Overview
This contract position seeks an experienced Information Security / Information Assurance professional to join a consultancy specializing in high-impact transformation and modernization projects within the Public and Defence sectors. The role involves collaborating with technical teams, stakeholders, and delivery partners to ensure that systems and services comply with security standards while managing security risks effectively.
Responsibilities
- Provide Information Security and Information Assurance guidance across complex programmes and projects.
- Conduct security risk assessments and identify appropriate risk treatment and mitigation measures.
- Support the development, review and maintenance of security documentation and assurance artefacts.
- Assess systems, architectures and technical solutions against relevant security policies, standards and frameworks.
- Work closely with architects, engineers, project teams and stakeholders to embed security throughout the delivery lifecycle.
- Identify, document and communicate security risks, vulnerabilities and control requirements.
- Support security governance, assurance reviews and accreditation activities.
- Provide clear security advice to both technical and non-technical stakeholders.
Requirements
- Strong experience within Information Security, Information Assurance or Cyber Security roles.
- Proven experience conducting security risk assessments and managing security risks.
- Good understanding of security governance, controls, policies and assurance processes.
- Experience working with recognised security standards and frameworks such as ISO 27001, NIST or NCSC guidance.
- Ability to review technical designs and translate security requirements into practical controls.
- Strong stakeholder management and communication skills, engaging effectively across technical and business teams.
- Experience working within complex transformation, infrastructure or technology programmes.
- Previous experience within Public Sector, Defence or other highly regulated/sensitive environments is desirable, but not essential.