Skip to content
Back to jobs

Principal Product Security Engineer

Expleo Group
The Brooms, Bristol
1w ago
TBDunknown$41,000 - $81,000

Key details

Compensation
$41,000 - $81,000

Job Description

Salary: £41,000 - 81,000 per year

Requirements

  • We are looking for someone with a strong blend of cybersecurity leadership, secure engineering, technical assurance, stakeholder management, governance, supplier oversight and defence regulatory experience.
  • We need proven experience in a senior cybersecurity, product security, information assurance, secure engineering or security architecture role.
  • We need strong understanding of security architecture, including zoning, segregation, trust boundaries, secure configuration baselines, identity and access management and secure remote access.
  • We need the ability to lead security input into formal engineering design reviews and technical governance forums.
  • We need the ability to translate security risks and regulatory expectations into practical engineering, architecture and delivery actions.
  • We need strong understanding of vulnerability assessment, penetration testing, technical assurance and security validation approaches.
  • We need the ability to review security evidence, technical designs, SBOMs, assurance artefacts and supplier security claims.
  • We need strong stakeholder management skills, including the ability to influence senior technical and programme stakeholders.
  • We need the ability to work across engineering, architecture, platform, IT, OT, assurance, supply chain and programme teams.
  • We need strong written and verbal communication skills, with the ability to produce concise technical assurance material, risk statements, executive briefings and decision papers.
  • We need the ability to work independently and provide senior technical direction without day-to-day supervision.
  • Relevant education or industry-recognised certifications in cybersecurity, information assurance, secure engineering, security architecture, risk management or a related discipline are required.
  • Suitable qualifications may include BSc, MSc, CISSP, CISM, CRISC, CISA, CCP, ISO 27001 Lead Implementer/Lead Auditor, Security+, CySA+, SABSA, TOGAF, IEC 62443, NCSC CAF-related experience or equivalent professional experience.
  • Experience working within UK MOD, defence, maritime, shipbuilding, naval, critical national infrastructure or operationally critical environments would be highly beneficial.
  • Proven experience supporting major defence, maritime, naval, shipbuilding, CNI or complex engineering programmes is required.
  • Experience defining or maintaining a Product Security Management Plan, Security Management Plan, Security Case, accreditation pack or equivalent assurance artefact is required.
  • Experience embedding cybersecurity across the full engineering lifecycle, from requirements and design through to build, integration, validation and acceptance is required.
  • Experience supporting secure architecture across IT and OT environments is required.
  • Experience with shipboard systems, platform systems, industrial control systems, mission systems, navigation, propulsion, communications or similar complex operational environments would be highly beneficial.
  • Experience leading security input into design reviews, technical governance forums and assurance gates is required.
  • Experience developing and maintaining security risk registers, treatment plans, control evidence and assurance records is required.
  • Experience supporting MOD, NCSC, defence or maritime compliance activity is required.
  • Experience defining supplier security requirements and assessing third-party security evidence is required.
  • Experience with SBOM review, software assurance, secure configuration, vulnerability management and technical security testing is required.
  • Experience supporting cyber incident response design, forensic readiness, logging, monitoring and detection requirements is required.
  • Experience operating within Integrated Project Teams or multi-disciplinary engineering delivery environments is required.
  • Experience handling high-classification or sensitive defence information in line with UK MOD, NCSC, client security and data protection requirements would be advantageous.
  • Cybersecurity experience within defence, maritime, shipbuilding, critical national infrastructure or operationally critical environments is required.
  • Strong experience operating in a senior product security, cyber assurance, information assurance, secure engineering or security architecture role is required.
  • Strong understanding of secure-by-design principles and their application across complex engineering lifecycles is required.
  • Experience securing complex IT and OT systems, including platform systems, industrial control systems, operational technology, networks, communications and support environments is required.
  • Practical experience applying MOD, NCSC, defence security, information assurance or risk management frameworks is required.
  • Experience supporting security accreditation, assurance, compliance or certification activities in a UK defence or similarly regulated environment is required.
  • Experience conducting threat modelling, security risk assessment and security requirements definition is required.
  • Experience supporting FAT, integration testing, harbour trials, sea trials or equivalent technical acceptance activities from a cybersecurity perspective is required.
  • TEMPEST awareness or experience, particularly as it relates to defence standards, secure design and NCSC guidance, would be beneficial.
  • Experience with maritime cybersecurity, naval systems, shipboard integration or platform security would be beneficial.
  • Experience with MOD security policy, defence standards, JSPs, Secure by Design, NCSC guidance or equivalent assurance frameworks is required.
  • Experience supporting accreditation, security case development, security assurance planning or certification activities for defence- or safety-related systems is required.
  • Experience with OT security architecture, industrial control systems, safety-related control environments and operational resilience is required.
  • Experience defining cybersecurity requirements for harbour trials, sea trials, factory acceptance testing or operational acceptance is required.
  • Experience supporting supplier assurance across complex engineering supply chains is required.
  • Experience contributing to executive-level security reporting, assurance dashboards, risk briefings or programme decision packs is required.
  • Strong supplier and third-party oversight experience, including security requirements definition, deliverable review, dependency management and acceptance criteria, is required.
  • We need the right to work in the UK.
  • We need someone willing and able to work in a hybrid model, including client site attendance as required.
  • We need someone who holds, or is eligible to obtain, UK Security Clearance where required by the client or programme.
  • We need someone comfortable working within secure collaboration environments.
  • We need someone able to work under applicable confidentiality and non-disclosure arrangements.

Responsibilities

  • We own and maintain the Product Security Management Plan, ensuring it defines the approach, governance, assurance expectations and lifecycle security activities required for the programme.
  • We define and assure the OT and IT security architecture for shipboard and supporting systems.
  • We act as a senior security authority within the Integrated Project Team, providing direction, challenge and assurance across engineering and delivery activity.
  • We embed secure-by-design principles across platform design, system integration, IT/OT architecture, operational technology, networks, communications and mission-supporting systems.
  • We provide security input into formal engineering design reviews, including SRR, PDR, CDR and equivalent programme governance gates.
  • We conduct threat modelling and risk assessment activity across ship systems, platform services, navigation, propulsion, communications, IT, OT and associated support environments.
  • We

Company & context

Evidence is labeled so you can tell internal community data from public sources.

JobiQueue salary sample

Range from 3 indexed roles at this employer: $41,000 - $81,000(mid ~61000)

Context may refresh in the background.

Trust-check this listing

Verify scam risk and ghost-job signals before you apply.

Related roles

Browse more remote Software Engineer jobs.

Principal Product Security Engineer

Expleo Group
TBDThe Brooms, Bristol$41,000 - $81,000
1w ago
View details

Principal Product Security Engineer

Expleo Group
TBDThe Brooms, Bristol$41,000 - $81,000
2d ago
View details

Source: DevITJobs • Last updated 1w ago