Security Governance Risk and Assurance Manager

Peregrine
Manchester, Greater Manchester
8 months ago
Applications closed

Related Jobs

View all jobs

Cyber Advisory - Manager

Forvis Mazars Ludgate Hill, City And County Of the City Of London, United Kingdom

Security Assurance Manager

Experis City of London, United Kingdom

Technology Risk – Internal Audit (Cloud) - Associate Director

Intec Select Broad Street, Greater London, City And County Of the City Of London, United Kingdom
£100,000 – £120,000 pa

Security Architect

Triad South Camberwell, London, United Kingdom
£75,000 – £80,000 pa

Cyber Security Assurance Specialist

GTC Recruitment Culham, Oxfordshire, OX14 4LY, United Kingdom
£50 – £55 ph Hybrid Clearance Required

Solution Architect

Adecco Worthing, West Sussex, United Kingdom
£800 pd Hybrid
Posted
26 Sep 2025 (8 months ago)

About the DCC:

At the DCC, we believe in making Britain more connected, so we can all lead smarter, greener lives. That desire to make a difference is what drives us every day and it wouldn’t be possible without our people. Each person at the DCC brings a special kind of power to the business, and if you join us, we’ll give you the means to unleash yours. Here, we depend on each other and hold each other accountable. You have the power to challenge and make change, to take the initiative and enjoy real responsibility. Whether it’s doing purposeful work, helping us grow or building the career you want – we’ll give you the support to do it all. Our secure network for smart meters is transforming Britain’s energy system and helping the country’s fight against climate change: we want you to be part of our journey.

The role:

The Information Security Assurance Manager is a hands-on, multi-disciplinary role combining project assurance, governance, risk management, and compliance. You will work across business units, projects, and suppliers to ensure security is embedded in everything we do—from design to delivery. You will also support the development and maintenance of our Information Security Management System (ISMS), lead internal audits, and provide expert guidance on risk mitigation and regulatory compliance.

Key Responsibilities:

Security Assurance & Project Engagement

Provide end-to-end security assurance across the Licence Renewal programme
Attend programme meetings to represent Information Security and provide expert guidance.
Review technical documentation (e.g., designs, network diagrams, data flows) to ensure alignment with security policies and architecture.
Conduct Information Security Impact Assessments and Data Protection Impact Assessments.
Support penetration testing and vulnerability assessments, tracking remediation to closure or handover to BAU.
Translate technical risks into business language for stakeholders.
Maintain alignment with ISO27001 and other frameworks (e.g., NIST).
Advise on compliance for staff, suppliers, and services.
Support procurement activities with security assessments and contract reviews.

Skills & Experience - Essential

Strong experience in Information Security across complex environments (e.g., outsourced, telecoms, energy).
Solid grasp of risk management methodologies (ISO27005, ISO31000).
Excellent communication skills—able to engage with technical and non-technical stakeholders.
Ability to work independently and collaboratively in a fast-paced environment.

Skills & Experience - Desirable

Recognised certifications: CISSP, CISM, CISA, CEH.
ISO27001 Lead Auditor / Implementer certification.
Knowledge of NIST Cybersecurity Framework and PKI.
Understanding of large public sector programmes.
Eligible for HMG SC clearance.

Personal Attributes

Analytical and detail-oriented with a proactive mindset.
Strong stakeholder engagement and influencing skills.
Able to prioritise effectively and remain calm under pressure.
Committed to continuous improvement and professional development.

Company benefits:

The DCC’s continued success depends on our people. It’s important to us that you enjoy coming to work, and feel healthy, happy and rewarded. In this role, you’ll have access to a range of benefits which you can choose from to create a personalized plan unique to your lifestyle.

If there are any questions you’d like to ask before applying, please contact [recruiter name, email address] or complete your application, so we can learn more about you. Your application will be carefully considered, and you’ll hear from us regarding its progress.

Join the DCC and discover the power of you

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Where to Advertise Cyber Security Jobs in the UK (2026 Guide)

Advertising cyber security jobs in the UK requires a different approach to most technical hiring. The candidate pool is small, heavily vetted and in high demand across government, financial services, critical national infrastructure and the private sector simultaneously. Many of the strongest candidates hold active security clearances, are not actively job-searching through general platforms, and move primarily through specialist networks and trusted referrals. General job boards reach a broad audience but lack the specificity that security professionals expect. Specialist platforms, government-affiliated channels and cleared candidate networks each serve a different part of the market. This guide, published by CybersecurityJobs.tech, covers where to advertise cyber security roles in the UK in 2026, how the main platforms compare, what employers should expect to pay, and what the data says about hiring across different role types.

Cyber Security Jobs UK 2026: What to Expect Over the Next 3 Years

Cyber security is one of the few sectors where demand for talent has never once dipped. Every major technological shift of the past decade — cloud migration, remote working, AI adoption, the proliferation of connected devices — has expanded the attack surface that security professionals are expected to defend. And every expansion of that attack surface has generated more jobs. But the cyber security jobs market of 2026 is not simply a larger version of what it was three years ago. It is a structurally different market. The threats have evolved, the technologies used to combat them have changed, the regulatory environment has tightened considerably, and the roles being created reflect all of that. A job seeker who understands only the cyber security landscape of 2023 is already working with an outdated map. The candidates who will thrive over the next three years are those who understand where the sector is heading — which specialisms are attracting the most investment, which technologies are reshaping defensive and offensive security practice, and how the definition of a cyber security professional is broadening well beyond the traditional image of a network defender in a SOC. This article breaks down what the UK cyber security jobs market is likely to look like through to 2028 — covering the titles emerging right now, the technologies driving employer demand, the skills that will matter most, and how to position your career ahead of the curve.

Penetration Tester Jobs in the UK: What Employers Actually Want in 2026

The demand for skilled professionals in cyber security has never been higher, and penetration testers sit at the very heart of this rapidly evolving industry. As organisations across the UK continue to digitise their operations, protect sensitive data, and defend against increasingly sophisticated threats, the need for ethical hackers has grown dramatically. If you are considering a career in this field—or looking to advance within it—it is essential to understand what employers are really looking for in 2026. This guide breaks down the current expectations, required skills, certifications, and practical experience that can help you stand out in a competitive job market.