Security Project Manager

Posted 5hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Security Project Manager leading Nasstar’s Telecoms Security Act and Ofcom compliance. Validating technical controls, assessing risks, and coordinating regulatory assurance across UK telecoms operations.

Responsibilities:

  • Lead Nasstar’s compliance with the Telecoms Security Act (TSA) and associated Ofcom regulatory requirements
  • Ensure the organisation can evidence a robust and defensible security posture
  • Partner with engineering, security, and operational teams to translate regulatory expectations into practical control effectiveness
  • Lead delivery of TSA compliance activities
  • Coordinate responses to Ofcom information requests and regulatory submissions
  • Interpret TSA Code of Practice measures and translate them into business and technical actions
  • Gather required information from Core Engineering, Voice, OSS, Operations, Procurement, and IT & Security teams
  • Review and validate technical, architectural, and operational evidence
  • Provide evidence-based challenge and ensure submissions are complete, accurate, and aligned to regulatory expectations
  • Identify evidence gaps, control weaknesses, and remediation areas
  • Assess compensating controls where full compliance is not achieved
  • Apply risk scoring in line with Nasstar’s risk management framework
  • Focus on risks impacting Security Critical Functions and supporting network oversight capabilities
  • Align TSA requirements with NCSC CAF, ISO 27001, and HSCN frameworks
  • Support governance reporting and risk committee discussions
  • Contribute to internal assurance and control frameworks
  • Review and advise on supplier contracts and security obligations
  • Support Legal & Procurement with security requirements and risk considerations
  • Contribute to third-party risk and assurance activities

Requirements:

  • Experience in telecoms or network service provider environments, cyber security, network security, infrastructure security, technology risk, compliance, or regulatory assurance
  • Experience supporting or responding to regulatory frameworks such as TSA, NCSC CAF, ISO 27001, or NIS
  • Experience operating in a second-line GRC or assurance capacity rather than hands-on engineering or operational delivery
  • Ability to engage with asset owners and technical SMEs
  • Ability to extract relevant control evidence
  • Ability to validate that controls are appropriately designed and operating
  • Ability to challenge insufficient control coverage or assurance
  • At least one relevant certification is ideally preferred, including CISSP, CISM, CRISC, CCNP Security, CCSP, CCNA Security, CompTIA Security+, CompTIA Network+, or equivalent recognised certification
  • Ability to interpret technical concepts and align them with security or regulatory requirements
  • Ability to assess control effectiveness and identify gaps or weaknesses
  • Experience within a regulated telecoms environment, particularly under the Telecoms Security Act or Ofcom regulatory engagement

Benefits:

  • 25 days’ holiday (excluding bank holidays) + Your Birthday Off
  • Flexible working
  • Virtual working / remote work
  • Best-of-breed software and hardware for all staff
  • 4x annual salary life assurance
  • Health cash plan
  • Retail discounts and other perks from major brands
  • Competitive salary
  • Supportive teams
  • Opportunity to progress in your career