Security & Compliance Manager
SRT Marine Systems plc (SRT) are a market leader in its domain of international marine surveillance technology and systems. We are respected, established and an ambitious multi-national company headquartered in the UK with a global customer base.
The company has a global impact in the marine domain by leading the next generation of Maritime Domain Awareness 'MDA' technologies, products and systems that significantly enhance, security, safety and environment protection and sustainability. Our customers are worldwide and range from the largest national coast guards to individual vessel owners.
SRT is an exciting company where high quality results are rewarded. We are ambitious and are constantly seeking to innovate to deliver better products and services to our customers. We strive to make SRT a rewarding and challenging place to work where talented hard-working individuals have the opportunity to make a real impact across the marine world.
We are looking for a Security & Compliance Manager to own the security of how our products and systems are deployed, operated and maintained in customer environments around the world, and to lead the security assurance and certification activity that stands behind them.
This is a senior, customer-facing leadership role sitting at the intersection of secure delivery, customer operations and corporate security. You as a Security & Compliance Manager will work closely with our delivery, customer-facing, network & infrastructure and corporate IT teams, and with our external security partners, to make sure the systems we deploy remain secure throughout their operational life.
The role is focused on leadership, coordination and communication rather than hands-on engineering. Much of the knowledge needed already exists across the business - your job is to bring it together into a coherent programme, and to be the champion who drives it through, backed by enough technical understanding to hold detailed conversations with customers, auditors and developers.
The role of Security & Compliance Manager is primarily based from our Bristol office, but you must be willing to travel to our offices in Cardiff and Bath on occasion, and from time to time to customer sites worldwide, with good flexibility for Hybrid working.
Responsibilities - Security & Compliance Manager - not exhaustive:
- Act as the senior voice and champion for security across our delivery and customer operations, ensuring deployed systems receive the same security attention as new ones.
- Define the customer operating policies, principles and patterns that delivery and customer-facing teams should follow for the secure implementation and operation of SRT systems.
- Own the through-life security of equipment deployed in customer environments, including patching, secure configuration, and equipment lifecycle and end-of-life replacement.
- Lead SRT's responses to customer security requirements, assurance questionnaires and connection approvals, including for sophisticated government and defence customers.
- Work with internal stakeholders to ensure engineering and operational reality supports the security claims we make to customers, partners and auditors.
- Lead our assurance and certification activity, including Cyber Essentials Plus, ISO 27001 and other relevant standards.
- Bring together the security expertise that already exists across the business into one coherent, prioritised programme of improvement.
- Direct our external security partners as an extended resource pool for monitoring, assessments and remediation.
- Assign pragmatic risk levels and support sensible prioritisation of remediation alongside project delivery and other commitments.
- Report clearly to senior leadership on risk, progress and priorities in business terms.
Requirements - Security & Compliance Manager - not exhaustive:
- Strong experience in security management, security assurance, compliance or a similar role, ideally where systems are delivered into and operated within customer environments.
- A track record of achieving and maintaining certifications such as ISO 27001 and Cyber Essentials Plus, including managing audits.
- Practical understanding of securing deployed infrastructure, including firewalls, patching, secure configuration and equipment lifecycle management.
- Experience leading customer-facing security engagements, including security questionnaires, accreditation and third-party assurance.
- The presence and communication skills to champion change across teams and to influence stakeholders without direct authority.
- The judgement to assess risk and business impact pragmatically.
- Experience coordinating third-party security providers such as managed SOC or security service partners.
- Familiarity with recognised frameworks such as ISO 27001, Cyber Essentials Plus, NIST CSF or similar.
- Experience in an engineering or manufacturing business delivering long-lived systems would be helpful.
- Experience in high-trust, regulated or mission-critical environments would be valuable.
Benefits
- Highly Competitive Salary and benefits package
- 25 days annual leave rising to 28 days with service
- Real individual development opportunities
SRT Marine Systems plc is an equal opportunity employer. We are committed to creating an inclusive environment for all employees and welcome applications from all backgrounds.