Security Assurance Support Coordinator
Security Assurance Support Coordinator
Security As A Service (SyaaS)
Role purpose
The Mid-Level Delivery Team Security Lead (DTSL) will work within the Security as a Service function, supporting a range of programmes, projects and delivery teams as priorities require. The role is responsible for coordinating and delivering defined security-assurance work packages across products, platforms, applications and services, dependencies and supporting platforms. The post holder will help teams apply MOD Secure by Design throughout the capability lifecycle and maintain an evidence-based, proportionate and continually managed security posture.
The post holder will operate with a level of autonomy, taking ownership of assigned activities and artefacts while working under the direction of a Senior DTSL or designated security lead. They may move between projects or portfolios in response to delivery priorities and will engage directly with product owners, application and engineering teams, architects, platform teams and governance stakeholders, identify issues and dependencies, maintain accurate records, and escalate material risks, policy interpretations and acceptance decisions through the appropriate authority.
Key responsibilities
- Act as the day-to-day security assurance point of contact for an allocated portfolio with Senior DTSL or designated security-lead oversight.
- Support delivery teams to interpret and apply MOD Secure by Design requirements, embedding proportionate security activities into application discovery, design, development, integration, testing, release and in-service change.
- Register and maintain digital capabilities in the relevant MOD cyber-risk and assurance tooling, ensuring records, ownership, status and supporting evidence remain current.
- Plan and coordinate assurance activity, including defining the assurance approach, selecting an appropriate risk assessment method, identifying applicable control frameworks and agreeing proportionate evidence requirements.
- Produce, review and maintain security assurance artefacts, including Governance and Assurance Packs, security risk assessments and treatment plans, threat assessments, vulnerability-management plans, business continuity and disaster-recovery evidence, risk registers, executive summaries and Data Protection Impact Assessment inputs where required.
- Coordinate Secure by Design maturity and in-service assurance activity, including evidence mapping, gap analysis, action tracking and preparation for governance or assurance reviews.
- Facilitate periodic cyber-risk reviews with delivery teams, normally at least quarterly and following material application, architectural or service change, ensuring risks, actions, dependencies and decisions are recorded and progressed.
- Support capability registration and assurance progression, including preparation of evidence needed to unblock CAAT or equivalent assurance milestones.
- Monitor delivery against agreed assurance plans, provide concise status reporting, identify blockers and trends, and escalate significant residual risk or overdue actions to the Senior DTSL, designated security lead and accountable stakeholders.
- Maintain auditable assurance records in approved repositories, applying appropriate handling, access and classification requirements, including separation of OFFICIAL and SECRET material where applicable.
- Build effective working relationships across product, software engineering, architecture, testing, service management, data protection, platform and governance communities, helping stakeholders understand and discharge their security responsibilities.
- Contribute to continuous improvement of assurance templates, guidance, ways of working and knowledge-transfer material, and provide proportionate coaching to less-experienced colleagues.
Accountability and decision boundaries
The role may recommend assurance approaches, draft risk and control positions, coordinate evidence and challenge delivery teams within assigned work. Formal risk ownership, risk acceptance, policy exemption, accreditation or authority-to-operate decisions remain with the designated accountable authorities. Novel, high-impact, cross-project, cross-programme or materially disputed matters must be escalated to the Senior DTSL or designated security lead.
Essential experience and capabilities
- Practical experience in cyber security, information assurance, technology risk or security governance, with evidence of independently delivering defined assurance activities.
- Working knowledge of risk-management principles and recognised approaches such as NIST Risk Management Framework, ISO 31000 or equivalent.
- Ability to produce clear, proportionate and auditable security documentation, including risk assessments, treatment plans and assurance evidence.
- Ability to analyse system designs, data flows, interfaces, dependencies and technical and non-technical evidence; identify gaps or risks; and translate findings into practical actions for delivery teams.
- Experience of working with multidisciplinary stakeholders and communicating security risks, requirements and decisions clearly to both technical and senior audiences.
- Strong organisation and delivery skills, including action tracking, prioritisation, evidence management and concise status reporting across multiple concurrent work packages or projects.
- Sound judgement to work independently within delegated boundaries and to recognise when escalation or specialist advice is required.
- Experience in an MOD, wider government or similarly regulated environment, or an industry-recognised cyber security or information assurance qualification.
- A demonstrable commitment to continued professional development and to building deeper DTSL capability.
Desirable experience
- Experience applying MOD Secure by Design, JSP 440, JSP 453, the Defence Cyber Security Framework or associated defence assurance processes.
- Experience developing or reviewing Governance and Assurance Packs, in-service assurance questionnaires, control mappings, threat assessments, business continuity and disaster-recovery evidence, or vulnerability-management artefacts.
- Familiarity with MOD cyber-risk and assurance tooling, CAAT-related registration or comparable governance workflows.
- Relevant professional certification or development pathway, such as CCP, CISSP, CISM.
Role details
- Contract currently running until July 2028.
- The post holder must be eligible to obtain and maintain SC clearance and be willing to undergo Developed Vetting (DV) if the role requires it.
- The role requires effective operation in a defence environment and compliance with applicable security, information-handling and need-to-know requirements.
- Based in Semaphore Tower, Portsmouth, England.
Guidant, Carbon60, Lorien & SRG - The Vertage Group Portfolio are acting as an Employment Business in relation to this vacancy.
Apply to this Job
Share this Job