Security Assurance Lead
DIVERSEJOBSMATTER LIMITED · Bristol, South West
Security Assurance Lead at DIVERSEJOBSMATTER LIMITED, based in Bristol, South West. This is a permanent role.
- Salary
- Competitive
- Location
- Bristol, South West
- Contract
- Permanent
- Posted
- 12 hours ago
- Closes
- 14 Oct 2026
- Sector
- Security Officer
Reference https://diversejobsmatter.co.uk/job/26224187/security-assurance-lead/
About the role
As part of the Information Security function, you'll be the primary security contact for a portfolio of initiatives across the SBC programme. You'll provide practical, risk based security guidance that supports programme delivery, helping assess incoming requests, understand its security risk and determine the appropriate level of security engagement and assurance. Working alongside business analysts, architects, product owners, delivery managers and engineering teams, you'll help define security requirements, influence solution design and make sure security is considered at the right stages of the delivery lifecycle.
The role sits within the Application Security team, which forms part of a wider Information Security function of around 40 security professionals. You'll work closely with specialists across Application Security, Security Operations, Identity, IT Continuity, Security Architecture and Cloud Security, recognising when specialist expertise is required and bringing the right teams into delivery at the right time. You'll help teams navigate Information Security effectively while building strong relationships across the business.
You'll also play a role in operating and maturing the Information Security Front Door capability, helping teams engage with Information Security consistently and at the right point in delivery. You'll help assess incoming demand, understand the level of security risk and coordinate the right level of assurance and specialist support, creating a straightforward and proportionate experience for teams seeking security guidance.
Although security consultancy is at the heart of the role, you'll remain technically engaged throughout delivery. You'll work alongside engineering teams to understand solutions, identify security risks, support threat modelling and design reviews, and provide practical guidance that helps teams build securely. Where deeper specialist knowledge is required, you'll work with colleagues across Information Security to bring the right expertise into delivery. It's well suited to someone who enjoys influencing outcomes through consultancy while remaining close to the technology and the teams building it.
Success in the role will be reflected in the quality of security engagement across the SBC programme, the maturity of the Information Security Front Door, and the consistent application of proportionate, risk based security assurance. You'll help improve threat modelling and security review practices, ensure security risks are clearly understood and prioritised, and help delivery teams access the right Information Security expertise when they need it. As the capability grows, you'll also have opportunities to mentor colleagues and contribute to the continued development of our Application Security operating model.
- Act as the primary Information Security point of contact for a portfolio of projects within the Sustainability & Business Change Programme (SBC), providing security consultancy that enables successful business delivery & security governance.
- Build trusted relationships with stakeholders across Technology and the wider business, offering clear, risk based security advice throughout the project lifecycle.
- Support Business Analysts and delivery teams in defining security activities, identifying security requirements and embedding Secure by Design principles from the earliest stages of delivery.
- Operate and continue improving the Information Security Front Door, helping establish a consistent and effective engagement model for accessing security services across the organisation.
- Facilitate threat modelling workshops, produce Data Flow Diagrams (DFDs) and carry out structured threat assessments using the STRIDE methodology.
- Conduct security assurance activities across new and existing services, including architecture and design reviews, configuration assessments, security hardening reviews and production security assessments.
- Prioritising, designing and then resolving the findings of threat models and security assurance assessments.
- Coordinate penetration testing activities, review findings with technical teams and ensure remediation plans are agreed, prioritised and tracked.
- Assess implementation plans, technical designs and solution architectures, providing practical recommendations that balance security, delivery and operational requirements.
- Work with AppSec, CloudSec, platform engineering and delivery teams where initiatives impact products, AWS, Azure services, helping identify app and cloud security considerations and ensuring specialist expertise is engaged where required.
- Collaborate with Security Operations, Identity, IT Continuity and other Information Security teams to deliver consistent security outcomes across programmes and operational services.
- Identify, assess and prioritise security risks arising from reviews, threat modelling and assurance activities, ensuring they are managed appropriately through to resolution.
- Promote security awareness and encourage secure engineering practices, helping delivery teams understand security requirements without creating unnecessary barriers.
- Contribute to the ongoing improvement of security standards, patterns, guidance and processes, ensuring they remain aligned with industry best practice and organisational objectives.
- Mentor colleagues where appropriate and help improve the wider Security Business Consulting capability.
Reference: https://diversejobsmatter.co.uk/job/26224187/security-assurance-lead/ · Posted 12 hours ago · Closes 14 Oct 2026 · Listed via DIVERSEJOBSMATTER LIMITED
Apply for this job
This role is listed via DIVERSEJOBSMATTER LIMITED. Applications are handled on the employer's site.
Apply on employer siteOpens the employer's website in a new tab.
Safe applying: a genuine employer will never ask you to pay for a DBS check, training or equipment, or move you onto WhatsApp before you are hired. If this listing does, report it and do not pay anything.