DXC Technology
Security Delivery Lead

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Job Description:
DXC Technology is committed to building diverse, inclusive teams. We welcome applications from all backgrounds and particularly encourage interest from women, underrepresented groups, and neurodivergent candidates. We offer reasonable adjustments throughout the hiring process and are dedicated to creating a supportive, accessible environment for everyone.
Security Delivery Lead
Location: Farnborough (onsite 5 days per week)
Due to the nature of the work and the customers we support, the successful candidate must be eligible to meet UK Government and contractual personnel security requirements, including the applicable residency requirements for the role, and have the right to work in the United Kingdom. Some roles may also be subject to nationality requirements where these are necessary to meet UK Government or contractual security obligations.
The Security Delivery Lead is the senior security subject matter expert (SME) accountable for the development, implementation, and maintenance of the security assurance regime across the service. This role owns the security policies, procedures, and governance framework that underpin the Contractor's compliance with client security requirements, accreditation obligations, and defence security standards.
This is a leadership and accountability role — not a technical implementation role. The Security Delivery Lead is responsible for ensuring the organisation's overall defence security posture is maintained, evidenced, and continuously improved. The role is the single point of accountability for security assurance, accreditation support, risk governance, and policy compliance across the service delivery lifecycle.
Key Responsibilities
Security Assurance Regime
- Develop, implement, and maintain the security assurance regime for the service — defining the framework, processes, activities, and evidence requirements that demonstrate ongoing security compliance.
- Establish and own the security assurance schedule — ensuring assurance activities are planned, executed, evidenced, and reported on a recurring basis.
- Define and maintain the security assurance evidence framework — specifying what evidence is required, how it is collected, where it is stored, and how it is presented to accreditation authorities and client security teams.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Accreditation Support & Maintenance
- Act as the Contractor's primary point of contact for all security accreditation matters — engaging with the client's Security Accreditation Authority, Information Asset Owners, and Senior Information Risk Owners (SIROs).
- Support the accreditation lifecycle.
- Maintain a register of all accreditation conditions, caveats, and risk acceptances — tracking compliance and closure.
Security Policy & Procedure Development
- Develop, maintain, and enforce security policies and procedures that ensure the Contractor's compliance.
- Conduct regular policy reviews to ensure currency with evolving client requirements, regulatory changes, and threat landscape developments.
- Manage policy exceptions and deviations through a formal process — ensuring exceptions are risk-assessed, time-bound, approved, and tracked.
Security Risk Governance
- Establish and maintain the security risk governance framework for the service — defining how security risks are identified, assessed, recorded, escalated, treated, and reported.
- Own and maintain the security risk register.
- Chair or participate in security risk governance forums — presenting risk posture, emerging threats, and treatment progress to senior leadership and client stakeholders.
Compliance Management & Audit Support
- Ensure the Contractor's ongoing compliance with all applicable security policies, standards, regulations, and contractual obligations.
- Develop and maintain a compliance monitoring framework — defining what is monitored, how compliance is measured, and how non-compliance is addressed.
- Conduct or commission regular compliance assessments.
- Manage non-compliance findings through a formal remediation process — ensuring findings are risk-assessed, prioritised, assigned, tracked, and closed.
- Support internal and external security audits by providing evidence, documentation, and subject matter expertise.
Defence Security Posture Management
- Maintain oversight of the overall defence security posture across the service — providing senior leadership and client stakeholders with a clear, evidence-based view of security health.
- Identify and escalate security posture degradation — ensuring corrective action is taken before risks materialise.
- Ensure the security posture is maintained during periods of change.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Personnel Security
- Ensure all personnel (employees, contractors, sub-contractors) working on the service meet the required security clearance levels and vetting requirements.
- Maintain oversight of personnel security compliance.
Physical & Environmental Security
- Ensure physical security controls for the service are appropriate to the classification and sensitivity of the environments supported.
- Maintain oversight of physical security compliance.
Security Incident & Breach Management
- Ensure security incident and breach management processes are defined, documented, tested, and aligned to client and regulatory requirements.
- Provide senior security oversight of security incidents.
- Ensure security incident trends are analysed and feed into risk governance, assurance activities, and process improvement.
At DXC Technology, we believe strong connections and community are key to our success. Our work model prioritizes in-person collaboration while offering flexibility to support wellbeing, productivity, individual work styles, and life circumstances. We’re committed to fostering an inclusive environment where everyone can thrive.
Recruitment fraud is a scheme in which fictitious job opportunities are offered to job seekers typically through online services, such as false websites, or through unsolicited emails claiming to be from the company. These emails may request recipients to provide personal information or to make payments as part of their illegitimate recruiting process. DXC does not make offers of employment via social media networks and DXC never asks for any money or payments from applicants at any point in the recruitment process, nor ask a job seeker to purchase IT or other equipment on our behalf. More information on employment scams is available here.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London