Enable job alerts via email!

C004173 CIS Security Program Manager (Cyber Security)

McBride Consulting

England

On-site

GBP 80,000 - 100,000

Full time

10 days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a dedicated security specialist to enhance their cyber defense initiatives. In this pivotal role, you will apply and maintain security controls, manage endpoint security components, and provide critical advice on security compliance. Your expertise in vulnerability assessments and incident management will be essential in safeguarding operations. This position offers a unique opportunity to contribute to an organization that values security and compliance in a dynamic environment. If you are passionate about cyber security and eager to make a significant impact, this role is perfect for you.

Qualifications

  • Experience in managing information assurance or security compliance programs.
  • Familiarity with NATO Security Directives and ITIL Version 4 concepts.

Responsibilities

  • Applies and maintains security controls as required by organizational policy.
  • Supports investigation of suspected attacks and security breaches.
  • Documents routine processes in Standard Operating Procedures.

Skills

Information Assurance Management
Security Compliance Programs
Incident Management
Vulnerability Assessment
Cyber Security Monitoring
Training Delivery

Education

NATO Cosmic Top Secret Clearance

Tools

Trellix ePolicy Orchestrator
Nessus
Microsoft Windows
ITIL Version 4

Job description

Job Description

Under the direction of the Section Head MSS Cyberspace Security (NSO OCY 0050), the incumbent will perform duties such as the following:

  1. Applies and maintains specific security controls as required by organizational policy and local risk assessments
  2. Drafts and maintains documents supporting security accreditation for CIS in AOR
  3. Drafts and maintains CIS Security policy documents
  4. Liaises with operational partners to ensure security accreditation compliance requirements
  5. Supports investigation of suspected attacks and security breaches
  6. Provides detailed and specific advice regarding the application of their specialism to the organization's planning and operations
  7. Assists in infrequent, limited management of Trellix ePolicy Orchestrator (ePO) and Endpoint Security (ENS) components required by NATO Cyber Security Centre (NCSC) policy on local and remote (deployed) devices in two security domains
  8. Manages endpoint security components on disconnected and standalone devices in AOR
  9. Monitors CIS logs for suspicious or anomalous activity and reports as required
  10. Documents routine processes in Standard Operating Procedures
  11. Configures and distributes two-factor authentication devices
  12. Performs trend analysis of routine vulnerability assessments using automated and semi-automated tools, including Nessus
Tenable
  1. Provides vulnerability mitigation advice to stakeholders
  2. Supports external service providers in management of local boundary protection and cyber security monitoring infrastructure
  3. Provides CIS Security advice and training, as required
  4. Executes the incident and change management processes in accordance with the Information Technology (IT) Information Library (ITIL) Version 4 framework
  5. Contributes to Asset Configuration Patching and Vulnerability Management activities
  6. Experience in developing, sourcing, and/or delivering training
  7. Performs other related duties, as required
Requirements
  1. Familiarity with NATO Security Directives
  2. Experience in managing information assurance or security compliance programs
  3. Experience drafting Standard Operating Procedures and directive policy documents
  4. Familiarity with Microsoft update and patch management systems, IT security frameworks and governance models, and Common Vulnerability Scoring System (CVSS) v3.X or later standards
  5. Familiarity with ITIL Version 4 concepts including Configuration Management and Service Asset Management
  6. Experience with Microsoft Windows desktop operating systems
  7. Experience with Microsoft Windows server operating systems including key components such as Active Directory, Group Policy, New Technology File System permissions, Dynamic Host Control Protocol
  8. Experience with key Information Technology concepts including shared storage, clustering, and virtualization
  9. Familiarity with security and network technologies such as IPv6, Firewalls, Virtual Private Networks, Public Key Infrastructure, Intrusion Detection, and Forensic Appliances
  10. Familiarity with International Organization for Standardization (ISO)/International Electro-technical Commission (IEC) 27001 framework
  11. Assists in developing, sourcing, and/or delivering CIS security training to operational partners and unit staff
  12. Prior experience of working in an international environment or organizations comprised of both military and civilian elements
Education and Clearance
  • NATO Cosmic Top Secret
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.