Information Assurance Technical Security Specialist
Crawley, West Sussex, RH11, England, UK
Listed on 2026-01-19
-
IT/Tech
Cybersecurity
Location:
Crawley, United Kingdom
In fast‑changing markets, customers worldwide rely on Thales. Thales is a business where brilliant people from all over the world come together to share ideas and inspire each other. In aerospace, transportation, defence, security, and space, our architects design innovative solutions that make tomorrow possible.
Together we offer fantastic opportunities for committed employees to learn and develop their career with us. At Thales UK, we research, develop, and supply technology and services that impact the lives of millions of people each day to make life better and keep us safer. We innovate across the major industries of Aerospace, Defence, Security and Space. Your health and well‑being matters to us and that’s why we offer flexibility: part‑time hours, job sharing, home working, or flexible start and finish times, where possible, to support a working pattern that suits your lifestyle.
Jobtitle
Information Assurance/Technical Security Specialist
Reporting lineReporting to the Thales UK Deputy CISO, the Information Assurance/Technical Security role involves the identification of applicable technical security requirements and their cost‑effective security controls, as well as continual through‑life security assurance of Thales IS environments.
Location flexibilityLocation:
Crawley / Doncaster, but we will consider other Thales locations.
- Performance‑Related Bonus
- Half day every Friday, usually finishing around 13:00
- Hybrid Working
- Pension Scheme
- 28 days annual leave (plus Bank Holidays)
- Life Cover
- 24/7 Employee Assistance Program and access to a mental wellbeing app
- Employee discount shopping schemes on major brands and retailers
- Gym membership discounts
- Technical Security: Support Thales UK in ensuring all IS/IT technical security measures are implemented, enhanced, and developed where necessary, to ensure successful and timely security assurance via ongoing through‑life continuous assurance and compliance programmes.
- Technical Security PoC: Provide a central PoC for all IS/IT technical security matters and concerns, supporting delivery teams and businesses throughout project life cycles.
- Change management: Conduct security reviews of internal/external platform‑related changes ensuring risks, impacts and mitigations are managed appropriately.
- Cloud Security: Provide security guidance around secure deployment and usage of Thales‑adopted public cloud infrastructure and/or SaaS services (e.g., Azure) in compliance with government security guidelines, Thales policy and industry‑accepted “good practices.”
- Compliance & Governance: Ensure Thales on‑premises and cloud environments comply with government policies such as Cyber Essentials, Def Stan 05‑138, UK GDPR, NCSC guidelines and other contractual and regulatory frameworks.
- Evidence Continual Security Assurance: Create, maintain and review all IS/IT technical security documentation, policies and procedures associated with Thales’ IS/IT networks, systems and applications, as per customer (primarily HMG UK MOD) and Thales Group policy.
- Incident Response: Report, investigate and analyse security incidents and potential breaches within classified environments, working with the Thales UK Incident management team to resolve issues promptly.
- IS/IT Squad Engagement: Develop security requirements, epics and stories, and provide governance to squads to ensure data protection and data security are included in scope of IS/IT squad activities, initiatives and projects.
- Risk Focused Delivery: Work collaboratively with other team members to ensure proposed solutions provide required security assurance in line with data processing requirements, Thales and customer risk appetites.
- Risk Management: Develop and coordinate implementation of formal and regular technical risk and compliance assessments of Thales’ IS environments, recommending remedial action.
- Third Party CoCo Assurance: Provide assurance and ensure successful delivery of all Code of Connections (CoCos), associated cryptographic products, key material and required documentation.
- Training & Development: Engage in continuous learning and develop less…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: