Enable job alerts via email!

CIS Security Program Manager (Cyber Security)

Alfa Rom Consulting SRL

Greater London

On-site

GBP 50,000 - 90,000

Full time

7 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a CIS Security Program Manager with a strong background in cyber security. This role involves applying and maintaining security controls, drafting essential security policy documents, and ensuring compliance with NATO directives. The successful candidate will manage endpoint security components, monitor CIS logs for anomalies, and provide training on CIS security practices. Join a dynamic team where your expertise will significantly contribute to safeguarding critical information and enhancing security measures in a collaborative environment. This is an exciting opportunity for professionals passionate about cyber security and compliance.

Qualifications

  • Active NATO COSMIC TOP SECRET security clearance is mandatory.
  • Experience in managing information assurance or security compliance programs is required.

Responsibilities

  • Maintain security controls as per organizational policy and risk assessments.
  • Support investigation of suspected attacks and security breaches.

Skills

NATO COSMIC TOP SECRET security clearance
Information assurance management
Security compliance programs
Standard Operating Procedures drafting
IT security frameworks
ITIL Version 4 concepts
Microsoft Windows operating systems
Network technologies
International standards compliance
Training development and delivery

Tools

Microsoft update and patch management systems
Nessus Tenable

Job description

2 527 4 - CIS Security Program Manager (Cyber Security)

Location: Northwood, United Kingdom.

Period: 836 (start on 26 May 2025).

Deadline: 10 Apr. 2025.

Duties/Roles:

  1. Applies and maintains specific security controls as required by organizational policy and local risk assessments;
  2. Drafts and maintains documents supporting security accreditation for CIS in AOR;
  3. Drafts and maintains CIS Security policy documents;
  4. Liaises with operational partners to ensure security accreditation compliance requirements;
  5. Supports investigation of suspected attacks and security breaches;
  6. Provides detailed and specific advice regarding the application of their specialism to the organization's planning and operations;
  7. Assists in infrequent, limited management of Trellix ePolicy Orchestrator (ePO) and Endpoint Security (ENS) components required by NATO Cyber Security Centre (NCSC) policy on local and remote (deployed) devices in two security domains;
  8. Manages endpoint security components on disconnected and standalone devices in AOR;
  9. Monitors CIS logs for suspicious or anomalous activity and reports as required;
  10. Documents routine processes in Standard Operating Procedures;
  11. Configures and distributes two-factor authentication devices;
  12. Performs trend analysis of routine vulnerability assessments using automated and semi-automated tools, including Nessus Tenable;
  13. Provides vulnerability mitigation advice to stakeholders;
  14. Supports external service providers in management of local boundary protection and cyber security monitoring infrastructure;
  15. Provides CIS Security advice and training, as required;
  16. Executes the incident and change management processes in accordance with the Information Technology (IT) Information Library (ITIL) Version 4 framework;
  17. Contributes to Asset Configuration Patching and Vulnerability Management activities;
  18. Experience in developing, sourcing and/or delivering training;
  19. Performs other related duties, as required.

Skills, Knowledge, Experience Required:

Mandatory:

  1. The candidate must have a currently active NATO COSMIC TOP SECRET security clearance;
  2. Familiarity with NATO Security Directives;
  3. Experience in managing information assurance or security compliance programs;
  4. Experience drafting Standard Operating Procedures and directive policy documents;
  5. Familiarity with Microsoft update and patch management systems, IT security frameworks and governance models, and Common Vulnerability Scoring System (CVSS) v3.X or later standards;
  6. Familiarity with ITIL Version 4 concepts including Configuration Management and Service Asset Management;
  7. Experience with Microsoft Windows desktop operating systems;
  8. Experience with Microsoft Windows server operating systems including the following key components such as Active Directory, Group Policy, New Technology File System permissions, Dynamic Host Control Protocol;
  9. Experience with key Information Technology concepts including shared storage, clustering and virtualization;
  10. Familiarity with security and network technologies such as IPv6; Firewalls, Virtual Private Networks, Public Key Infrastructure, Intrusion Detection and Forensic Appliances;
  11. Familiarity with International Organization for Standardization (ISO)/International Electro-technical Commission (IEC) 27001 framework;
  12. Assists in developing, sourcing and/or delivering CIS security training to operational partners and unit staff;
  13. Prior experience of working in an international environment or organizations comprised of both military and civilian elements.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.