- Company Name
- Metrea
- Job Title
- Security Controller
- Job Description
-
**Job Title:** Security Controller
**Role Summary:**
Lead the strategic and operational management of an organisation’s physical and procedural security posture. Develop and implement security policy, ensure compliance with Facility Security Clearance (FSC) and national security requirements, manage incidents, deliver training, conduct audits, and advise senior leadership on risk and threat landscapes.
**Expectations:**
- Provide senior‑level security guidance and influence board‑level decisions.
- Maintain continuous compliance with UK security standards and contractual obligations.
- Foster a pervasive security culture across all departments and visitors.
- Ensure timely, effective incident response and threat mitigation.
**Key Responsibilities:**
- Develop, promote, and embed a physical security culture organization‑wide.
- Serve as primary security advisor to senior leadership and Board.
- Manage FSC accreditation, continuous compliance reviews, and documentation (IPZ, FSC instructions, posters).
- Act as Incident Response Manager: detect, coordinate, and resolve security events; liaise with authorities and regulatory bodies.
- Monitor threat intelligence, issue alerts, and recommend mitigation actions.
- Represent the organisation during external audits, inspections, and FSC engagements.
- Collaborate with Facilities, IT, Legal, HR, and external agencies to integrate security into all operations.
- Deliver onboarding and ongoing security awareness training that meets regulatory and organisational standards.
- Conduct internal security audits, reviews, and investigations; implement corrective and preventive actions.
- Track security control effectiveness, recommend enhancements, and report outcomes to stakeholders.
**Required Skills:**
- Exceptional written and verbal communication; influence at Board‑level.
- Security communication expertise—translate technical risk to non‑technical audiences.
- Deep understanding of UK Government and MOD security requirements (JSP 440, SPF, ISO/IEC 27001, Cyber Essentials/Plus).
- Knowledge of FSC accreditation processes and related contractual obligations.
- Strategic challenge mindset—question assumptions, drive innovation, align security with evolving threats.
- Strong stakeholder engagement across internal teams and external agencies (ISAC, MOD, NCSC).
- Project and operational delivery skills: plan and manage security projects, facility adaptations, audits, risk‑mitigation plans.
- Risk assessment, threat intelligence analysis, incident management, and audit management abilities.
**Required Education & Certifications:**
- Bachelor’s degree in Security Management, Information Security, Defence Studies, or related field.
- Professional security certifications such as CISSP, CISM, or Security+ strongly preferred.
- Proven experience with ISO/IEC 27001 implementation and audit, and Cyber Essentials/Plus certification expertise.
---