About this role
Salary: £35,000 - 75,000 per year
Requirements: Experience in information security, including a security assessment or assurance roleDemonstrated experience conducting security design reviews and assessmentsStrong background in defence, aerospace, or government security programmesExperience with security certification and accreditation processesExperience managing a team in a security/JDT functionWorking knowledge of IT architecture and design principlesComprehensive understanding of IT security controls and security frameworksStrong knowledge of network, infrastructure, application, and data securityUnderstanding of threat modelling and risk assessment methodologiesFamiliarity with MOD security requirements, Classification Guides, and security policyKnowledge of ITAR regulations and export control requirementsUnderstanding of security standards such as ISO 27001 and NIST CSFPractical knowledge of common IT architectures and technologiesStrong analytical and problem-solving skillsExcellent leadership skillsExcellent written and verbal communication skillsAttention to detail with the ability to identify gaps and inconsistenciesCollaborative approach to working with architects and technical teamsAbility to explain complex security concepts clearlyProfessional approach to challenging design decisions on security groundsCommitment to security excellence and MOD compliance Responsibilities: Lead security design review, assessment, and assurance for defence and aerospace IT programmesProvide technical security guidance to joint design teamsConduct security assessments of proposed IT solutionsEnsure MOD security complianceIdentify security risks and recommend security controlsConduct detailed security reviews of IT architecture and design documentationAssess security controls and identify gaps against MOD security requirementsEvaluate threat models and security assumptions underlying IT designsReview security specifications for completeness and MOD complianceIdentify residual security risks and recommend mitigation strategiesSupport authority leads and advise third partiesVerify IT designs comply with Defence Security Policy and MOD Classification GuidesAssess adherence to ITAR regulations and export control requirementsReview security controls against IS1 (IS1A) and other MOD security standardsValidate data handling and classification complianceEnsure personnel security and vetting requirements are addressedParticipate actively in joint design team meetings and architecture workshopsProvide security input to infrastructure, network, and application architecture decisionsReview proposed solutions from a security perspective and recommend alternativesChallenge assumptions and help identify security risks early in the design phaseSupport customer security decision-making through technical analysisPrepare detailed security assessment reports documenting findings and recommendationsDocument security control specifications and implementation guidanceCreate security assessment matrices and compliance traceability matricesProvide executive summaries of security findings for stakeholder communicationMaintain security documentation for compliance and audit purposesConduct security risk assessments using appropriate risk methodologiesDevelop risk matrices and prioritise risks based on likelihood and impactRecommend security controls and mitigation strategies for identified risksSupport risk management processes and evidence gathering for MOD approvalTrack risk mitigation and provide assurance of control implementationValidate implementation of recommended security controlsReview security test plans and validation approachesProvide assurance that security controls operate effectivelySupport security certification and accreditation activitiesDocument security assurance evidence for MOD complianceCommunicate security findings and recommendations clearly to technical and non-technical stakeholdersFacilitate security discussions between design teams and customer security teamsExplain complex security concepts in accessible languageSupport customer understanding of MOD security requirements and implications Technologies: SupportNetworkSecurity More:
We are DXC Technology, and we are committed to building diverse, inclusive teams. We welcome applications from all backgrounds and particularly encourage interest from women, underrepresented groups, and neurodivergent candidates. We offer reasonable adjustments throughout the hiring process and are dedicated to creating a supportive, accessible environment for everyone. This Security Assurance Analyst role is based in Farnborough and requires onsite working five days per week. Due to the secure nature of the work and customer requirements, candidates must hold DV clearance.
last updated 32 week of 2026