At a Glance
- Tasks: Lead security for product design and development, ensuring robust protection throughout the lifecycle.
- Company: Join a leading tech firm focused on innovative security solutions.
- Benefits: Competitive pay, flexible working, and opportunities for professional growth.
- Other info: Dynamic role with potential for career advancement in a high-stakes environment.
- Why this job: Make a real difference in product security while working with cutting-edge technologies.
- Qualifications: Experience in bespoke security solutions and relevant engineering degree required.
The predicted salary is between 60750 - 74250 £ per year.
- Product Security Engineer
- Luton
- 6-month contract
- Paying up to Circa £93p/h (Inside IR35)
Please note - Due to the nature of the work, you'll be required to hold a high level of UK Security Clearance
Overview: As the Product Security Engineer /Lead security Engineer, you'll take responsibility for all security aspects of product design, development, verification and maintenance through all phases of the product lifecycle.
The role will focus on undertaking security risk assessments, preparing security risk mitigation plans, deriving security requirements and working closely and directly with product development teams to design, implement and maintain appropriate security controls and the production of wider security artefacts.
Responsibilities
- Production of Security Management Plans, work package descriptions and cost estimates in support of product bids, services and proposals.
- Undertaking security risk assessments, risk mitigation plans, mitigation gap analysis and preparation of security management documentation for system assurance.
- Defining product security requirements, advising development teams on bespoke implementations for product security control implementations and overseeing product development activities.
- Liaison with internal and external security assurance authorities to desmontrate product compliance against recognised UK and wider frameworks.
- Driving collaborative working with external security authorities such as the NCSC to provide underwriting of security solutions.
- Understanding and management of security activities within development, testing and manufacturing environments.
- Advising development teams on suitable platform lockdown and configurations, and supporting penetration test activities.
Analysing penetration test results and preparation of remedial action plans.
- Identify, communicate and drive through life security management, including but not limited to obsolescence planning, vulnerability and patch management for all products within area of responsibility.
- Lead security incident management teams during incident/crisis situations in conjunction with Head of Product Security for EW/FCA.
- Review, maintain and participate corporate product security policies.
- Deliver product security training to project engineering teams.
Essential Skills & Experience
- Experience in the development of besoke product-based security solutions for a military and/or commercial products and systems.
- Graduate degree in relevant engineering, computing or related scientific discipline, and/or evidence of further professional study.
- Full membership of an NCSC recognised professional security body organisation (i. e. CIISec, ISC2 or ISACA).
- Recent experience and demonstratable knowledge of live and legacy UK/EU/NATO information security standards and frameworks, including the UK MOD Secure by Design framework, Gov S 007, HMG IS1&2, ISO27001, NIST SP800-30/37/53, UK MOD Information Security related JSPs, EU CRA and US Do D information security policies.
- Practical experience of producing technical assurance documentation such as Key Management Plans, Testing Security Instructions, Security Operating Procedures and Security Cases.
- Knowledge of current cryptographic technologies and key management systems.
- Understanding of Model Based System Engineering (MBSE) and how Product Security directly inputs into the process.
- Knowledge and understanding of bespoke product-specific Operating Systems, Firmware and Software security controls and how to apply them.
- Knowledge of Quantum Cryptography & Quantum Key management.
- Experience or knowledge of existing threat intelligence sources.
- Knowledge of NATO security policy, risk management and Accreditation.
Disclaimer
This vacancy is being advertised by either Advanced Resource Managers Limited, Advanced Resource Managers IT Limited or Advanced Resource Managers Engineering Limited ("ARM").
ARM is a specialist talent acquisition and management consultancy.
We provide technical contingency recruitment and a portfolio of more complex resource solutions.
Our specialist recruitment divisions cover the entire technical arena, including some of the most economically and strategically important industries in the UK and the world today.
We will never send your CV without your permission.
Where the role is marked as Outside IR35 in the advertisement this is subject to receipt of a final Status Determination Statement from the end Client and may be subject to change.
Product Security Engineer in Luton employer: Jobiqo
Bromley Council is an exceptional employer, dedicated to fostering a supportive and inclusive work environment where employees can thrive. With a strong commitment to professional development, flexible working arrangements, and a generous benefits package, including a local government pension scheme and unique discounts, the Council prioritises employee well-being and career growth. Located in the vibrant Bromley Civic Centre, you will be part of a team that plays a crucial role in shaping the future of the borough while enjoying the balance of urban and suburban life.
StudySmarter Expert Advice🤫
We think this is how you could land Product Security Engineer in Luton
✨Get Engaged in Cybersecurity Communities
Dive into online forums or local meetups, like OWASP events or Cybersecurity conferences. These spaces are packed with pros who can share insights and might even know about temporary roles at places like Jobiqo.
✨Showcase Your Skills Publicly
Link your GitHub or create a series of blogs sharing your knowledge on cybersecurity topics. It’s a great way to demonstrate your expertise and attract attention from hiring managers, especially when they see your passion in action.
✨Stay On Top of Temp Opportunities
Keep an eye on platforms that list temporary positions specifically in tech. Websites focusing on contract roles in cybersecurity can lead straight to employers like Jobiqo.
✨Make Contact with Recruiters Specialising in Cybersecurity
Reach out to recruitment agencies that focus on cybersecurity roles. They often have insights into temporary roles before they’re advertised and can put your name forward to companies like Jobiqo.
We think you need these skills to ace Product Security Engineer in Luton
Some tips for your application 🫡
Show Off Your Technical Skills:In cybersecurity, it's vital to highlight your skills with relevant tools and technologies. Make sure your CV showcases your experience with firewalls, intrusion detection systems, and any cybersecurity frameworks you've worked with. This gives Jobiqo a clear view of your capabilities right off the bat.
Certifications Matter:If you’ve got any cybersecurity certifications, like CompTIA Security+ or CISSP, flaunt them! These not only validate your skills but also show that you’re committed to the field. Add a section to your CV specifically for this, because in a temporary role like this, those credentials can really set you apart.
Tailor Your Cover Letter to the Role:For a temporary position, we want to see your willingness to learn and adapt quickly. Make your cover letter specific to the role at Jobiqo; mention why you’re excited about the opportunity and how it fits your career goals. A personal touch can make a big difference!
Don’t Forget the Soft Skills:In cybersecurity, technical skills are crucial, but so are soft skills like teamwork and communication. Make sure to weave examples of how you've collaborated with teams or communicated complex ideas into your application. This shows that you're not just a tech whizz but also a great team player, perfect for a temporary role at Jobiqo.
How to prepare for a job interview at Jobiqo
✨Brush Up on Technical Skills
Make sure you’re familiar with the latest cybersecurity tools and techniques, like firewalls, intrusion detection systems, and malware analysis. During the interview with Jobiqo for the Product Security Engineer, be prepared to discuss specific scenarios where you tackled security threats or vulnerabilities.
✨Show Your Problem-Solving Prowess
Cybersecurity is all about thinking on your feet. Expect technical questions that require you to demonstrate your problem-solving abilities. You might be presented with a mock security breach scenario, so practising your responses to potential threats can be a game changer!
✨Demonstrate Your Adaptability
As this is a temporary role, showing that you're adaptable and quick to learn is crucial. Talk about times you've picked up new skills or reacted to changing situations quickly. Employers want to know you can hit the ground running and keep things secure during your short stay at Jobiqo.
✨Bring Relevant Certifications
If you have any relevant cybersecurity certifications, like CompTIA Security+ or CEH, be sure to mention them. This can really help you stand out during a temporary hiring process, as it showcases your commitment to the field and your readiness to take on the Product Security Engineer role at Jobiqo.