Key Responsibilities
- Conduct risk assessments and recommend security mitigations.
- Develop security documentation (RMADS, SMPs, SyOPs).
- Ensure compliance with MOD standards like JSP 440, JSP 604, and Secure by Design.
- Manage system security risk registers and governance processes.
- Perform or oversee vulnerability assessments and penetration testing.
- Knowledge of MOD standards (e.g., JSP 440, Secure by Design).
- Experience with ISO27001, NIST, and similar frameworks.
- Ability to produce RMADS and other accreditation documentation.
- Strong risk management and technical security skills.
- Security Cleared (SC) or willing to undergo clearance.
- Relevant certifications: ISO27001 Lead Auditor, CISM, or CISSP.