At a Glance
- Tasks: Lead cybersecurity efforts in a dynamic defence and maritime programme, ensuring secure engineering practices.
- Company: Join a leading organisation focused on innovative defence solutions and cybersecurity.
- Benefits: Competitive salary, hybrid work model, and opportunities for professional growth.
- Other info: Work in a collaborative environment with excellent career advancement opportunities.
- Why this job: Make a real impact in national security while working with cutting-edge technology.
- Qualifications: Proven experience in cybersecurity and strong leadership skills required.
The predicted salary is between 41000 - 81000 £ per year.
Requirements
- We are looking for someone with a strong blend of cybersecurity leadership, secure engineering, technical assurance, stakeholder management, governance, supplier oversight and defence regulatory experience.
- We need proven experience in a senior cybersecurity, product security, information assurance, secure engineering or security architecture role.
- We need strong understanding of security architecture, including zoning, segregation, trust boundaries, secure configuration baselines, identity and access management and secure remote access.
- We need the ability to lead security input into formal engineering design reviews and technical governance forums.
- We need the ability to translate security risks and regulatory expectations into practical engineering, architecture and delivery actions.
- We need strong understanding of vulnerability assessment, penetration testing, technical assurance and security validation approaches.
- We need the ability to review security evidence, technical designs, SBOMs, assurance artefacts and supplier security claims.
- We need strong stakeholder management skills, including the ability to influence senior technical and programme stakeholders.
- We need the ability to work across engineering, architecture, platform, IT, OT, assurance, supply chain and programme teams.
- We need strong written and verbal communication skills, with the ability to produce concise technical assurance material, risk statements, executive briefings and decision papers.
- We need the ability to work independently and provide senior technical direction without day-to-day supervision.
- Relevant education or industry-recognised certifications in cybersecurity, information assurance, secure engineering, security architecture, risk management or a related discipline are required.
- Suitable qualifications may include BSc, MSc, CISSP, CISM, CRISC, CISA, CCP, ISO 27001 Lead Implementer/Lead Auditor, Security+, Cy SA+, SABSA, TOGAF, IEC 62443, NCSC CAF-related experience or equivalent professional experience.
- Experience working within UK MOD, defence, maritime, shipbuilding, naval, critical national infrastructure or operationally critical environments would be highly beneficial.
- Proven experience supporting major defence, maritime, naval, shipbuilding, CNI or complex engineering programmes is required.
- Experience defining or maintaining a Product Security Management Plan, Security Management Plan, Security Case, accreditation pack or equivalent assurance artefact is required.
- Experience embedding cybersecurity across the full engineering lifecycle, from requirements and design through to build, integration, validation and acceptance is required.
- Experience supporting secure architecture across IT and OT environments is required.
- Experience with shipboard systems, platform systems, industrial control systems, mission systems, navigation, propulsion, communications or similar complex operational environments would be highly beneficial.
- Experience leading security input into design reviews, technical governance forums and assurance gates is required.
- Experience developing and maintaining security risk registers, treatment plans, control evidence and assurance records is required.
- Experience supporting MOD, NCSC, defence or maritime compliance activity is required.
- Experience defining supplier security requirements and assessing third‑party security evidence is required.
- Experience with SBOM review, software assurance, secure configuration, vulnerability management and technical security testing is required.
- Experience supporting cyber incident response design, forensic readiness, logging, monitoring and detection requirements is required.
- Experience operating within Integrated Project Teams or multi‑disciplinary engineering delivery environments is required.
- Experience handling high‑classification or sensitive defence information in line with UK MOD, NCSC, client security and data protection requirements would be advantageous.
- Cybersecurity experience within defence, maritime, shipbuilding, critical national infrastructure or operationally critical environments is required.
- Strong experience operating in a senior product security, cyber assurance, information assurance, secure engineering or security architecture role is required.
- Strong understanding of secure‑by‑design principles and their application across complex engineering lifecycles is required.
- Experience securing complex IT and OT systems, including platform systems, industrial control systems, operational technology, networks, communications and support environments is required.
- Practical experience applying MOD, NCSC, defence security, information assurance or risk management frameworks is required.
- Experience supporting security accreditation, assurance, compliance or certification activities in a UK defence or similarly regulated environment is required.
- Experience conducting threat modelling, security risk assessment and security requirements definition is required.
- Experience supporting FAT, integration testing, harbour trials, sea trials or equivalent technical acceptance activities from a cybersecurity perspective is required.
- TEMPEST awareness or experience, particularly as it relates to defence standards, secure design and NCSC guidance, would be beneficial.
- Experience with maritime cybersecurity, naval systems, shipboard integration or platform security would be beneficial.
- Experience with MOD security policy, defence standards, JSPs, Secure by Design, NCSC guidance or equivalent assurance frameworks is required.
- Experience supporting accreditation, security case development, security assurance planning or certification activities for defence‑or safety‑related systems is required.
- Experience with OT security architecture, industrial control systems, safety‑related control environments and operational resilience is required.
- Experience defining cybersecurity requirements for harbour trials, sea trials, factory acceptance testing or operational acceptance is required.
- Experience supporting supplier assurance across complex engineering supply chains is required.
- Experience contributing to executive‑level security reporting, assurance dashboards, risk briefings or programme decision packs is required.
- Strong supplier and third‑party oversight experience, including security requirements definition, deliverable review, dependency management and acceptance criteria, is required.
- We need the right to work in the UK.
- We need someone willing and able to work in a hybrid model, including client site attendance as required.
- We need someone who holds, or is eligible to obtain, UK Security Clearance where required by the client or programme.
- We need someone comfortable working within secure collaboration environments.
- We need someone able to work under applicable confidentiality and non‑disclosure arrangements.
Responsibilities
- We own and maintain the Product Security Management Plan, ensuring it defines the approach, governance, assurance expectations and lifecycle security activities required for the programme.
- We define and assure the OT and IT security architecture for shipboard and supporting systems.
- We act as a senior security authority within the Integrated Project Team, providing direction, challenge and assurance across engineering and delivery activity.
- We embed secure‑by‑design principles across platform design, system integration, IT/OT architecture, operational technology, networks, communications and mission‑supporting systems.
- We provide security input into formal engineering design reviews, including SRR, PDR, CDR and equivalent programme governance gates.
- We conduct threat modelling and risk assessment activity across ship systems, platform services, navigation, propulsion, communications, IT, OT and associated support environments.
- We define and assure network zoning, segregation, trust boundaries, secure configuration baselines and identity and access management requirements for shipboard systems.
- We support the definition and validation of secure architecture patterns across onboard and supporting environments.
- We apply relevant MOD, NCSC, defence and maritime security frameworks to support assurance, accreditation and compliance activities.
- We maintain and support security risk registers, ensuring risks are clearly articulated, owned, treated, tracked and escalated where required.
- We provide cybersecurity input to accreditation, certification, assurance and acceptance activities.
- We define supplier security requirements and ensure they are embedded in contracts, delivery expectations, security schedules and technical acceptance criteria.
- We review and assess supplier security deliverables, including security claims, compliance evidence, technical designs, assurance artefacts and software bills of materials.
- We support the assessment of third‑party and supply chain security risks across products, systems, components and supporting services.
- We scope and support vulnerability assessment, penetration testing and technical assurance activities across platform, IT, OT and supporting environments.
- We define security requirements for factory acceptance testing, integration testing, harbour trials and sea trial cyber validation.
- We support test planning, test readiness, defect management and security acceptance activity.
- We design and support onboard cyber incident response capabilities, including monitoring, logging, forensic readiness and evidence‑capture requirements.
- We define and assure logging, monitoring and detection requirements across shipboard and supporting environments.
- We provide security advice on operational resilience, cyber recovery, secure maintenance, patching, configuration control and through‑life security management.
- We work collaboratively with naval architects, systems engineers, platform engineers, OT specialists, IT teams, suppliers, assurance teams and senior programme stakeholders.
- We produce clear technical assurance outputs, security design material, decision papers, risk statements, briefing notes and governance updates.
- We work independently as a senior subject matter expert, determining the day‑to‑day technical approach, stakeholder engagement and assurance rhythm required to achieve agreed outcomes.
- Technologies
- Embedded
- Support
- Network
- Security
- TOGAF
- More
We are recruiting a senior cybersecurity and product security specialist to support a complex defence and maritime programme.
This role operates within a hybrid model, with client site attendance as required, and involves working in secure collaboration environments under confidentiality and non‑disclosure arrangements.
The position requires UK right to work and the ability to hold or obtain UK Security Clearance where needed.
We are looking for an experienced professional who can provide senior technical direction across security architecture, assurance, supplier oversight and lifecycle cyber governance for shipboard, IT and OT environments.
- last updated 28 week of 2026
- #J-18808-Ljbffr
Principal Product Security Engineer in England employer: Expleo Group
Expleo Group is an excellent employer that fosters a collaborative work culture, encouraging innovation and creativity among its employees. Located in Preston, the company offers competitive benefits, professional development opportunities, and a supportive environment for growth, making it an ideal place for those looking to make a meaningful impact in the automotive engineering sector.
StudySmarter Expert Advice🤫
We think this is how you could land Principal Product Security Engineer in England
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Expleo Group, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Expleo Group
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Expleo Group. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Principal Product Security Engineer in England
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Expleo Group insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Expleo Group that you’re committed to staying ahead in the game.
How to prepare for a job interview at Expleo Group
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Expleo Group to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Expleo Group.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.