Cybersecurity Consultant (Discovery, Threat and Requirements) in Bristol

Cybersecurity Consultant (Discovery, Threat and Requirements) in Bristol

Bristol Full-Time 63000 - 77000 £ / year (est.) Home office (partial)
Expleo

At a Glance

  • Tasks: Lead cybersecurity discovery and risk assessment for a major UK defence maritime programme.
  • Company: Join Expleo, a trusted partner in digital transformation and engineering services.
  • Benefits: Enjoy a collaborative environment, competitive benefits, and access to accredited training courses.
  • Other info: Be part of a dynamic team with opportunities for professional growth.
  • Why this job: Make a real impact on national security while working with cutting-edge technology.
  • Qualifications: Relevant education or certifications in cybersecurity and experience in technical programmes.

The predicted salary is between 63000 - 77000 £ per year.

Overview

Expleo is a trusted partner for end-to-end, integrated engineering, quality services, and management consulting for digital transformation.

We help businesses harness technological change to successfully deliver innovation, improve resilience and support secure, regulated and operationally critical environments.

As part of the Expleo UK Cybersecurity Practice, you will deliver the discovery, threat, risk and requirements activity that underpins the security case for a major UK defence maritime programme, supporting an autonomous surface vessel capability being matured towards a whole-ship system design review.

This is a delivery-focused consultancy role for someone methodical and evidence-driven.

You will establish the asset baseline that everything else traces back to, contribute to the threat and risk picture, and capture the security requirements that the design team will build to.

You will work within a small, security-cleared team alongside a Secure by Design lead and a security architect, and directly with the client's design team, in an environment where accuracy, traceability and clear documentation carry real weight.

The role suits a cybersecurity consultant with a solid grounding in threat and risk methods and requirements work, who is looking to apply this in a technically demanding defence maritime programme.

Responsibilities

  • Lead discovery activity across documentary, logical, interview and physical sources to establish an authoritative asset baseline.
  • Populate and maintain the initial asset register, capturing asset class, criticality, ownership, configuration state, dependencies and interfaces.
  • Establish and maintain the platform threat landscape by drawing on credible, up-to-date threat information.
  • Contribute to threat modelling using recognised methods such as STRIDE and MITRE ATT&CK for Industrial Control Systems, expressed as attack paths.
  • Support the preliminary security risk assessment using NIST SP 800-30 and ISO/IEC 27005, and maintain entries in the design risk register.
  • Capture security requirements and maintain the traceability thread from threat to risk to control to requirement.
  • Support security classification and criticality assessment across platform systems and information.
  • Prepare clear, well-structured documentation and evidence packs suitable for design review and client acceptance.
  • Support the compliance crosswalk of programme artefacts against applicable standards and assurance frameworks.
  • Support security stakeholder meetings, capture actions and drive them to closure.
  • Produce knowledge-transfer material to enable the client design team to maintain the artefacts across subsequent phases.
  • Work collaboratively with colleagues in engineering, architecture, IT, OT, and assurance, and promptly escalate issues and risks.

Qualifications

  • Relevant education or industry-recognised certifications in cybersecurity, information assurance, risk management or a related discipline.
  • Suitable qualifications may include BSc, MSc, Comp TIA Security+, Cy SA+, CISM, CISSP (or associate), ISO 27001 Lead Implementer/Lead Auditor, ISO 27005 risk, ISA/IEC 62443 Cybersecurity Fundamentals Specialist, or equivalent professional experience.
  • Candidates working towards relevant certifications alongside strong practical experience are welcome to apply.
  • Experience working within UK MOD, defence, maritime, shipbuilding, naval, critical national infrastructure or operationally critical environments would be highly beneficial.

Essential skills

  • Working knowledge of threat modelling methods and the ability to express threats as credible attack paths.
  • Understanding of both IT and operational technology environments and the different security considerations each carries.
  • Awareness of MOD, NCSC or defence security frameworks and how they shape assurance evidence.
  • Strong documentation skills, with the ability to produce accurate, well-structured and reviewable technical material.
  • Methodical, detail-focused approach with a strong sense of ownership for the quality and traceability of evidence.
  • Good stakeholder skills, with the ability to gather information effectively from engineers and system owners.
  • Ability to work as part of a small, security-cleared delivery team to fixed milestones.
  • A military or defence background, particularly in communications, information systems or security.

Experience

  • Experience delivering cyber risk, assurance or security requirements work on technical programmes.
  • Experience contributing to threat assessments, threat models or risk assessments for complex systems.
  • Experience producing security documentation and evidence for review by clients, assessors or regulators.
  • Experience working alongside engineering or design teams in a multi-disciplinary environment.
  • Experience of regulated, safety-critical or operationally critical delivery environments.
  • Experience handling sensitive defence or client information in line with UK MOD, NCSC, client security and data protection requirements.
  • Practical cybersecurity consultancy experience in defence, maritime, critical national infrastructure or another regulated or operationally critical environment.
  • Experience conducting discovery and building or maintaining asset registers or configuration baselines.
  • Experience supporting security risk assessment using recognised methods such as NIST SP 800-30 or ISO/IEC 27005.
  • Experience capturing security requirements and maintaining traceability to threat, risk and control.
  • Experience with marine or vessel systems, or with defence communications and information systems.
  • TEMPEST awareness, or experience of emanation security assurance to NATO standards.
  • Experience with IEC 62443, NCSC CAF, MOD Secure by Design, ISO 27001 or Def Stan 05-138.
  • Experience of autonomous, uncrewed or remotely operated systems.
  • Experience supporting design reviews or formal assurance gates.
  • Experience with requirements management or traceability tooling.
  • What do I need before I apply
  • Have the right to work in the UK.
  • Hold, or be eligible to obtain, UK Security Check (SC) clearance.

Clearance is a mandatory requirement for this programme, and applicants must meet the UK residency criteria for security clearance.

  • Be willing and able to work in a hybrid model, including client site attendance as required.
  • Be comfortable working within secure collaboration environments and handling information marked up to OFFICIAL-SENSITIVE.
  • Be able to work under the terms of applicable confidentiality and non-disclosure arrangements.

Benefits

  • Collaborative working environment – we stand shoulder to shoulder with our clients and our peers through good times and challenges
  • We empower all passionate technology loving professionals by allowing them to expand their skills and take part in inspiring projects
  • Expleo Academy - enables you to acquire and develop the right skills by delivering a suite of accredited training courses
  • Competitive company benefits
  • Always working as one team, our people are not afraid to think big and challenge the status quo

• As a Disability Confident Committed Employer we have committed to

  • Ensure our recruitment process is inclusive and accessible
  • Communicating and promoting vacancies
  • Offering an interview to disabled people who meet the minimum criteria for the job
  • Anticipating and providing reasonable adjustments as required
  • Supporting any existing employee who acquires a disability or long term health condition, enabling them to stay in work at least one activity that will make a difference for disabled people

“We are an equal opportunities employer and welcome applications from all suitably qualified persons regardless of their race, sex, disability, religion/belief, sexual orientation or age”.

We treat everyone fairly and equitably across the organisation, including providing any additional support and adjustments needed for everyone to thrive

Cybersecurity Consultant (Discovery, Threat and Requirements) in Bristol employer: Expleo

Expleo is an exceptional employer, offering a collaborative work environment in Preston where innovation thrives. As an Automotive Systems Engineer, you'll benefit from opportunities for professional growth and skill enhancement while working on cutting-edge projects in Electrical and Embedded Systems. The company prioritises ISO26262 compliance and technical leadership, ensuring that you are at the forefront of automotive advancements.

Expleo

Contact Details:

Expleo Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Cybersecurity Consultant (Discovery, Threat and Requirements) in Bristol

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Expleo, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Expleo

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Expleo. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Cybersecurity Consultant (Discovery, Threat and Requirements) in Bristol

Threat Modelling
Risk Assessment
Cybersecurity
Documentation Skills
Stakeholder Engagement
Asset Management
NIST SP 800-30

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Expleo insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Expleo that you’re committed to staying ahead in the game.

How to prepare for a job interview at Expleo

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Expleo to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Expleo.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.