Public Sector Resourcing
Security Testing and Assurance Manager

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
DESCRIPTION & REQUIREMENTS
On behalf of Companies House, we are looking for a Security Testing and Assurance Manager Inside IR35 for a 6-month contract based remotely.
Companies House drives confidence in the economy and makes the UK a great place to start, and run, a business.
SC Clearance is an essential requirement for this role, as a minimum you must be willing & eligible to undergo checks. Please note, due to the exceptional requirements of this position (short-term nature of this role and speed at which we require a postholder in situ) preference may be given to candidates who meet all of the essential criteria and hold active SC clearance.
As an executive agency sponsored by The Department for Business and Trade (DBT) we have the ability to play a leading role in the right against corrupt business practices by providing the transparency and clarity necessary for the UK to continue to be regarded as a world-leading place to do business.
Companies House is undergoing an historic change – to our systems, culture, services, and ways of working. Our people are at the heart of these changes.
The Economic Crime and Corporate Transparency Act (2023) gives Companies House the power to play a more significant role in disrupting economic crime and supporting economic growth.
These changes represent the biggest opportunity for Companies House in almost 170 years. This move will help us achieve the kind of culture we want – one which drives high performance and where our brilliant people can flourish.
Responsibilities
As a Security Testing and Assurance Manager, your main responsibilities will be:
- Lead the planning, coordination, and delivery of security testing across applications, APIs, cloud platforms, networks, and infrastructure.
- Manage relationships with internal and external penetration testing providers, ensuring high-quality and timely delivery of assessments.
- Review penetration test reports, validate findings, and assess business impact and risk.
- Own the triage, prioritisation, tracking, and remediation of security vulnerabilities through to resolution.
- Ensure security issues are accurately logged, assigned, and monitored using tools such as Jira.
- Develop and maintain security testing standards, methodologies, and quality assurance processes.
- Produce security risk assessments and provide clear recommendations to technical and business stakeholders.
- Report on security posture, vulnerability trends, remediation progress, and key risk metrics.
- Support security accreditation, audit, and compliance activities against frameworks such as ISO 27001, NIST, GovS 007, and Cyber Essentials.
- Work closely with architects, developers, platform engineers, delivery teams, and risk functions to drive security improvements.
- Support the development and implementation of information security policies, standards, procedures, and guidance.
- Contribute to incident response activities, risk assessments, and wider cyber security assurance initiatives.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Essential Skills & Experience
- Strong experience leading security testing, vulnerability management, or cyber security assurance functions.
- Experience managing penetration testing programmes and third-party security testing suppliers.
- Proven ability to assess, prioritise, and drive remediation of security vulnerabilities.
- Strong understanding of application security, infrastructure security, cloud security, and API security.
- Experience producing security risk assessments and presenting findings to senior stakeholders.
- Knowledge of security governance, risk management, and compliance frameworks.
- Experience working with vulnerability tracking and management tools such as Jira.
- Excellent stakeholder management and communication skills, with the ability to engage both technical and non-technical audiences.
Technical Knowledge
- Vulnerability Management
- Penetration Testing
- Security Assurance
- Risk Management
- Cloud Security
- Application Security
- Infrastructure Security
- Networking
- Encryption Technologies
- Microsoft Technologies
- Linux Platforms
- Incident Management


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Desirable Experience
- ISO 27001, NIST, GovS 007, Cyber Essentials, or similar security frameworks.
- GDPR and Data Protection Act 2018 knowledge.
- Experience operating within an ITIL-based environment.
- Public sector, government, or highly regulated industry experience.
- Security audit and accreditation support experience.
What We're Looking For
- A security professional who can bridge the gap between cyber security testing, assurance, and risk management.
- Someone capable of challenging remediation activities and driving security improvements across multiple teams.
- A strong communicator who can influence stakeholders, manage suppliers, and provide clear security guidance at all levels.
- An individual who can provide confidence that digital services meet organisational security requirements and industry best practice.
Please be aware that this role can only be worked within the UK and not Overseas.
Armed Forces Covenant / Commitment
As a signatory of the Armed Forces Covenant, Companies House welcome applications from veterans, service leavers, reservists and military spouses or partners. Applications from eligible candidates who meet the essential criteria for the role will be prioritised for review. Where application volumes are high, additional role-specific and desirable criteria may be applied as part of the shortlisting process which may include holding active security clearance.
In applying for this role, you acknowledge the following "this role falls in scope of the Off Payroll Working in the Public Sector legislation. Any rates of payment quoted will reflect the gross rate per day for the assignment and will be subject to appropriate taxes and statutory costs. As such the payment to the intermediary and your income resulting from this contract will be different".
GENERAL INFORMATION
Posting ID: PIP11407
Type of employment: Contract
Organisation: Companies House
Contract duration: 6 months
Location: Cardiff
Workplace Type: Remote
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London