Cyber Security Assurance Specialist - Security-cleared
We are currently recruiting for an experienced Cyber Security Assurance Specialist to work a contract until mid-December this year with our client 2-3 days per week on-site in Culham, Oxfordshire.
Minimum Requirement:
This is a cross-functional role with both advisory and hands-on responsibilities, focusing on security assurance, risk management and supporting architecture reviews, vulnerability management, risk assessments, cyber defence posture, driving technical assurance, and embedding risk-aligned security controls across IT and OT systems and secure-by-design practices. You will work across hybrid environments including cloud, infrastructure, applications, and OT systems. You will be responsible for reviewing and advising on security architecture patterns, reviewing and maintaining risk registers, leading assurance assessments, and embedding security controls across infrastructure and platforms. You will also guide teams in applying secure-by-design principles and support both internal audit and external compliance efforts including Gov Assure, CAF, ISO 27001, and Cyber Essentials (CE and CE+) while supporting the secure operation of core services.
Essential:
- Demonstrable experience in designing and implementing secure infrastructure or cloud architectures.
- Proven experience with risk assessment methodologies and maintaining enterprise risk registers.
- Working knowledge of risk assessment methodologies (eg ISO 31000, FAIR, OWASP risk rating).
- Strong understanding of Gov Assure, CAF, ISO 27001, Cyber Essentials, and NIST frameworks.
- Experience conducting or supporting security audits and implementing remediation plans.
- Proficiency in assessing and securing platforms such as Entra ID (Azure AD), Microsoft 365 E5, Azure IaaS/PaaS, Windows/Linux/Unix.
- Strong knowledge of security tooling such as SIEM, endpoint detection (EDR/XDR), and vulnerability management platforms.
- Hands-on experience with policy development, access control models (RBAC, ABAC), and logging standards.
- Experience supporting assurance activities or government-mandated reviews (eg GovAssure, Secure by Design).
- Knowledge of Incident Management, Vulnerability Assessments, SIEM & SOC Systems.
- Familiarity with ITSM workflows and change control procedures
- Experience designing or reviewing secure software supply chain and CI/CD security.
- Ability to interpret CVEs, CVSS scores, and threat intelligence feeds.
- Strong stakeholder engagement and communication skills with an ability to produce technical reports and articulate risk to non-specialists.
- Excellent written and verbal communication skills with the ability to present to senior stakeholders.
Desirable:
- Degree in Cybersecurity, Information Technology, or a STEM subject (or equivalent experience).
- Security Assurance certifications such as CCP, SIRA
- Security certifications such as CISSP, SSCP, CISM, CRISC, CCSP, SABSA, or SANS GIAC (GSEC, GCCC, GCPM).
- Experience working in a regulated environment, particularly within research, energy, or national infrastructure.
- Knowledge of OT/ICS/SCADA security principles and industrial control environments.
If you feel you have the skills and experience needed for this role; please do apply now.
By applying for this job and submitting your CV to Parker Shaw, you acknowledge and give permission for us to pass it to an associate company for resourcing purposes. We outsource some of our resourcing calls to a trusted third-party company and they may call you to discuss this opportunity with you. They will then report back to us with the outcome of their conversation with you, where upon we will decide whether to submit your CV to the end client. Please be assured that the third-party company do not store or control any of your data, this is all done by ourselves (Parker Shaw).