Project Assurance Security Specialist
Contract Length : 6-months
Inside IR35
Locations : London or Manchester
Daily rate : £625 - £650 p/d
We're currently partnering with a leading UK organisation that operates a large-scale national infrastructure programme - delivering critical, secure digital services to support the country's transition to a smarter, greener future.
As part of their growth, they are seeking a Project Assurance Security Specialist to join their well-established Information Security team. This is a fantastic opportunity to work across a wide range of projects that have both public and commercial impact.
You'll work closely with architects, analysts, engineers, business users, and third-party suppliers to ensure that security requirements are built into the design, development, and delivery of complex technical projects. You'll be the go-to person for ensuring security compliance, identifying and mitigating risk, and aligning project outcomes with internal security frameworks and external regulatory obligations.
Provide end-to-end security assurance across multiple concurrent projects.
Review architecture and design documents to identify potential vulnerabilities or compliance issues.
Translate security policies into clear, actionable requirements for delivery teams.
Engage with technical and non-technical stakeholders to influence secure outcomes.
Conduct Information Security impact assessments (e.g. DPIAs) and support penetration testing and remediation.
Produce and maintain security artefacts such as Supplier Security Assessments, Software Security Reviews, and Business Continuity Assessments.
Support security input into contract reviews and third-party supplier due diligence.
Essential:
Extensive experience in Information Security assurance, ideally in complex, multi-vendor or regulated environments.
Strong understanding of security frameworks, risk management principles, and relevant standards (e.g. ISO 27001, GDPR/DPA).
Broad technical knowledge across infrastructure, cloud, networking, and security tooling.
Ability to work collaboratively across teams while also driving independent decision-making.
Excellent documentation and stakeholder communication skills.
Desirable:
Certifications such as CISSP, CISM, CISA, ISO 27001 Lead Auditor/Implementer.
Familiarity with the NIST Cybersecurity Framework.
Experience in highly regulated sectors (e.g. telecoms, energy, critical national infrastructure).
Knowledge of cloud security and smart technologies (a plus, not a must).