Sign up for the chance to get matched to this role, and similar opportunities.
Cyber Security Assessment Professional
Location: The role will primarily be hybrid working at UK based office (Manchester, Gloucester, Guildford or Leeds). This is to perform on-site assessment work (Classified Networks) or to connect with other employees for meetings and wellbeing purposes.
Role summary
What you’ll be doing
· BAE Systems has internal security assurance requirements from our Chief Information Security Officer covering all areas of the business. You would be part of that assurance activity within Digital Intelligence, to provide the firm with confidence that our security controls are implemented and are performant and also using your knowledge around remediation, when gaps are identified.
· Working within an established/documented controls framework (Secure by Design, to confirm controls aligned to the NIST 800-53 Framework are implemented and performant for a system or application across the Digital Intelligence networks. The firm has customised the core NIST 800-53 standard controls and documented this in the Group Cyber Security Standards (GCSS) which will be used as the compliance information needed to enable you to assess and measure against for compliance.
· Liaising with Information Management & Technology (IM&T) and Engineering System Managers to review their Level 1 self-assessments to ensure that the control evaluation evidence is complete. This evaluation serves as the Level 2 assessment and our second line of defence.
· Contributing to risk assessments as part of your work when evaluating the gaps in control effectiveness for each system.
Your skills and experiences
· Familiarity with industry standards and compliance frameworks, specifically NIST 800-53 but awareness of ISO 27001 and Cyber Essentials would be beneficial.
· Awareness and working experience of assessing security controls – specifically technical and administrative controls. Physical controls are out of scope as they are managed by a different part of the Security team at BAE Systems.
· Exposure to Operational Technology (OT) assurance aligned with NIST controls
· Ability to obtain a UK National Security Clearance (UKSC) or have existing UKSC clearance.
· Security control assessor attitude – attention to detail and proven skills in IT system audit.
· Excellent written and oral communication skills to enable working with stakeholders from different levels within the business - technical/non-technical.
· Adept at managing multiple priorities in a dynamic environment.
· Adopts a flexible approach to work, showcasing the ability to proactively take initiative and work independently, yet equally comfortable collaborating within a team where ideas and skills are shared.
· Outgoing personality to work with our wide range of stakeholders.
· Enthusiasm all things cyber security assurance and continuous learning to keep skills and knowledge current.
Sign up for the chance to get matched to this role, and similar opportunities.
Level up the hackajob way. Verify your skills, learn brand new ones and test your ability with Pathways, our learning and development platform.