Cyber Security Assurance Specialist
Key details
- Compensation
- $45,000 - $85,000
Job Description
Salary: £45,000 - 85,000 per year
Requirements
- We are looking for a Cyber Security Assurance Specialist with demonstrable experience designing and implementing secure infrastructure or cloud architectures.
- We need proven experience with risk assessment methodologies and maintaining enterprise risk registers.
- We require working knowledge of risk assessment approaches such as ISO 31000, FAIR, and OWASP risk rating.
- We need a strong understanding of Gov Assure, CAF, ISO 27001, Cyber Essentials, and NIST frameworks.
- We require experience conducting or supporting security audits and implementing remediation plans.
- We need proficiency in assessing and securing platforms such as Entra ID, Microsoft 365 E5, Azure IaaS/PaaS, and Windows/Linux/Unix.
- We require strong knowledge of security tooling including SIEM, endpoint detection, and vulnerability management platforms.
- We need hands-on experience with policy development, access control models, and logging standards.
- We require experience supporting assurance activities or government-mandated reviews such as GovAssure and Secure by Design.
- We need knowledge of incident management, vulnerability assessments, and SIEM and SOC systems.
- We require familiarity with ITSM workflows and change control procedures.
- We need experience designing or reviewing secure software supply chain and CI/CD security.
- We require the ability to interpret CVEs, CVSS scores, and threat intelligence feeds.
- We need strong stakeholder engagement and communication skills, with the ability to produce technical reports and explain risk to non-specialists.
- We require excellent written and verbal communication skills, including the ability to present to senior stakeholders.
- Security clearance eligibility for SC Clearance is required.
- We require the ability to work on site three days per week near Oxford, with no further flexibility on the on-site requirement.
Responsibilities
- We will have the Cyber Security Assurance Specialist conduct technical risk assessments on IT, OT, and cloud systems.
- We will have the specialist provide secure design guidance to digital projects across cloud, infrastructure, and applications.
- We will have the specialist maintain and update the security risk register on a quarterly basis.
- We will have the specialist evaluate critical technical changes for architectural risk, such as network reconfiguration and application onboarding.
- We will have the specialist document evidence gathering and remediation planning for Secure by Design, CAF, and GovAssure.
- We will have the specialist conduct internal technical assurance reviews aligned to GovAssure, CAF, and ISO 27001 domains.
- We will have the specialist maintain traceability of security controls to frameworks including NIST, Cyber Essentials Plus, and NCSC guidance.
- We will have the specialist evaluate suppliers against internal and external risk criteria for assurance.
- We will have the specialist contribute to the adoption of Zero Trust principles in platform design.
- We will have the specialist provide secure-by-design input into infrastructure, cloud, and application initiatives.
- We will have the specialist define security control templates for new deployments such as SaaS, Azure services, and OT upgrades.
- We will have the specialist deliver knowledge sessions to technical teams on secure configuration, threats, and compliance.
- We will have the specialist develop secure configuration guidance for platforms such as Entra ID, Linux, and Microsoft 365.
- We will have the specialist represent cyber security in architecture and design authorities.
- We will have the specialist produce and maintain technical security reports for assurance cycles.
- We will have the specialist support compliance audit evidence packs for GovAssure, CAF, Cyber Essentials Plus, and ISO 27001.
- We will have the specialist develop or update security standard documents such as threat modelling and vulnerability management.
- We will have the specialist support cyber input for IT, research, or OT programmes.
- We will have the specialist work with IT teams to co-author and test secure configuration standards and playbooks.
- We will have the specialist support security policy application in hybrid cloud, infrastructure, and application settings.
- We will have the specialist support audit and compliance activities through reporting and evidence gathering.
Technologies
- Azure
- CI/CD
- Cloud
- IaaS
- Support
- ITSM
- Linux
- Microsoft 365
- Network
- OWASP
- PaaS
- Security
- Unix
- Windows
- Office 365
More
We are recruiting a Cyber Security Assurance Specialist for our government client on a contract running until December 2026, with potential to extend. This is an inside IR35 role delivered through an umbrella solution, offering a rate of £45-55 per hour. The position is hybrid, with a fixed requirement to work on site three days per week in Abingdon, Oxfordshire, and the remainder remotely. The successful candidate must be eligible for Security Check clearance. We are looking for someone who can support assurance, compliance, and secure design across complex technical environments while working closely with technical teams and senior stakeholders. We also aim to make our recruitment process accessible and can accommodate reasonable adjustments where needed.
last updated 19 week of 2026
Company & context
Evidence is labeled so you can tell internal community data from public sources.
Range from 51 indexed roles at this employer: $35,000 - $137,800(mid ~64871)
Context may refresh in the background.
Trust-check this listing
Verify scam risk and ghost-job signals before you apply.
Related roles
Browse more remote Security Engineer jobs.
Offensive & Penetration Test Automation Engineer
Senior Visualfiles Developer - Home Working
Senior IT Systems Engineer
Source: DevITJobs • Last updated May 11, 2026