Plan and ensure the Incident Manager and Service Delivery Manager are informed and aligned.
- Treat information security issues, weaknesses or deficiencies identified by the client as Security Incidents under the client's Cyber Security Incident Response Plan.
- Provide client auditors with access to security documentation, configurations of security‑enforcing technologies,…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: