Security Architect (OT, IT, Network and Physical) in Bristol

Security Architect (OT, IT, Network and Physical) in Bristol

Bristol Full-Time 63000 - 77000 £ / year (est.) Home office (partial)
Expleo

At a Glance

  • Tasks: Design and develop security architecture for cutting-edge maritime defence systems.
  • Company: Join Expleo, a leader in engineering and cybersecurity solutions.
  • Benefits: Enjoy a collaborative environment, competitive benefits, and opportunities for skill development.
  • Other info: Flexible hybrid working model with a focus on inclusivity and support.
  • Why this job: Make a real impact on national security with innovative technology.
  • Qualifications: Relevant certifications in cybersecurity and experience in critical infrastructure are essential.

The predicted salary is between 63000 - 77000 £ per year.

Overview

Expleo is a trusted partner for end-to-end, integrated engineering, quality services, and management consulting for digital transformation.

We help businesses harness technological change to successfully deliver innovation, improve resilience and support secure, regulated and operationally critical environments.

As part of the Expleo UK Cybersecurity Practice, you will define and ensure the security architecture for a major UK defence maritime programme, supporting an autonomous surface vessel capability that is being matured towards a whole-ship system design review.

This is a hands-on architecture role for an engineer who is comfortable designing across operational technology, IT, networks, and physical security, and who can serve as a design lead to naval architects, systems engineers, a digital system integrator, and subsystem owners.

Because the platform is designed to operate crewless, the architecture must be fail-safe under compromise and maintain a defined minimum-risk state upon loss of the remote command-and-control link.

You will own the security architecture and the asset baseline that underpins it, working to the Security Management Plan set by the Secure by Design lead and providing architectural evidence to support formal design review.

The role requires strong secure-by-design architectural skills, deep IT and OT understanding, and the ability to translate risk and consequences into segmentation, controls, and defensible design decisions.

Responsibilities

  • Develop the security architecture for OT and IT in coordination with the digital system integrator and sub-system owners, and produce the preliminary security architecture design.
  • Partition the platform into zones and conduits in accordance with IEC 62443, setting target security levels based on safety and mission consequences.
  • Review the network architecture and communications security, and provide advice, including on the resilience of remote command-and-control links and of position, navigation, and timing.
  • Produce the network security architecture in coordination with the digital teams.
  • Review the physical security provision in the design and develop appropriate protection measures, producing the physical security design in coordination with the arrangement team.
  • Define trust boundaries, segregation, secure configuration baselines, identity and access management, and secure remote access requirements for shipboard and supporting systems.
  • Build and structure the initial asset register for configuration control, capturing criticality, zone, ownership and dependency attributes.
  • Support threat modelling and security risk assessment from an architecture perspective, and translate assessed risk into architectural controls.
  • Define architecture-level security requirements and maintain their traceability into the wider requirements specification.
  • Assure that architectural controls are fail-safe and do not defeat safety functions, working alongside safety and engineering colleagues.
  • Provide architectural evidence and materials for internal and external design reviews, including system design reviews, and close out resulting actions.
  • Contribute to supplier and interface security requirements where these bear on the architecture, including third-party payload and control-system interfaces.
  • Produce clear high- and low-level design material, architecture views, decision records and design rationale suitable for technical scrutiny.

Qualifications

  • Relevant education or industry-recognised certifications in security architecture, cybersecurity, secure engineering, operational technology security or a related discipline.
  • Suitable qualifications may include BSc, MSc, CISSP, CISM, CRISC, CCP, ISA/IEC 62443 (Fundamentals Specialist, Risk Assessment Specialist, Design Specialist or Expert), SABSA, TOGAF, CCNP, OSCP, ISO 27001 Lead Implementer/Lead Auditor or equivalent professional experience.
  • Experience working within UK MOD, defence, maritime, shipbuilding, naval, critical national infrastructure or operationally critical environments would be highly beneficial.

Essential skills

  • Demonstrable application of IEC 62443, including zones and conduits, target security levels, and 62443-3-2 style risk assessment.
  • Strong understanding of secure configuration baselines, hardening, identity and access management and privileged access for OT environments.
  • Understanding of secure industrial and platform communications, including relevant protocols, cryptographic protection and public key infrastructure.
  • Ability to translate risk and consequence into proportionate architectural controls, and to defend those decisions in technical forums.
  • Ability to work across engineering, architecture, platform, IT, OT, assurance and supply chain teams.
  • Strong written and verbal communication skills, with the ability to produce precise technical design material.
  • TEMPEST awareness, particularly as it relates to defence standards and secure design.

Experience

  • Proven experience as a security architect, OT security architect, or secure engineering specialist on complex technical programmes.
  • Experience supporting defence, maritime, naval, energy, rail, manufacturing or other critical national infrastructure environments.
  • Experience developing enterprise or platform OT security reference architectures.
  • Experience of multi-site or multi-system IT and OT segmentation programmes.
  • Experience with asset discovery and inventory tooling, and with passive-first approaches in sensitive operational environments.
  • Experience supporting factory acceptance testing, site acceptance testing, integration testing or equivalent technical validation from a security perspective.
  • Experience working alongside system integrators and sub-system suppliers to land architectural requirements.
  • Experience developing security architecture in environments where safety and availability constraints shape the design.
  • Experience handling sensitive defence or client information in line with UK MOD, NCSC, client security and data protection requirements.
  • Strong experience in a security architecture role covering both operational technology and IT environments.
  • Experience designing network segmentation, industrial demilitarised zones, trust boundaries and secure remote access for operational environments.
  • Experience securing industrial control systems, embedded or platform control systems, and safety-related control environments.
  • Experience producing security architecture documentation, including high- and low-level designs, architecture views and design rationale.
  • Experience building or structuring asset inventories and registers to support configuration control and risk assessment.
  • Experience contributing security architecture into formal engineering design reviews and assurance gates.
  • Experience with shipboard systems, platform systems, mission systems, navigation, propulsion, power management or similar complex operational environments.
  • Awareness of maritime cyber engineering benchmarks such as IACS Unified Requirements E26 and E27.
  • Experience with autonomous, uncrewed or remotely operated platforms, including command-and-control link protection and position, navigation and timing resilience.
  • Experience with data diodes, unidirectional gateways or equivalent high-assurance boundary protection.
  • Experience with MOD Secure by Design, NCSC CAF, NIST SP 800-82, ISO 27001 or Def Stan 05-138.
  • Experience of physical and electronic security convergence, including protection of equipment spaces and cable routes.
  • What do I need before I apply
  • Have the right to work in the UK.
  • Hold, or be eligible to obtain, UK Security Check (SC) clearance.

Clearance is a mandatory requirement for this programme, and applicants must meet the UK residency criteria for security clearance.

  • Be willing and able to work in a hybrid model, including client site attendance as required.
  • Be comfortable working within secure collaboration environments and handling information marked up to OFFICIAL-SENSITIVE.
  • Be able to work under the terms of applicable confidentiality and non-disclosure arrangements.

Benefits

  • Collaborative working environment – we stand shoulder to shoulder with our clients and our peers through good times and challenges
  • We empower all passionate technology loving professionals by allowing them to expand their skills and take part in inspiring projects
  • Expleo Academy - enables you to acquire and develop the right skills by delivering a suite of accredited training courses
  • Competitive company benefits
  • Always working as one team, our people are not afraid to think big and challenge the status quo

• As a Disability Confident Committed Employer we have committed to

  • Ensure our recruitment process is inclusive and accessible
  • Communicating and promoting vacancies
  • Offering an interview to disabled people who meet the minimum criteria for the job
  • Anticipating and providing reasonable adjustments as required
  • Supporting any existing employee who acquires a disability or long term health condition, enabling them to stay in work at least one activity that will make a difference for disabled people

“We are an equal opportunities employer and welcome applications from all suitably qualified persons regardless of their race, sex, disability, religion/belief, sexual orientation or age”.

We treat everyone fairly and equitably across the organisation, including providing any additional support and adjustments needed for everyone to thrive

Security Architect (OT, IT, Network and Physical) in Bristol employer: Expleo

Expleo is an exceptional employer, offering a collaborative work environment in Preston where innovation thrives. As an Automotive Systems Engineer, you'll benefit from opportunities for professional growth and skill enhancement while working on cutting-edge projects in Electrical and Embedded Systems. The company prioritises ISO26262 compliance and technical leadership, ensuring that you are at the forefront of automotive advancements.

Expleo

Contact Details:

Expleo Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Security Architect (OT, IT, Network and Physical) in Bristol

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Expleo, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Expleo

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Expleo. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Security Architect (OT, IT, Network and Physical) in Bristol

Security Architecture
Operational Technology (OT) Security
Information Technology (IT) Security
Network Security
Physical Security
IEC 62443 Standards
Risk Assessment

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Expleo insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Expleo that you’re committed to staying ahead in the game.

How to prepare for a job interview at Expleo

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Expleo to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Expleo.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.