IT Security Engineer in Farnborough

IT Security Engineer in Farnborough

Farnborough Full-Time 50000 - 78800 £ / year (est.) Home office (partial)
Leidos

At a Glance

  • Tasks: Lead the implementation of security in cutting-edge defence projects.
  • Company: Join Leidos, a global leader in technology and innovation.
  • Benefits: Enjoy competitive pay, flexible working, and generous leave.
  • Other info: Dynamic team environment with opportunities for growth and learning.
  • Why this job: Make a real impact on national security while developing your skills.
  • Qualifications: Experience in cyber security and knowledge of security frameworks required.

The predicted salary is between 50000 - 78800 £ per year.

Location: Farnborough, UK

Security Clearance Level - High - DV Developed Vetting

Leidos has more than 30 years’ experience of developing and running some of the largest government systems in the world. We are currently hiring to expand our UK based technical team who support our delivery for the UK Govt.

As a Cyber Security Architect, you will be able to work with minimal direction on a specific MOD programme. You will ensure that the solution security design meets the customer functional and non-functional security requirements and provides the necessary assurance to our client, highly likely to be backed up by rigorous assurance and certification processes, normally HMG standards (including MOD-specific JSP), NCSC and NIST 800 standards.

You will have responsibility for interfacing to security design partners across the programme, both customer and supplier representatives, and colleagues within our engineering, service, and business development teams. You will ensure that Leidos can establish and maintain an effective and efficient security architecture for the programme, and that the designs will be able to adapt as customer requirements, legislation and assurance standards change over the programme lifespan.

Within the programme, the role will primarily be responsible to a solution architect and Chief Engineer for developing and delivering the relevant elements of the solution, whilst understanding the whole. You will be required to work in both delivery and change proposal environments. You will have a complete understanding of cyber risk and treatment approaches. Based on a strong ability to communicate risk and its proportionate management, you will know how this issue is addressed both in traditional ‘on-premise’ highly sensitive platforms, and in public cloud technologies. You will be experienced and accomplished in meeting the challenges associated with assuring systems in public and private cloud environments. You will be required to develop high- and low-level security architecture designs for systems intended for secure/sensitive environments, with appropriate security based on detailed risk analysis.

Required Skills:

  • Proven experience of applying Defence-in-Depth principles and a layered security approach to the design and implementation of secure systems.
  • Experience in selecting and implementing proportionate preventive, detective and corrective security controls to manage and reduce risk to acceptable levels.
  • Strong understanding of systems engineering governance processes and practical experience across key stages of the Systems Engineering Lifecycle, including requirements management, configuration management, verification and validation.
  • Experience working within a variety of delivery methodologies, including Waterfall, Incremental Delivery, SAFe Agile and DevSecOps environments.
  • Experience supporting and contributing to key engineering and assurance reviews, including System Requirements Reviews (SRR), Preliminary Design Reviews (PDR), Critical Design Reviews (CDR) and security assurance activities.
  • Proven ability to conduct security and architectural trade-off analyses, collaborating with architects, engineers and stakeholders to develop integrated, coherent and secure solutions.
  • Understanding of service management principles and experience contributing to security operations, service transition and operational security management planning.
  • Experience operating within both programme delivery and business development/bid environments, including supporting solution development, risk assessments and technical proposals.
  • Experience working with Defence Digital, Defence standards, and MOD security policies, architectures and assurance approaches.
  • Experience engaging with customers, suppliers and accrediting authorities to support security assurance, risk management and system accreditation activities.
  • Understanding of security governance, risk management and compliance activities within highly regulated government and defence environments.

Technology skills/Experience:

  • Extensive experience designing, implementing and assuring secure solutions within Amazon Web Services (AWS) environments, including the use of AWS native security services, cloud security best practices, and secure-by-design principles.
  • Extensive experience designing and assuring secure virtualised solutions within VMware environments, including the application of security controls to protect infrastructure, workloads and management platforms.
  • Experience of designing, accrediting and securing solutions hosted within MODCloud environments, particularly MODCloud ICE, including an understanding of Defence cloud hosting patterns and assurance requirements.
  • Experience of security infrastructure in public and private cloud environments, including virtual networking, identity and access management, encryption, logging and monitoring, and hybrid IaaS/PaaS/SaaS architectures.
  • Experience of achieving and maintaining security accreditation and assurance for systems operating in Defence, Government, or other highly regulated environments.
  • Excellent understanding of Confidentiality, Integrity and Availability (CIA) and practical experience in applying these principles.
  • Experience in defining derived security requirements for a system and managing traceability.
  • Experience in producing security assurance documentation sets (such as SyOPS, Security Management Plan, ISMS, and documentation to support DART submissions).
  • Experience of network and boundary protection technologies (firewalls, mail gateways, load balancers, anti-virus), including cross-domain technologies.
  • Experience of authentication and authorisation technologies (SAML, LDAP, PKI, etc.).
  • Understanding of MOD ISN 23/09 Secure by Design.
  • Understanding of the implementation, operation and maintenance of SIEM products.
  • Relevant cloud and security certifications such as AWS Solutions Architect, AWS Security Specialty, CISSP, SABSA, CCSK, or equivalent qualifications would be advantageous.

Communication and Soft Skills:

  • Excellent verbal and written communication skills and works well in a team environment.
  • Capable of developing and communicating a vision to meet the System Requirements.
  • Ability to communicate complex technical ideas across a wide range of different audiences.
  • A good level of commercial awareness that will support the bid and delivery environments.

Clearance Requirements:

This role will require Developed Vetting (DV) Security Clearance. Those candidates without DV must be suitable for the process and will be required to commence application immediately upon successful application.

Commitment to Diversity:

We welcome applications from every part of the community and are committed to a truly diverse and inclusive culture. We foster a sense of belonging, welcoming all perspectives and contributions, and providing equal access to opportunities and resources for everyone.

IT Security Engineer in Farnborough employer: Leidos

Leidos is an exceptional employer that fosters a dynamic work culture in Whiteley, Hampshire, where innovation and collaboration thrive. With a strong focus on employee growth, we offer comprehensive benefits including a contributory pension, private medical insurance, and an impressive 33 days of annual leave, ensuring our team members are well-supported both personally and professionally. Join us to be part of a market-leading operation that values your contributions and empowers you to drive meaningful change.

Leidos

Contact Details:

Leidos Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land IT Security Engineer in Farnborough

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Leidos, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Leidos

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Leidos. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace IT Security Engineer in Farnborough

Cyber Security Architecture
Security Frameworks (e.g., Government Functional Standard 007, NCSC, NIST 800)
Defence-in-Depth Principles
Risk Management
Cloud Security (AWS, VMware)
Security Accreditation and Assurance
Systems Engineering Governance

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Leidos insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Leidos that you’re committed to staying ahead in the game.

How to prepare for a job interview at Leidos

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Leidos to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Leidos.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.