Cyber Security Manager
16 hours ago
Glasgow
Venesky-Brown’s client, a public sector organisation in Edinburgh, is currently looking to recruit a Cyber Security Manager for an initial 6 month contract with potential to extend on a rate of £700/day (Inside IR35). This role currently will be working from home, however from the end of October there will be a move towards hybrid working. Responsibilities: • Identify, design, and develop cyber security solutions across a wide variety of applications and infrastructure., • Lead the implementation of cyber security policy and standards., • Provide senior cyber security consultancy services (from risk assessments and audits to strategy development) across a variety of technology projects., • Engage with the Technology Architecture team and support the design of technology solutions and architecture for a variety of projects and programmes., • Engage with a broad range of internal and external stakeholders, providing cyber security assurance and managing the change process for the implementation of cyber security strategy, standards, and solutions., • Develop security operating procedures for use across multiple information systems or support compliance with them., • Apply routine security procedures appropriate to the role, such as patching, managing access rights, malware protection, or vulnerability testing with autonomy., • Develop and test rules for detecting violations of security operating procedures with autonomy., • Lead small teams managing Cyber Security operations within an organisation., • Champion secure design principles, frameworks, and standards for a digital service or programme., • Sponsor and direct the design of detailed low-level workflows, diagrams that describe input, output, and logical operation of a digital service. Design and develop the processes of a digital service through its full life cycle., • Lead and translate security requirements into application design elements including documenting specific security criteria., • Develop services by writing programming and scripting language., • Act as a subject matter expert (SME) for CI/CD pipeline security tools, lead software debugging and guide engineers to resolve issues., • Create and deliver automated assurance against Technical Security guidance and configurations., • Implement business logic and technical solutions to design out fraud and error., • Build and implement security audit points in digital services., • Drive secure coding practices and champion them, mentoring the engineering team to be able to undertake these tasks., • Support and empower the engineering team to understand and articulate the impact of vulnerabilities on existing and future designs and systems and provide insight into how these can be exploited and remediated., • Have developed knowledge of a range of systems and may specialise in a number of specific systems. Essential Skills: • Demonstrable experience in design, delivery and operation of cloud native vulnerability management, security monitoring and cyber incident management tools and processes within large Scottish/UK Public Sector and/or corporate industry (financial services)., • Demonstrable experience in designing, implementing and managing security solutions tailored for cloud environments and aligned to industry-standard cybersecurity frameworks such as NCSC CAF/NIST/CIS. This includes proficiency in securing cloud platforms such as AWS, Azure, understanding cloud-native security services, and expertise in configuring security groups, IAM policies, and network access controls., • In depth experience and understanding of DevSecOps principles, emphasising the integration of security practices into the DevOps pipeline. This includes knowledge of shift left security, implementing security as code and tools, such as Terraform, Bicep, CloudFormation., • Demonstrable experience of working closely with engineers, architects and other stakeholders to embed security practices into CI/CD workflows with ability to articulate complex security concepts clearly. This includes providing security guidance and coaching to Application, DevOps and Platform Engineers, and fostering a culture of shared responsibility for security throughout the organisation. Desirable Skills: • Experience of securing the delivery and operation of public facing identity-based authentication and verification services within large Scottish/UK Public Sector and/or corporate industry (financial services). If you would like to hear more about this opportunity please get in touch.