Rodeo
Get started

Motability Operations Ltd

Security Assurance Lead

Bristol
Posted 1 day ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

About The Role

Reporting to the Application Security Team Lead and Programme Manager for Sustainability & Business Change (SBC), the Security & Governance Engineer will act as the embedded security contact for the SBC programme, working closely with delivery squads to embed security throughout the design, implementation and operation of technology. Alongside this core responsibility, you'll support the wider Security Engineering function, helping mature how Information Security engages with delivery teams across Motability Operations.

As part of the Information Security function, you'll be the primary security contact for a portfolio of initiatives across the SBC programme. You'll provide practical, risk based security guidance that supports programme delivery, helping assess incoming requests, understand its security risk and determine the appropriate level of security engagement and assurance. Working alongside business analysts, architects, product owners, delivery managers and engineering teams, you'll help define security requirements, influence solution design and make sure security is considered at the right stages of the delivery lifecycle.

The role sits within the Application Security team, which forms part of a wider Information Security function of around 40 security professionals. You'll work closely with specialists across Application Security, Security Operations, Identity, IT Continuity, Security Architecture and Cloud Security, recognising when specialist expertise is required and bringing the right teams into delivery at the right time. You'll help teams navigate Information Security effectively while building strong relationships across the business.

You'll also play a role in operating and maturing the Information Security Front Door capability, helping teams engage with Information Security consistently and at the right point in delivery. You'll help assess incoming demand, understand the level of security risk and coordinate the right level of assurance and specialist support, creating a straightforward and proportionate experience for teams seeking security guidance.

Although security consultancy is at the heart of the role, you'll remain technically engaged throughout delivery. You'll work alongside engineering teams to understand solutions, identify security risks, support threat modelling and design reviews, and provide practical guidance that helps teams build securely. Where deeper specialist knowledge is required, you'll work with colleagues across Information Security to bring the right expertise into delivery. It's well suited to someone who enjoys influencing outcomes through consultancy while remaining close to the technology and the teams building it.

Success in the role will be reflected in the quality of security engagement across the SBC programme, the maturity of the Information Security Front Door, and the consistent application of proportionate, risk based security assurance. You'll help improve threat modelling and security review practices, ensure security risks are clearly understood and prioritised, and help delivery teams access the right Information Security expertise when they need it. As the capability grows, you'll also have opportunities to mentor colleagues and contribute to the continued development of our Application Security operating model.

  • Act as the primary Information Security point of contact for a portfolio of projects within the Sustainability & Business Change Programme (SBC), providing security consultancy that enables successful business delivery & security governance.
  • Build trusted relationships with stakeholders across Technology and the wider business, offering clear, risk based security advice throughout the project lifecycle.
  • Support Business Analysts and delivery teams in defining security activities, identifying security requirements and embedding Secure by Design principles from the earliest stages of delivery.
  • Operate and continue improving the Information Security Front Door, helping establish a consistent and effective engagement model for accessing security services across the organisation.
  • Facilitate threat modelling workshops, produce Data Flow Diagrams (DFDs) and carry out structured threat assessments using the STRIDE methodology.
  • Conduct security assurance activities across new and existing services, including architecture and design reviews, configuration assessments, security hardening reviews and production security assessments.
  • Prioritising, designing and then resolving the findings of threat models and security assurance assessments.
  • Coordinate penetration testing activities, review findings with technical teams and ensure remediation plans are agreed, prioritised and tracked.
  • Assess implementation plans, technical designs and solution architectures, providing practical recommendations that balance security, delivery and operational requirements.
  • Work with AppSec, CloudSec, platform engineering and delivery teams where initiatives impact products, AWS, Azure services, helping identify app and cloud security considerations and ensuring specialist expertise is engaged where required.
  • Collaborate with Security Operations, Identity, IT Continuity and other Information Security teams to deliver consistent security outcomes across programmes and operational services.
  • Identify, assess and prioritise security risks arising from reviews, threat modelling and assurance activities, ensuring they are managed appropriately through to resolution.
  • Promote security awareness and encourage secure engineering practices, helping delivery teams understand security requirements without creating unnecessary barriers.
  • Contribute to the ongoing improvement of security standards, patterns, guidance and processes, ensuring they remain aligned with industry best practice and organisational objectives.
  • Mentor colleagues where appropriate and help improve the wider Security Business Consulting capability.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

About You

You're an experienced cyber security professional who enjoys working with people as much as solving technical problems. You understand that effective security comes from collaboration, helping delivery teams build secure solutions rather than acting as a gatekeeper. You're comfortable working with both technical and non-technical stakeholders, translating complex security concepts into clear, practical advice that supports informed decision making.

You have a strong consulting mindset and are comfortable managing multiple initiatives at the same time, balancing business priorities with security risk. Alongside your consultancy skills, you enjoy staying technically involved and taking opportunities to design and implement security improvements where they make a real difference. You're naturally curious, collaborative and always looking for ways to improve how security is delivered across the organisation.

Minimum criteria

You’ll need all of these.

  • Proven experience working in cyber security, with experience in security consulting, application security, product security or security engineering.
  • Experience partnering with delivery teams to provide security guidance throughout project and programme lifecycles.
  • Excellent communication and stakeholder management skills, with the ability to build credibility and influence both technical and business audiences at all levels.
  • The ability to balance competing priorities while working across multiple projects and initiatives.
  • Experience conducting threat modelling, producing Data Flow Diagrams and applying methodologies such as STRIDE.
  • Experience carrying out security assurance activities, including solution reviews, security assessments, configuration reviews and security hardening.
  • Experience coordinating penetration testing activities and managing the remediation of identified vulnerabilities.
  • A good understanding of Secure by Design principles and the ability to apply them throughout solution delivery.
  • Experience identifying, assessing and prioritising security risks, providing pragmatic recommendations that align with business objectives and the organisation's risk appetite.
  • Good working knowledge of recognised security frameworks and standards such as NIST or ISO27001, along with industry best practice.
  • Experience working with cloud technologies, particularly AWS and Azure, and a good understanding of cloud native security controls and services.
  • Experience working alongside engineering teams to design and implement security controls and improvements across applications, infrastructure and cloud environments.
  • An understanding of CI/CD pipelines, secure software delivery practices and modern application development approaches.
  • A collaborative approach and a “can-do” attitude with a willingness to share knowledge, mentor colleagues and contribute to the continual improvement of the Information Security function.
  • A recognised security certification such as CISSP would be advantageous, although equivalent experience and a commitment to continued professional development are equally valued.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

About The Company

Motability Operations is a unique organisation, virtually one of a kind. We combine a strong sense of purpose with a real commercial edge to ensure we provide the best possible worry-free mobility solutions to over 800,000 customers and their families across the UK. Customers exchange their higher rate mobility allowance to lease a range of affordable vehicles (cars, wheelchair accessible vehicles, scooters, and powered wheelchairs) with insurance, maintenance and breakdown assistance included. We are the largest car fleet operator in the UK (purchasing around 10% of all the new cars sold in the UK) and work with a network of around 5,000 car dealers and all the major manufacturers. We pride ourselves on delivering outstanding customer service, achieving an independently verified customer satisfaction rating of 9.8 out of 10.

Our Values Are At The Heart Of Everything We Do. They Represent Ambition, And We Look For Our People To Live And Breathe Them Every Day

  • We find solutions
  • We drive change
  • We care

We operate hybrid working across the organisation where we split our time between working on-site at our offices, and at home, remotely within the UK. We believe hybrid working achieves a good work/life balance for our colleagues, allowing us to connect with each other, collaborate on important work, and perform together to deliver for our customers. It allows us to have the flexibility to work remotely up to 2-days per week whilst also using the great office spaces we have available.

As a Motability Operations Team Member, You Can Expect

  • An annual discretionary bonus
  • 15% non-contributory pension (9% non-contributory pension during probation period)
  • Life assurance at 4 times your basic salary to give you peace of mind that your loved ones will receive some financial help
  • Employee Discount Scheme with a huge number of retailers and an app to save on the go
  • Discounted Electric/Hybrid Car Salary Sacrifice Scheme
  • Access to the Cycle to Work Scheme (we have showers, changing rooms and secure bike sheds on site)

As well as financial benefits, our staff's health and well-being are very important to us, so we also offer:

  • 28 days annual leave with option to purchase and sell days
  • Funded Private Medical Insurance cover
  • Critical illness insurance
  • Free access to healthcare apps, such as Peppy, Unmind, Aviva Digital GP
  • Funded health screening for over 50s
  • 1 day per year to volunteer – Staff can support a local charity or do a sponsored event whilst being paid for it
  • Access to our fully accessible company allotment – Where we grow our own produce
Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

Bristol, England, United Kingdom

Sign up to applySee more jobs like this