Security Testing and Assurance Manager
Alexander Mann Solutions - Public Sector Resourcing
Job Description
On behalf of Companies House, we are looking for a Security Testing and Assurance Manager Inside IR35 for a 6 month contract based remotely.
Companies House drives confidence in the economy and makes the UK a great place to start, and run, a business.
SC Clearance is an essential requirement for this role, as a minimum you must be willing & eligible to undergo checks. Please note, due to the exceptional requirements of this position (short-term nature of this role and speed at which we require a postholder in situ) preference may be given to candidates who meet all of the essential criteria and hold active SC clearance.
As an executive agency sponsored by The Department for Business and Trade (DBT) we have the ability to play a leading role in the right against corrupt business practices by providing the transparency and clarity necessary for the UK to continue to be regarded as a world-leading place to do business.
Companies House is undergoing an historic change - to our systems, culture, services, and ways of working. Our people are at the heart of these changes.
The Economic Crime and Corporate Transparency Act (2023) gives Companies House the power to play a more significant role in disrupting economic crime and supporting economic growth.
These changes represent the biggest opportunity for Companies House in almost 170 years. This move will help us achieve the kind of culture we want - one which drives high performance and where our brilliant people can flourish.
As a Security Testing and Assurance Manager, your main responsibilities will be:
. Lead the planning, coordination, and delivery of security testing across applications, APIs, cloud platforms, networks, and infrastructure. . Manage relationships with internal and external penetration testing providers, ensuring high-quality and timely delivery of assessments. . Review penetration test reports, validate findings, and assess business impact and risk. . Own the triage, prioritisation, tracking, and remediation of security vulnerabilities through to resolution. . Ensure security issues are accurately logged, assigned, and monitored using tools such as Jira. . Develop and maintain security testing standards, methodologies, and quality assurance processes. . Produce security risk assessments and provide clear recommendations to technical and business stakeholders. . Report on security posture, vulnerability trends, remediation progress, and key risk metrics. . Support security accreditation, audit, and compliance activities against frameworks such as ISO 27001, NIST, GovS 007, and Cyber Essentials. . Work closely with architects, developers, platform engineers, delivery teams, and risk functions to drive security improvements. . Support the development and implementation of information security policies, standards, procedures, and guidance. . Contribute to incident response activities, risk assessments, and wider cyber security assurance initiatives.
Essential Skills & Experience . Strong experience leading security testing, vulnerability management, or cyber security assurance functions. . Experience managing penetration testing programmes and third-party security testing suppliers. . Proven ability to assess, prioritise, and drive remediation of security vulnerabilities. . Strong understanding of application security, infrastructure security, cloud security, and API security. . Experience producing security risk assessments and presenting findings to senior stakeholders. . Knowledge of security governance, risk management, and compliance frameworks. . Experience working with vulnerability tracking and management tools such as Jira. . Excellent stakeholder management and communication skills, with the ability to engage both technical and non-technical audiences.
Technical Knowledge . Vulnerability Management . Penetration Testing . Security Assurance . Risk Management . Cloud Security . Application Security . Infrastructure Security . Networking . Encryption Technologies . Microsoft Technologies . Linux Platforms . Incident Management
Desirable Experience . ISO 27001, NIST, GovS 007, Cyber Essentials, or similar security frameworks. . GDPR and Data Protection Act 2018 knowledge. . Experience operating within an ITIL-based environment. . Public sector, government, or highly regulated industry experience. . Security audit and accreditation support experience.
What We're Looking For . A security professional who can bridge the gap between cyber security testing, assurance, and risk management. . Someone capable of challenging remediation activities and driving security improvements across multiple teams. . A strong communicator who can influence stakeholders, manage suppliers, and provide clear security guidance at all levels. . An individual who can provide confidence that digital services meet organisational security requirements and industry best practice.
Please be aware that this role can only be worked within the UK and not Overseas.
Armed Forces Covenant/Commitment
As a signatory of the Armed Forces Covenant, Companies House welcome applications from veterans, service leavers, reservists and military spouses or partners. Applications from eligible candidates who meet the essential criteria for the role will be prioritised for review. Where application volumes are high, additional role-specific and desirable criteria may be applied as part of the shortlisting process which may include holding active security clearance.
In applying for this role, you acknowledge the following "this role falls in scope of the Off Payroll Working in the Public Sector legislation. Any rates of payment quoted will reflect the gross rate per day for the assignment and will be subject to appropriate taxes and statutory costs. As such the payment to the intermediary and your income resulting from this contract will be different".