At a Glance
- Tasks: Design and implement security for cutting-edge space software systems.
- Company: Join Bright Ascension, a leader in space technology innovation.
- Benefits: Collaborative culture, professional growth, and exposure to advanced technologies.
- Other info: Opportunity to work on mission-critical projects in a dynamic environment.
- Why this job: Shape the future of space exploration with your security expertise.
- Qualifications: Experience in security architecture and cloud systems is essential.
The predicted salary is between 70000 - 90000 £ per year.
Bright Ascension , we're building the software that powers the next generation of space missions.
Our flagship platform, HELIX®, enables organisations to develop, deploy, and operate complex space systems faster, more efficiently, and with greater confidence.
As we continue to grow across commercial, government, defence, and national security sectors, we're looking for an exceptional Security Architect to help define how security is designed, implemented, and governed across our technology ecosystem.
This is a unique opportunity to influence the security architecture of a cutting‑edge software platform that supports mission‑critical systems deployed in some of the world's most demanding environments.
The Opportunity
Reporting to the Chief Architect, this role ensures that security is embedded by design across HELIX’s model‑based, component‑based, and service‑oriented approach.
The Product Security Architect drives a distributed, zero‑trust security architecture that is deployable across diverse computing infrastructures, including cloud, on‑premise, air‑gapped and mission‑critical environments.
The role bridges abstract architectural principles and real‑world implementation, translating security principles into product security features, engineering standards, secure deployment patterns and assurance activities for customers, including those in National Security and Defence domains in the UK and US.
If you are passionate about Zero Trust Architecture, cloud security, secure deployment patterns, and influencing technical strategy at scale, we'd love to hear from you.
- What You'll Be Doing
- Security Architecture
- Define, develop, and maintain the security aspects of the HELIX reference architecture.
- Embed security principles (e. g., zero trust, least privilege, defence-in‑depth) within HELIX’s model‑based, service‑oriented, and component‑based paradigms.
- Ensure architectural consistency across all HELIX products and development kits.
- Own the translation of security principles into product security capabilities, engineering standards and secure‑by‑design product patterns.
- Technology Mapping and Standards
- Identify, evaluate, and select key security technologies and standards appropriate for HELIX applications.
- Define clear mappings from technology‑independent architecture to implementation using selected technologies.
- Maintain alignment with industry and government security standards relevant to defence and sensitive applications.
- Product Security Feature Design
- Define and architect product security capabilities within HELIX and associated products, including authentication, authorisation, identity federation, role‑based access control and policy‑based access control.
- Specify product requirements for audit logging, security event capture, tamper evidence, compliance reporting and customer security administration.
- Define encryption, key management, secrets management and secure configuration approaches appropriate for product and deployment contexts.
- Work with product managers, architects and engineering teams to translate security architecture into product backlog items, acceptance criteria and implementation guidance.
- Ensure security features are usable, scalable and appropriate for customer deployment environments.
- Implementation Guidance and Assurance
- Provide expert guidance to product architects and engineering teams on implementing security architecture.
- Support assurance activities, including verification of security controls and architectural compliance.
- Collaborate with teams to ensure secure coding, secure system integration, and appropriate use of cryptography and identity services.
- Secure Software Development and Dev Sec Ops
- Establish and mature secure software development practices across product engineering teams
- Define security requirements, secure coding standards, security acceptance criteria and release gates
- Embed threat modelling, attack surface analysis and security design reviews into product development processes
- Guide the integration of security tooling into CI/CD pipelines, including static application security testing, software composition analysis, secrets scanning, container scanning and dependency vulnerability management
- Support vulnerability triage, remediation prioritisation and product security risk reporting
- Define and maintain a reference set of secure deployment patterns supporting distributed and cloud‑based environments
- Ensure deployment approaches meet both architectural principles and customer‑specific needs
- Support product engineering teams in implementing deployment architectures across varied infrastructure environments (e. g., public cloud, private cloud, on‑premise, air‑gapped systems)
- Technology Selection for Deployment
- Identify and guide the adoption of deployment technologies (e. g., containerisation, orchestration, infrastructure‑as‑code)
- Ensure deployment approaches support secure operations, scalability, and resilience
- Customer and Stakeholder Engagement
- Understand and incorporate customer deployment and security requirements, particularly in regulated and high‑assurance environments.
- Act as a product security subject matter expert for customer assurance, bids, security questionnaires, audits and due diligence activities.
What We're Looking For
Essential technical skills and experience
- Strong experience in security architecture for distributed and cloud‑based systems.
- Practical knowledge of zero trust architecture principles and their application in complex systems
- Experience with cloud platforms (e. g., AWS, Azure, or similar), including secure architecture patterns.
- Deep understanding of; Identity and Access Management (IAM), federation, and authentication protocols (e. g., OAuth 2.0, Open ID Connect, SAML)
- Cryptography and key management (e. g., PKI, TLS, HSMs)
- Network security principles (segmentation, secure communication, service mesh)
- Secure API design, audit logging, tenant isolation, access control models and product security administration patterns
- Familiarity with containerisation and orchestration technologies (e. g., Docker, Kubernetes) and their security implications
- Experience with infrastructure‑as‑code and repeatable deployment patterns.
• Knowledge of relevant standards and frameworks such as
- NIST Cybersecurity Framework / NIST 800‑53
- UK NCSC guidance and Cloud Security Principles
- Zero Trust Architecture (NIST SP 800‑207)
- OWASP Top 10, OWASP SAMM and NIST Secure Software Development Framework
- Experience embedding secure software development practices, threat modelling and security design reviews into product development processes
- Experience integrating application security and supply‑chain security tooling into CI/CD pipelines, including SAST, SCA, secrets scanning and container scanning
- Experience defining architectures independently of specific technologies and then mapping them onto implementations
Essential personal skills and experience
- Strong systems thinking and ability to operate at both conceptual and implementation levels
- Excellent communication skills with the ability to convey complex security concepts to engineers and other stakeholders
- Collaborative mindset with experience working across architecture and engineering teams
- Ability to influence technical direction without direct authority
- High attention to detail combined with strategic thinking
- Strong problem‑solving capabilities in complex, ambiguous environments
Desirable skills and experience
- Experience in National Security, Defence, or highly regulated domains in the UK or US
• Familiarity with
- Secure by Design and Dev Sec Ops practices
- Cross‑domain solutions and handling data at different classification levels
- Service mesh technologies (e. g., Istio, Linkerd)
• Knowledge of compliance frameworks such as
- US Do D Zero Trust Strategy
- Fed RAMP/IL‑level environments
- Experience with high‑assurance systems, mission‑critical systems, or accreditation processes.
- Exposure to model‑based engineering approaches.
Why Join Bright Ascension?
At Bright Ascension, you'll have the opportunity to work on technology that directly supports the future of space exploration, satellite operations, and mission‑critical systems around the world.
You'll join a collaborative, innovative team where your expertise will have genuine impact, helping shape the architecture of products used in some of the most challenging and exciting technical environments.
We offer
- The opportunity to influence the future direction of a market‑leading space software platform
- Exposure to cutting‑edge cloud, security, and distributed systems technologies
- A highly collaborative engineering culture
- The chance to work with customers across commercial, government, defence, and international markets
- Professional growth in a rapidly expanding company at the forefront of the space industry
- Additional Information
- Occasional travel may be required to support customers, partners, and internal teams.
- Eligibility for UK and/or US Security Clearance may be required depending on project involvement.
- A strong alignment with Bright Ascension's values, culture, and engineering excellence is essential.
If you're excited by the challenge of securing the next generation of space software and want to play a key role in shaping the future of HELIX®, we'd love to hear from you.
#J-18808-Ljbffr
Product Security Architect in Edinburgh employer: Bright Ascension Ltd
Bright Ascension Ltd is an excellent employer, offering a dynamic and innovative work environment in the heart of Edinburgh. With a strong focus on employee well-being, the company provides a competitive salary, 36 days of paid leave, and opportunities for professional growth, making it an ideal place for Frontend Engineers looking to make a meaningful impact while enjoying a hybrid work model.
StudySmarter Expert Advice🤫
We think this is how you could land Product Security Architect in Edinburgh
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Bright Ascension Ltd, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Bright Ascension Ltd
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Bright Ascension Ltd. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Product Security Architect in Edinburgh
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Bright Ascension Ltd insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Bright Ascension Ltd that you’re committed to staying ahead in the game.
How to prepare for a job interview at Bright Ascension Ltd
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Bright Ascension Ltd to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Bright Ascension Ltd.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.