Responsibilities/Duties
System Information Security Management
• Provide Line Management of System Information Security Engineers
• Responsible for System Security Engineering best practice including adherence to, and maintenance of, Engineering System Security processes and procedures
• Provide a leading role in development, maintenance and implementation of the organisation’s System Security System
• Coordination of System Security related matters between Anschuetz offices in Portsmouth and Kiel
• Keep up to date with UK MOD and industry system security regulations and best practice
• Is accountable to the Engineering Manager
• Works in close cooperation with Programme and Project Managers
• Provide direction and guidance on system deployment through the lifetime of the project
System Information Security Engineering
Provide System Security Engineering and Deployment Services for Maritime Surveillance Systems projects and Naval Bridge Systems projects from bid phase through to support phase including:
• Design, implement, document security controls across systems, devices and applications to comply with MoD policies on Naval Platforms and Commercial Systems as appropriate
• Management and documentation of security requirements for systems including interpretation of security guidance from customers and external sources
• Perform security risk assessments using methodologies to identify and prioritise cyber security and cyber resilience risks, controls and mitigations to manage those risks through risk treatment plans
• Produce security documentation such as Security Management Plans, System Security Design Documents, RMADS and SyOPs as required to meet project deliverable requirements
• Support with project induction including management of the SAL for project data
• Provide cyber security advice and guidance to all stakeholders, engineers, technical authorities, project managers, the wider business and customer communities, throughout the whole project lifecycle and at all required classifications
• Scoping and managing testing by external penetration test companies and ensuring remediation activity is performed to completion
• Achieving and maintaining security accreditations or assurance as required, including assessing the impact to security of all proposed system changes
• Engage with stakeholders, including the CyDR Accreditor and Security Assurance Coordinator, to ensure that the security solution is accreditable whilst considering and mitigating the impact on the development programme and end users
• Support security within the supply chain, including meeting the requirements of the Defence Cyber Protection Partnership plus our own company initiatives.
• Engage with stakeholders, engineering teams and sub-contractors to provide direction, guidance and support on acceptable and balanced information security solutions
• Works in close cooperation with and is accountable to the Project Manager
• Design, document and provisioning of deployment artefacts for software systems including Virtual Machines, Active Directory Servers and configuration, Operating Systems including configuration and cyber security hardening procedures.
• Support automation of deployment pipelines of the software systems where appropriate to
reduce effort and improve quality of deployed systems.
• Design and documentation of network architecture including support of critical activities associated with the network infrastructure configuration and test such as switching, routing,
encryption, security, optimisation, VLANs.
Education requirements
• Degree in Engineering, Physics, Computing or other relevant subject
Vocational Training requirements
• Deep knowledge of network systems, including design, troubleshooting, infrastructure (hardware, software and telecommunications), maintenance and operations.
• Demonstrable knowledge of Information assurance systems engineering and development practices.
• Ability to articulate security advice directly to key stakeholders within both the business and the customer community.
• Excellent communication skills with the ability to influence technical experts in other technical competencies.
• Knowledge and solid understanding of industry best practices including appropriate MoD Secure by Design and Defence Standards such as DefStan 05-138 and DefStan 05-139.
• CISSP, CISM or similar
• Defence, systems or software engineering background.
• CISCO IOS knowledge.
• Knowledge of and experience with implementation of ISO27001.
• Experience of security risk assessments, risk treatment plans, and accreditation document sets
Personal
Must have a driving licence and passport.
Must have or be able to get Security Clearance from the UK Defence Vetting Agency.
Should have excellent communication’s skills and an outgoing personality.
Must be self motivated.
Supervisory Responsibility
System Information Security Engineers
Supervision Received
UKAN Engineering Manager
System Information Security Manager in Portsmouth employer: Anschuetz UK
Anschütz is an exceptional employer, offering a collaborative and inclusive work culture that prioritises continuous improvement and professional growth. Located in the vibrant Portsmouth area, employees benefit from flexible working options, generous holiday allowances, and comprehensive career development opportunities, making it an ideal place for those seeking meaningful and rewarding employment in the engineering and maritime sectors.