
Sanderson Government and Defence
Security Assurance Analyst
Job Description
Salary: £80,000 - 80,000 per year
Requirements:- We require a strong understanding of IT security controls and security frameworks.
- We require strong knowledge of network, infrastructure, application and data security.
- We require understanding of threat modelling and risk assessment methodologies.
- We require familiarity with MOD security requirements, Classification Guides and security policy.
- We require knowledge of ITAR regulations and export control requirements.
- We require understanding of security standards such as ISO 27001 and NIST CSF.
- We require practical knowledge of common IT architectures and technologies.
- We require strong analytical and problem-solving skills.
- We require excellent leadership skills.
- We require excellent written and verbal communication skills.
- We require attention to detail and the ability to identify gaps and inconsistencies.
- We require a collaborative approach to working with architects and technical teams.
- We require the ability to explain complex security concepts clearly.
- We require a professional approach to challenging design decisions on security grounds.
- We require a commitment to security excellence and MOD compliance.
- We prefer experience with defence or aerospace security programmes.
- We prefer CISSP, CISM or an equivalent security certification.
- We prefer experience with CESG or MOD security assessment methodologies.
- We prefer knowledge of Common Criteria or other formal security evaluation frameworks.
- We prefer familiarity with joint design team processes and defence programme delivery.
- We prefer a background in architecture, infrastructure or systems engineering.
- We conduct detailed security reviews of IT architecture and design documentation.
- We assess security controls and identify gaps against MOD security requirements.
- We evaluate threat models and security assumptions underlying IT designs.
- We review security specifications for completeness and MOD compliance.
- We identify residual security risks and recommend mitigation strategies.
- We support authority leads and advise third parties.
- We verify IT designs comply with Defence Security Policy and MOD Classification Guides.
- We assess adherence to ITAR regulations and export control requirements.
- We review security controls against IS1 (IS1A) and other MOD security standards.
- We validate data handling and classification compliance.
- We ensure personnel security and vetting requirements are addressed.
- We prepare detailed security assessment reports documenting findings and recommendations.
- We document security control specifications and implementation guidance.
- We create security assessment matrices and compliance traceability matrices.
- We provide executive summaries of security findings for stakeholder communication.
- We maintain security documentation for compliance and audit purposes.
- We conduct security risk assessments using appropriate risk methodologies.
- We develop risk matrices and prioritise risks based on likelihood and impact.
- We recommend security controls and mitigation strategies for identified risks.
- We support risk management processes and evidence gathering for MOD approval.
- We track risk mitigation and provide assurance of control implementation.
- We validate implementation of recommended security controls.
- We review security test plans and validation approaches.
- We provide assurance that security controls operate effectively.
- We support security certification and accreditation activities.
- We document security assurance evidence for MOD compliance.
- We communicate security findings and recommendations clearly to technical and non-technical stakeholders.
- We facilitate security discussions between the design team and customer security teams.
- We explain complex security concepts in accessible language.
- We support customer understanding of MOD security requirements and implications.
- Support
- Network
- Security
More:
We are hiring a Security Assurance Analyst with DV clearance for a permanent, full-time role based in Farnborough, Hampshire, UK, with five days on-site. The salary is £70,000 to £80,000 and we offer a competitive benefits package including an enhanced pension and private medical insurance, flexible working arrangements, and professional development plus security training support. We support high-impact defence programmes and offer exposure to cutting-edge defence technology and security challenges. We are committed to respect, equality, diversity and inclusion, and we welcome applicants from all backgrounds. If you need any help or adjustments during the recruitment process, we encourage you to let us know when you apply or speak with our recruiters directly so we can support you.
last updated 32 week of 2026
Interested in this role?
Submit your application now
How to Apply
About Sanderson Government and Defence

Sanderson Government and Defence
Farnborough
IT
Skills & Technologies
Inferred from job description
Salary Insight
£80,000
This role
£45,000
UK median
This salary is 78% above the UK median for Analysts (£45,000/yr).
Based on 2024–2025 UK technology sector benchmarks