Product Cybersecurity Engineer / Specialist in Harwell

Product Cybersecurity Engineer / Specialist in Harwell

Harwell Full-Time 50000 - 65000 £ / year (est.) Home office (partial)
Agilent Technologies, Inc.

At a Glance

  • Tasks: Lead cybersecurity efforts for innovative products in a dynamic tech environment.
  • Company: Join Agilent Technologies, a leader in spectroscopy and vacuum solutions.
  • Benefits: Enjoy competitive pay, hybrid work options, and career growth opportunities.
  • Other info: Collaborative team culture with exciting projects and a focus on continuous improvement.
  • Why this job: Make a real impact on product security in regulated industries like defence and aviation.
  • Qualifications: Experience in product cybersecurity and strong problem-solving skills required.

The predicted salary is between 50000 - 65000 £ per year.

Location: Harwell, Oxfordshire (Hybrid)

Company: Agilent Technologies - Spectroscopy & Vacuum Division

We are seeking an experienced Product Cybersecurity Engineer to lead and support cybersecurity activities across our spectroscopy and vacuum product portfolio. This role is critical to ensuring our products meet evolving global cybersecurity regulations, customer requirements, and industry best practices—particularly in regulated markets such as aviation security, customs & borders, pharmaceuticals, and defence.

You will work cross-functionally with R&D, Product Security, Agilent IT, Sales, and Marketing teams, ensuring cybersecurity is embedded throughout the product lifecycle—from design and development through to deployment and ongoing support.

Key Responsibilities:

  • Cybersecurity Compliance & Regulation
    • Interpret and apply global cybersecurity and privacy regulations (e.g. GDPR, EU Cyber Resilience Act).
    • Act as product line lead for EU CRA readiness, including:
      • Product cybersecurity documentation
      • Policy and procedure development
      • Coordination and collaboration with product teams and central security functions
    • Own and track remediation plans to ensure continued product compliance.
    • Maintain and review cybersecurity requirements aligned to target markets (e.g. defence, aviation, customs).
    • Ensure products are GDPR compliant.
  • Sales & Customer Cybersecurity Support
    • Support Sales and Marketing with cybersecurity content for tenders and bids:
      • Contribute to cybersecurity whitepapers and standard documentation
      • Provide technical input for tender compliance submissions
    • Participate in customer-facing cybersecurity discussions, where needed.
    • Review customer and regulatory documentation and translate requirements into product development inputs.
    • Stay aligned with industry developments and best practices.
  • Secure Product Development
    • Ensure products meet:
      • Internal Agilent security policies and procedures
      • External regulatory and customer requirements
    • Drive a proactive cybersecurity approach within product development.
    • Conduct or support cybersecurity testing and assessments, identifying vulnerabilities and providing reports.
    • Collaborate with R&D to:
      • Analyse vulnerabilities
      • Identify false positives and controls
      • Conduct threat modelling
      • Define, implement and track remediation plans
    • Provide technical guidance on:
      • Encryption and key management
      • Patch management
      • Identity and user management
    • Contribute to infrastructure security (e.g. certificate and secret management).
    • Support secure product configuration tailored to customer needs.
  • DevSecOps & Security Engineering
    • Drive adoption of DevSecOps practices, including:
      • CI/CD security integration
      • Automated vulnerability scanning (e.g. Nessus)
    • Implement and maintain:
      • Static Application Security Testing (SAST)
      • Dynamic Application Security Testing (DAST)
      • Software Composition Analysis (SCA)
    • Lead Software Bill of Materials (SBOM) creation and management in the spectroscopy and vacuum product lines.
    • Perform application security and penetration testing in collaboration with the internal Product Security Program team.
  • Embedded Systems Security
    • Secure Windows 10/11 IoT-based embedded systems, including:
      • Group policy and registry hardening
      • Attack surface reduction (services, ports, etc.)
      • Patch and update management
      • Endpoint protection and antivirus
      • Mobile Device Management (e.g. Intune)
    • Implement Microsoft security features such as:
      • BitLocker, AppLocker, Unified Write Filter (UWF)
    • Support development and maintenance of embedded OS images.
    • (Desirable) Knowledge of Embedded Linux security.
  • Continuous Improvement & Future-Proofing
    • Monitor emerging threats, vulnerabilities, and regulatory changes.
    • Ensure products remain secure throughout their lifecycle.
    • Promote continuous improvement in cybersecurity practices.
  • Operational Security Activities
    • Manage OS patching and release cycles for product platforms.
    • Maintain secure embedded OS builds (e.g. FFU images).
    • Ensure regular:
      • Vulnerability scanning (e.g. Nessus)
      • Security testing and validation
    • Support CI/CD environment hardening and security patching.

Qualifications:

Essential

  • Bachelor’s or master’s degree or equivalent
  • Proven experience in product cybersecurity or application security – typically 4+ years relevant experience.
  • Strong understanding of:
    • Secure software development lifecycle (SSDLC)
    • Vulnerability management and remediation
    • Regulatory compliance (GDPR, EU CRA, emerging EU and global regulations)
  • Hands-on experience with:
    • Security testing (SAST, DAST, SCA)
    • Penetration testing or vulnerability analysis
    • Threat modelling
  • Knowledge of Windows OS security (preferably embedded/IoT variants).
  • Experience working with cross-functional engineering teams.

Desirable

  • Relevant cybersecurity certifications (e.g. CISSP, CompTIA PenTest, ISC2 CSSLP would be beneficial)
  • Familiarity with DevSecOps tools and CI/CD pipelines
  • Experience with:
    • Nessus or similar scanning tools
    • Software Bill of Materials (SBOM)
  • Embedded Linux security knowledge.
  • Exposure to regulated industries (defence, aviation, pharma, border security).
  • Experience leveraging modern AI-assisted tools (e.g. Copilot, LLMs) to enhance secure development, documentation, and cybersecurity analysis while applying appropriate engineering judgement and data security controls.

Personal Attributes

  • Strong analytical and problem-solving skills
  • Ability to translate regulations into actionable engineering requirements
  • Excellent communication skills, including customer-facing interactions
  • Proactive, self-driven, and detail-oriented
  • Comfortable working across multiple stakeholders and geographies

What we offer

  • Exciting projects in a multifaceted collaborative team grounded on an Agile Culture and Approach
  • Career development opportunities in an international company
  • Competitive compensation and benefits package
  • Work-Life-Balance programs
  • Permanent contract in a fast-growing global company
  • Company pension scheme
  • Private health care

Agilent inspires and supports discoveries that advance the quality of life. We provide life science, diagnostic and applied market laboratories worldwide with instruments, services, consumables, applications, and expertise. Agilent enables customers to gain the answers and insights they seek, so they can do what they do best: improve the world around us.

This job has a full time weekly schedule. Our pay ranges are determined by role, level, and location. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. During the hiring process, a recruiter can share more about the specific pay range for a preferred location. Pay and benefit information by country are available at: https://careers.agilent.com/locations

Agilent Technologies Inc. is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability or any other protected categories under all applicable laws.

Travel Required: Occasional

Shift: Day

Duration: No End Date

Product Cybersecurity Engineer / Specialist in Harwell employer: Agilent Technologies, Inc.

Agilent Technologies is an exceptional employer, offering a dynamic work environment in Harwell, Oxfordshire, where innovation meets collaboration. With a strong focus on employee growth through career development opportunities and a commitment to work-life balance, Agilent fosters a culture that values diversity and inclusion. Employees benefit from competitive compensation, comprehensive health care, and the chance to work on exciting projects that make a real impact in regulated industries such as defence and pharmaceuticals.

Agilent Technologies, Inc.

Contact Details:

Agilent Technologies, Inc. Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Product Cybersecurity Engineer / Specialist in Harwell

Tip Number 1

Network like a pro! Reach out to folks in the cybersecurity field, especially those at Agilent or similar companies. Attend industry events or webinars to make connections and get your name out there.

Tip Number 2

Prepare for interviews by brushing up on your knowledge of global cybersecurity regulations and best practices. Be ready to discuss how you can contribute to compliance and security in product development.

Tip Number 3

Showcase your hands-on experience with security testing tools like SAST and DAST. Bring examples of how you've identified vulnerabilities and implemented solutions in past roles.

Tip Number 4

Don't forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you're serious about joining the team.

We think you need these skills to ace Product Cybersecurity Engineer / Specialist in Harwell

Product Cybersecurity
Application Security
Cybersecurity Compliance
GDPR
EU Cyber Resilience Act
Vulnerability Management
Threat Modelling

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Product Cybersecurity Engineer role. Highlight relevant experience, especially in cybersecurity compliance and secure product development. We want to see how your skills align with our needs!

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about cybersecurity and how your background makes you a great fit for our team. Don’t forget to mention any hands-on experience with security testing or regulatory compliance.

Showcase Your Technical Skills:We love seeing technical expertise! Be sure to include specific tools and methodologies you've used, like SAST, DAST, or vulnerability management. This will help us understand your hands-on experience and how you can contribute to our projects.

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, you’ll find all the details you need about the role and our company culture there!

How to prepare for a job interview at Agilent Technologies, Inc.

Know Your Cybersecurity Regulations

Make sure you brush up on global cybersecurity regulations like GDPR and the EU Cyber Resilience Act. Being able to discuss how these regulations impact product development will show that you understand the industry's compliance landscape.

Showcase Your Cross-Functional Experience

This role involves working with various teams, so be ready to share examples of how you've collaborated with R&D, Sales, or Marketing in past projects. Highlighting your ability to communicate effectively across departments will set you apart.

Prepare for Technical Questions

Expect questions about secure software development lifecycle (SSDLC), vulnerability management, and security testing methods like SAST and DAST. Brush up on these topics and be prepared to discuss your hands-on experience with them.

Demonstrate Continuous Improvement Mindset

Agilent values continuous improvement in cybersecurity practices. Be ready to talk about how you've identified and implemented improvements in past roles, especially in relation to emerging threats and vulnerabilities.