Overview
Key Responsibilities - Information Security Governance & Policy Act as a subject matter expert on information security governance for UK national security programmes. Translate government and customer security requirements into scalable, operationally workable controls. Provide independent advice and constructive challenge where security, contractual or compliance obligations may be at risk. Support audits, inspections, assurance reviews and customer accreditation activity. Maintain awareness of evolving UK Government security policy, regulation and the national security threat landscape. Provide information security leadership across the programme lifecycle, from early engagement and tenders through delivery and operation. Work with programme management and engineering teams to embed security in programme design and delivery. Support the development and maintenance of Security Managemen
Full job description
Full Job Description
Key Responsibilities - Information Security Governance & Policy Act as a subject matter expert on information security governance for UK national security programmes. Translate government and customer security requirements into scalable, operationally workable controls. Provide independent advice and constructive challenge where security, contractual or compliance obligations may be at risk. Support audits, inspections, assurance reviews and customer accreditation activity. Maintain awareness of evolving UK Government security policy, regulation and the national security threat landscape. Provide information security leadership across the programme lifecycle, from early engagement and tenders through delivery and operation. Work with programme management and engineering teams to embed security in programme design and delivery. Support the development and maintenance of Security Management Plans, procedures and assurance documentation. Ensure information security risks are identified, documented, reviewed and escalated through appropriate governance. Advise on security obligations within Statements of Work and related contractual documents. Support customer discussions where security requirements require clarification or negotiation. Ensure agreed security requirements transition effectively into programme delivery. Support security risk assessments across UK national security programmes. Ensure significant security risks are escalated to the appropriate risk owner or governance body. Provide information security assurance to programme leadership and senior stakeholders. Support remediation, assurance assessments, accreditation reviews and security testing. Provide guidance on the handling, storage, sharing, transfer, retention and disposal of sensitive information. Support secure document management and customer-specific information handling requirements. Advise on restricted collaboration environments, ethical firewalls and information-separation controls. Provide information security advice and support during security incidents affecting relevant programmes. Ensure potential incidents are identified, recorded and escalated appropriately. Support proportionate, independent incident investigations where required. Ensure lessons learned are reflected in programme controls, guidance and training. Develop security briefings for programme leadership, senior executives and customers. Develop positive relationships with legal colleagues within the UK & Ireland Legal Affairs team, with UK government affairs colleagues and with colleagues in the wider EMEA region to coach and advise on compliance issues. Support programme-specific security briefings, training and awareness material. Support and collaborate with NST Personnel Security Controller and Facility Manager. Collaborate with service providers to develop strategies and innovative solutions to address business issues and achieve business objectives. International travel will be required from time to time. Demonstrable experience in information security, operational security, programme security or a government security role. The successful candidate is a sole UK National and hold, or be able to obtain and maintain, the UK Government security clearance required for the role (DV). Knowledge of UK Government security policy, security controls and government information handling requirements. Demonstrable experience supporting large, complex programmes for UK Government, defence or national security customers. Experience interpreting contractual security requirements and translating them into practical operational controls. Experience managing information security risk, assurance or accreditation activities. Stakeholder-management skills, including engagement with leaders, customers and multidisciplinary delivery teams and ability to establish a “trusted advisor” relationship. An ability to work independently while also being a collaborator with the ability to work with colleagues based in different locations. A high tolerance for ambiguity and change. Desirable CISSP, CISM, CCSP.
Tips for this job
Practical JobOpportunity guidance. These tips do not replace official rules or create new eligibility requirements.
- Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
- Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
- Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
- Apply through the original employer or official recruitment destination shown on this page.
Verification notes
Verified from public schema.org JobPosting structured data on the official source page. The complete published description, responsibilities, requirements and benefits were normalized when present; unstated facts were not inferred.
JobOpportunity is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.
Apply through JobOpportunity →Browse current JobOpportunity listings from Microsoft Careers →