C004173 CIS Security Program Manager (Cyber Security) (CTS) UK - 10 Apr

JobAdder
Be-Ach
2 weeks ago
Create job alert

Deadline Date: Thursday 10 April 2025
 
Requirement: CIS Security Program Manager (Cyber Security)
 
Location: Northwood, GB ,UK
 
Full Time On-Site: Yes
 
Time On-Site: 100%
 
Not to Exceed Rate: 54 EUR
 
Total Scope of the request (hours): 836
 
Required Start Date: 26 May 2025
 
Required Security Clearance: NATO COSMIC TOP SECRET
 
Duties and Role:
Under the direction of the Section Head MSS Cyberspace Security (NSO OCY 0050) the incumbent will perform duties such as the following:

  • Applies and maintains specific security controls as required by organizational policy and local risk assessments
  • Drafts and maintains documents supporting security accreditation for CIS in AOR
  • Drafts and maintains CIS Security policy documents
  • Liaises with operational partners to ensure security accreditation compliance requirements
  • Supports investigation of suspected attacks and security breaches
  • Provides detailed and specific advice regarding the application of their specialism to the organization's planning and operations
  • Assists in infrequent, limited management of Trellix ePolicy Orchestrator (ePO) and Endpoint Security (ENS) components required by NATO Cyber Security Centre (NCSC) policy on local and remote (deployed) devices in two security domains
  • Manages endpoint security components on disconnected and standalone devices in AOR
  • Monitors CIS logs for suspicious or anomalous activity and reports as required
  • Document routine processes in Standard Operating Procedures
  • Configures and distributes two-factor authentication devices
  • Performs trend analysis of routine vulnerability assessments using automated and semi-automated tools, including Nessus Tenable
  • Provides vulnerability mitigation advice to stakeholders
  • Supports external service providers in management of local boundary protection and cyber security monitoring infrastructure
  • Provides CIS Security advice and training, as required
  • Executes the incident and change management processes in accordance with the Information Technology (IT) Information Library (ITIL) Version 4 framework
  • Contributes to Asset Configuration Patching and Vulnerability Management activities
  • Experience in developing, sourcing and/or delivering training
  • Performs other related duties, as required

Specific Working Conditions: 
Personal Liability and comprehensive insurance required
 
Requirements:
 
Skill, Knowledge & Experience:

  • The candidate must have a currently active NATO COSMIC TOP SECRET security clearance
  • Familiarity with NATO Security Directives
  • Experience in managing information assurance or security compliance programs
  • Experience drafting Standard Operating Procedures and directive policy documents
  • Familiarity with Microsoft update and patch management systems, IT security frameworks and governance models, and Common Vulnerability Scoring System (CVSS) v3.X or later standards
  • Familiarity ITIL Version 4 concepts including Configuration Management and Service Asset Management
  • Experience with Microsoft Windows desktop operating systems;
  • Experience with Microsoft Windows server operating systems including the following key components such as Active Directory, Group Policy, New Technology File System permissions,  Dynamic Host Control Protocol;
  • Experience with key Information Technology concepts including shared storage, clustering and virtualization;
  • Familiarity with security and network technologies such as IPv6; Firewalls, Virtual Private Networks, Public Key Infrastructure, Intrusion Detection and Forensic Appliances;
  • Familiarity with International Organization for Standardization (ISO)/International Electro-technical Commission (IEC) 27001 framework.
  • Assists in developing, sourcing and/or delivering CIS security training to operational partners and unit staff
  • Prior experience of working in an international environment or organizations comprised of both military and civilian elements

Get the latest insights and jobs direct. Sign up for our newsletter.

By subscribing you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Contract vs Permanent Cybersecurity Jobs: Which Pays Better in 2025?

Cybersecurity has become one of the fastest-growing and most crucial fields in modern business. With high-profile breaches dominating headlines and the ongoing digital transformation exposing organisations to new threats, companies across the UK are competing to attract skilled cybersecurity professionals. Roles range from penetration testers (pen testers) and SOC (Security Operations Centre) analysts to compliance officers, cloud security architects, threat intelligence analysts, and CISOs (Chief Information Security Officers). As demand continues to surge, cybersecurity salaries have climbed accordingly, and businesses have turned to more flexible hiring practices. Alongside permanent employment, many professionals explore short-term day‑rate contracting or fixed-term contracts (FTCs), searching for the ideal balance of pay, job security, and growth opportunities. Which arrangement truly pays better in 2025—and which best aligns with your ambitions? In this article, we dive into the contract vs. permanent debate with a focus on cybersecurity roles. We will examine the current market, the structure of day‑rate vs. FTC vs. permanent positions, the pros and cons of each, and some hypothetical pay comparisons. By the end, you should have a clearer sense of which career path might suit your situation and goals—whether you are a seasoned specialist aiming for top rates, or an up-and-coming analyst seeking a stable environment to develop in.

Cyber Security Jobs for Non‑Technical Professionals: Where Do You Fit In?

Defence Needs More Than Hackers in Hoodies When headlines warn of ransomware crippling hospitals or deepfakes swaying elections, we picture hoodie‑clad hackers and elite penetration testers. Yet the reality of the UK’s cyber security sector is broader—and desperately short of talent. The Department for Science, Innovation & Technology (DSIT) estimates a shortfall of 11,200 cyber security professionals in 2024, while 43 % of advertised roles require governance, risk or communication skills rather than hands‑on technical exploits. Put plainly: if you can guide policy, manage projects, interpret regulations or inspire behaviour change, cyber security wants you. This guide highlights the fastest‑growing non‑technical roles, the transferable skills you already possess, and a concrete 90‑day plan to land a cyber security job—no packet sniffers required.

BAE Systems Cybersecurity Jobs in 2025: Your Complete UK Guide to Protecting Governments, Businesses and Critical Infrastructure

From securing the Royal Navy’s new Dreadnought submarines to foiling multimillion‑pound fraud rings, BAE Systems Digital Intelligence (DI)—formerly Detica—sits at the sharp end of global cyber defence. Head‑quartered in Guildford with hubs in Gloucester, Leeds and London, the 5,500‑strong DI business delivers threat‑intelligence platforms, secure‑by‑design software and 24/7 SOC services to government and commercial clients worldwide. With escalating ransomware, AI‑driven disinformation and complex supply‑chain threats, BAE plans to expand its UK cyber workforce by 20 % in 2025. Whether you’re a graduate passionate about reverse engineering, a DevSecOps engineer who loves IaC, or an incident‑response pro comfortable in high‑side environments, this guide explains how to land a BAE Systems cybersecurity job in 2025.