UK Information Assurance Practitioner
// Role Summary
Join Northrop Grumman UK as an Information Assurance Practitioner in Cheltenham, playing a critical role in protecting business and customer information for vital UK programmes. This hands-on role offers the chance to influence security strategy and drive improvements.
// Key Responsibilities
- Provide expert guidance on information assurance, risk management, and security controls.
- Conduct information risk assessments and support certification activities.
- Develop and maintain security policies and procedures aligned with recognised frameworks.
- Requires SC Clearance (or ability to obtain) and UK citizenship.
- Hybrid working model with 3 days onsite in Cheltenham.
- Competitive salary range of £52,000 - £70,000 per annum.
// Role Specification
Information Assurance Practitioner
Northrop Grumman UK is seeking an Information Assurance Practitioner to join our Information Security team in Cheltenham. Reporting to the UK Information Assurance Lead, you will be instrumental in safeguarding our business, customer data, and critical programmes, while simultaneously fostering innovation and supporting growth.
This is a practical, hands-on role for a professional with a strong passion for information security, risk management, and assurance. You will collaborate closely with stakeholders across the organisation, offering expert advice, assisting with certification processes, and ensuring security is integrated throughout the project lifecycle. You will have the opportunity to shape security strategies, influence policy, and implement significant enhancements to protect some of the UK's most important programmes and capabilities.
What You'll Do
- Provide expert advice and guidance on information assurance activities, strategies, and risk management approaches.
- Conduct information risk assessments, gap analyses, and risk treatment planning across projects and programmes.
- Support security certification activities and drive continuous improvement initiatives.
- Develop and maintain security policies, standards, and procedures aligned to recognised frameworks and regulatory requirements.
- Advise on the implementation and operation of physical, procedural, and technical security controls.
- Support internal and external audits while contributing to the successful delivery of major organisational programmes and objectives.
What We're Looking For
We are looking for individuals who possess a blend of technical knowledge, security expertise, and a collaborative working style.
Essential Experience and Knowledge:
- Experience working within information assurance, cyber security, or information security environments.
- Familiarity with information security legislation, governance, and compliance requirements.
- Knowledge of ISO 27001, NIST 800-171, NCSC CAF v3, and CSM v4 frameworks.
- Experience in developing policies, standards, and procedures to support compliance and assurance objectives.
- Excellent communication skills with the ability to influence stakeholders and present recommendations clearly.
- Strong planning, organisational, and problem-solving skills with excellent attention to detail.
Desirable Experience:
- Knowledge of Secure by Design principles.
- Experience of MOD Supply Chain Assurance processes.
- Knowledge of supply chain assurance frameworks, including ISO 28001.
- Understanding of Commercial Off-The-Shelf (COTS) assurance activities.
- Degree-level qualification or equivalent relevant experience.
Most importantly, we are seeking individuals who are passionate about protecting information, people, and organisations, and who thrive in a fast-paced, collaborative environment. Even if you do not meet every requirement, we encourage you to apply as your experience, potential, and perspective could be a valuable addition to our team.
Security Clearance
Due to the nature of our work, UK citizenship is required, and candidates must be able to obtain and maintain UK Government security clearance.
Benefits
We offer a flexible and rewarding benefits package, including:
- Flexible working options (hybrid arrangements, compressed fortnights).
- Private healthcare, dental cover, life assurance, and pension.
- Flexible benefits package (critical illness cover, health cash plan).
- Holiday buy and sell scheme.
- Career development and learning programmes.
- Annual performance incentive programme.