Are you a collaborative team member with technical security knowledge? Are you keen to use your skills to protect the organisation, our assets, and employees?
As a CNIS Specialists you will work in a small team providing strategic leadership, consistent standards, and expert capability across physical, personnel, cyber, and supply chain security for CNIS. The team will ensure compliance with national security obligations, resilience, and risk management.
We are recruiting for three roles: CNIS Protective Security Specialist, CNIS Personnel Security and Vetting Specialist, Commercial Security Assurance Specialist.
CNIS Protective Security Specialist role: you will lead protective security risk assessments and controls across CNIS assets, designing, publishing, and maintaining standards, ensuring alignment with asset management and corporate policies. Key responsibilities include:
• Conduct and assure site risk assessments and define protective measures
• Provide security design requirements for new builds/major changes, reviewing specifications
• Coordinate with CTSA for site advice and plan testing/exercises
• Oversee incident management playbooks and after-action reviews for physical incidents
CNIS Personnel Security & Vetting role: you will define and assure role-based vetting and personnel security requirements across CNIS roles and contractors. Key responsibilities include:
• Set role-based vetting, working with Defra group Security on applications
• Embed insider risk controls, working with Professional Standards
• Partner with Professional Standards, HR and Security to manage investigations and cases
• Define, create, and manage training requirements
Commercial Security Assurance role: you will ensure contracts, procurement, and supplier management do not compromise CNIS security. Key responsibilities include:
• Work with Commercial on CNIS security clauses and schedules, providing advice during procurement and on managing contracts securely
• Run supplier due diligence and ongoing assurance
• Coordinate with NPSA/NCSC guidance for supply chain risk, advising on remediation and termination where needed
• Monitor contract performance against security KPIs, escalating non-conformance