Cybersecurity Governance & Assurance Specialist

Amaris GROUP SA, West Norwood, Lambeth

Cybersecurity Governance & Assurance Specialist

Salary not available. View on company website.

Amaris GROUP SA, West Norwood, Lambeth

  • Full time
  • Permanent
  • Onsite working

Posted today, 31 Aug | Get your application in now to be one of the first to apply.

Closing date: Closing date not specified

Job ref: 20b75e9db76d4ef8921a4ac71a7106e0

Location ref: West Norwood, Lambeth

Full Job Description

  • Own and maintain the product cybersecurity governance and assurance framework, aligned with the broader compliance model used across disciplines
  • Develop and maintain internal standards, templates, checklists, and guidance to enable consistent execution across programmes (e.g., System of Interest definitions, TARA guidance, cybersecurity requirements, testing expectations, and evidence packs)
  • Create and deliver training and enablement programmes to uplift engineering teams and drive "right first time" compliance
  • Programme Compliance Assessment and Assurance
  • Plan and execute cybersecurity compliance assessments of product programmes and suppliers, reporting status, risks, and evidence gaps clearly and early
  • Assess alignment against internal requirements and relevant external standards and regulations, including ISO/SAE 21434, ISO 24882, IEC 62443, and the Cyber Resilience Act (CRA)
  • Review the adequacy of key cybersecurity work products such as threat modelling/TARA outputs, requirements, architecture evidence, verification and validation strategies, and residual risk statements
  • Drive closure of findings with stakeholders across systems, embedded software, verification, manufacturing/service, and suppliers
  • Cybersecurity Testing Assurance
  • Define cybersecurity testing expectations required for compliance evidence, covering coverage scope, methods, reporting, and remediation tracking
  • Coordinate Red Team and testing activities to ensure outputs support programme assurance and close testing capability gaps, Establish and assure governance for post-production vulnerability management, including monitoring from suppliers, research findings, Red Team outputs, and PSIRT channels, and routing to affected products
  • Support readiness for CRA mandatory reporting, including Article 14 reporting workflows and fast-track response for actively exploitable issues
  • Capture and disseminate lessons learned (e.g., CWE/CVE insights) back into standards, checklists, and training materials

    3+ years of experience within Tier 1 or OEM sectors (on-highway or off-highway) in a cybersecurity role
  • Demonstrable experience in product cybersecurity assurance, governance, compliance assessment, or cybersecurity audit for embedded or cyber-physical products
  • Strong working knowledge of ISO/SAE 21434 and ISO 24882, with the ability to translate them into practical internal processes and evidence expectations
  • Working knowledge of IEC 62443 and supplier assurance requirements
  • Familiarity with CRA compliance needs, including defined reporting workflows such as Article 14
  • Excellent technical writing, communication, and stakeholder management skills, with the ability to present risk clearly and pragmatically
  • Knowledge or experience of TARA and threat modelling approaches, including review of threat artefacts such as attack trees, is a plus
  • Background in vulnerability management and post-production monitoring/triage governance is a plus
  • Experience in cybersecurity requirements engineering and cybersecurity testing (including test evidence expectations) is a plus
  • Awareness of functional safety interfaces and the security-safety relationship is a plus
  • Understanding of embedded product environments including ECUs, CAN, J1939, and diagnostics such as UDS is a plus
  • Familiarity with SBOM concepts and their role in vulnerability monitoring and compliance evidence is a plus
  • Self-motivated, analytical, and pragmatic, with strong interpersonal skills and a collaborative mindset
  • Resilient and adaptable, with a drive for continuous improvement and a high standard of technical delivery

Direct job link

https://www.jobs24.co.uk/job/cybersecurity-governance-assurance-specialist-127309165