
Security Project Manager
Posted Aug 6

Posted Aug 6
This is a fully remote position, open to applicants in United Kingdom.
• Oversee Nasstar's adherence to the Telecoms Security Act (TSA) and related Ofcom regulatory standards.
• Ensure that the organization demonstrates a strong and defensible security posture.
• Collaborate with engineering, security, and operational teams to convert regulatory expectations into effective practical controls.
• Drive the execution of TSA compliance initiatives.
• Manage responses to Ofcom information requests and regulatory submissions.
• Analyze TSA Code of Practice measures and transform them into actionable business and technical steps.
• Collect necessary data from Core Engineering, Voice, OSS, Operations, Procurement, and IT & Security teams.
• Evaluate and confirm technical, architectural, and operational evidence.
• Provide evidence-based scrutiny and ensure that submissions are thorough, precise, and aligned with regulatory requirements.
• Identify gaps in evidence, control deficiencies, and areas needing remediation.
• Evaluate compensating controls when full compliance is not realized.
• Implement risk scoring consistent with Nasstar's risk management framework.
• Concentrate on risks affecting Security Critical Functions and enhancing network oversight capabilities.
• Integrate TSA requirements with NCSC CAF, ISO 27001, and HSCN frameworks.
• Assist in governance reporting and discussions within the risk committee.
• Contribute to the development of internal assurance and control frameworks.
• Review and provide guidance on supplier contracts and security obligations.
• Support Legal & Procurement teams with security requirements and risk assessments.
• Engage in third-party risk and assurance activities.
• Experience in telecom or network service provider settings, cyber security, network security, infrastructure security, technology risk, compliance, or regulatory assurance.
• Background in supporting or responding to regulatory frameworks such as TSA, NCSC CAF, ISO 27001, or NIS.
• Experience functioning in a second-line Governance, Risk, and Compliance (GRC) or assurance role instead of hands-on engineering or operational tasks.
• Ability to engage with asset owners and technical Subject Matter Experts (SMEs).
• Competence in extracting relevant control evidence.
• Skill in validating that controls are well-designed and effective.
• Capability to challenge inadequate control coverage or assurance.
• Possession of at least one relevant certification is highly preferred, such as CISSP, CISM, CRISC, CCNP Security, CCSP, CCNA Security, CompTIA Security+, CompTIA Network+, or an equivalent recognized certification.
• Ability to interpret technical concepts and align them with security or regulatory standards.
• Proficiency in assessing control effectiveness and identifying gaps or vulnerabilities.
• Experience in a regulated telecom environment, especially regarding the Telecoms Security Act or Ofcom regulatory interactions.
• 25 days of holiday (excluding bank holidays) + Your Birthday Off.
• Flexible working arrangements.
• Virtual working / remote work options.
• Access to top-tier software and hardware for all employees.
• Life assurance equivalent to four times the annual salary.
• Health cash plan available.
• Discounts and additional benefits from major brands.
• Competitive salary package.
• Supportive team environment.
• Opportunities for career advancement.
M3 USA
Core & Main
Brafton Inc.
Brafton Inc.
Get handpicked remote jobs straight to your inbox weekly.