M4, an IT Delivery Practice, is a forward-thinking and fast-growing SME with an established UK client base. As the next stage in our expansion plan, we require the services of a Security Assurance Subject Matter Expert (SME).
Role Overview
We are seeking an experienced Security Assurance SME to play a crucial role in designing, engineering, testing, and implementing security solutions for a Strategic Infrastructure business. Your expertise will shape the security posture of critical business products, ensuring alignment with industry best practices, government frameworks, and compliance standards. You will provide specialist security architecture oversight, advice, and guidance across projects and functions to ensure information assets, materials, and equipment operate under an acceptable risk management regime.
While candidates are not expected to possess every skill listed in this specification, successful applicants will demonstrate in-depth expertise in several key operational areas, supported by a broad, well-rounded understanding across the wider domain. Breadth and depth of experience, particularly within global organizations or enterprise-scale environments, will significantly enhance an application.
Key Accountabilities:
Risk & Threat Analysis: Provide comprehensive risk analysis on information systems to inform risk owners, project managers, and executive leadership, enabling effective decision-making. Lead Security Risk Management workshops.
Executive & Advisory Support: Provide expert subject matter advice to the CTO, CSO, senior management, and project delivery teams. Act as a Security Business Partner across the organization and serve as the primary technical interface to official security bodies, including the UK National Cyber Security Centre (NCSC).
Security Architecture & Design: Design end-to-end service security architectures, define key security controls, and review high- and low-level solution designs for compliance and operational efficacy.
Standards, Compliance & Governance: Develop, maintain, and enforce information security policies, standards, and procedures. Conduct and document compliance assessments against frameworks such as the Cyber Assessment Framework (CAF) and Secure by Design (SbD) principles, while embedding Information Risk Management best practices across the organization.
Key Responsibilities:
Security Architecture & Governance: Author, review, and enforce security policies, standards, and governance frameworks. Define and evaluate architectural patterns, gateway/network topologies, and security tooling integrations. Determine how security architecture applies to active projects and advise technical solution architects on specific security requirements.
Security & Cyber Assurance: Conduct and review assessments against Secure by Design (SbD) principles, the Cyber Assessment Framework (CAF), and lightweight security assurance methodologies for projects, SaaS platforms, and cloud services. Liaise with Data Protection leads to manage Data Protection Impact Assessments (DPIAs) and evaluate supplier compliance with UK GDPR, data residency, and transfer risks.
IT Health Check (ITHC) & Penetration Testing: Oversee the end-to-end delivery of ITHCs and vulnerability assessments. This includes managing ITHC contracts, defining and reviewing Principal Security Concerns (PSCs), drafting scoping documentation, overseeing execution, agreeing remediation plans with stakeholders, and driving findings to resolution.
Procurement & Vendor Risk Management: Provide technical security evaluations for procurement tenders, supplier bids, and third-party tooling for government IT contracts. Assess vendor products and third-party software against operational risks, UK data protection legislation, UK/EU data sovereignty, and international data transfer considerations.
Smart Buildings, IoT & Network Security: Assess and secure connected building technology systems, including IoT sensor arrays, IP Telephony, digital signage, and room booking infrastructure. Collaborate with service delivery and ITSM partners to maintain overall network environment security and cloud/network assurance.
Strategic Guidance & Leadership: Advise leadership on emerging strategic initiatives, such as Post-Quantum Cryptography (PQC) Migration and network protocol upgrades. Chair or participate in project Security Working Groups to track and manage risk mitigation plans.
Relevant Technical & Functional Experience:
Cloud & Network Assurance: Hands-on experience assessing cloud hosting environments, SaaS platforms, network architecture security, and Identity & Access Management (IAM) tooling.
Government & Defence Cyber Frameworks: Direct experience applying NCSC guidelines, GovAssure, Cyber Assessment Framework (CAF), and Secure by Design (SbD) principles within highly regulated sectors such as Government, Defence, or Finance.
Third-Party Risk & Privacy: Practical experience evaluating vendor tooling against UK data protection law (UK GDPR), data sovereignty rules, and international transfer risks.
Penetration Testing/ITHC Management: Demonstrable track record managing complete ITHC lifecycles, including defining scoping parameters, establishing Principal Security Concerns (PSCs), evaluating vulnerability reports, and driving stakeholder remediation.
IoT & Operational Technology Security: Experience assessing and securing smart building systems, connected IoT devices, IP telephony, and associated network infrastructures.
Role Details
Job Type: Contract
Duration: TBC
Location: TBC
IR35 Status: Outside IR35
Security Clearance: Applicants must hold, or be eligible to obtain, SC Clearance.
Please advise on availability and rate expectations upon application.
Discovering Direct IT Contract Opportunities for Contract Spy members.