Head of Product Security (RATS) in Edinburgh
Head of Product Security (RATS)

Head of Product Security (RATS) in Edinburgh

Edinburgh Full-Time 48000 - 72000 £ / year (est.) No home office possible
Go Premium
L

At a Glance

  • Tasks: Lead product security for cutting-edge airborne systems and ensure compliance with industry standards.
  • Company: Join Leonardo, a leader in aerospace innovation and technology.
  • Benefits: Enjoy a comprehensive benefits package, including career development and work-life balance support.
  • Why this job: Make a real impact on mission-critical systems while working with innovative technologies like AI and autonomy.
  • Qualifications: Experience in security risk management and knowledge of relevant frameworks is essential.
  • Other info: Collaborate with talented engineers and contribute to global aerospace programmes.

The predicted salary is between 48000 - 72000 £ per year.

Your impact

Leonardo has an exciting opportunity to contribute at a senior governance level, to the design and certification of an expanding portfolio of world class Mission Critical and Flight Safety involved Airborne Systems. As part of the Engineering Governance organisation, working across the Radar and Advanced Targeting (RATS) product portfolio, you will be responsible for determining a basis of certification appropriate to the security threat. Ideally, you will have practical experience of UK MOD Secure-by-Design, ISO27001/27004/27005, NIST Risk Management Framework (RMF) and NIST SP800-30/SP800-53. Knowledge of UK/NATO Information Assurance/Accreditation frameworks would be helpful as well as familiarity with the application of cyber resilience controls within embedded systems.

Working across the Sector product lines within the RATS Line of Business (LoB), you will support and advise the Chief Engineer (CE) Design Integrity (DI) to develop security and engineering management plans, resourced and executed by each of the Integrated Product Teams (IPTs) under the oversight of an assigned Product Cyber Resilience Manager (PCRM). You will support the PCRMs guiding the engineering teams within the IPTs through the product lifecycle, managing the basis of certification and/or acceptance on behalf of the System Design Authority, to achieve successful delivery of the products. You will also provide subject matter advice into the product maturity reviews, following the principles of Secure by Design. A significant intrinsic factor of the role is the requirement for continuous improvement of the cyber resilience of Leonardo products. Leonardo will support you to develop yourself and the process capability of the business.

Many Leonardo products exist at the ‘bleeding edge’ applying innovative technologies such as AI/ML, Autonomy, high-assurance multicore processing, Electro-Optics, and Model Based Systems Engineering. You will have the opportunity to contribute to and learn from these innovations. The RATS products cover sensor and defensive applications such as Laser Directed Energy Weapons (LDEW), Infrared Countermeasure (IRCM), Integrated Sensing Radar, Surveillance Radar plus other Non-Kinetic Effects products. You’ll be involved in major UK and Global programmes such as Eurofighter Typhoon and Global Combat Air Program, together with many other Crewed and Un-Crewed Airborne Platforms around the globe.

As the Head of Product Security, you will:

  • The RATS HoPS is responsible for the strategic elements of Product Security.
  • They are accountable to the CE DI for performance of Product Security management within RATS, and accountable to the Leonardo Electronics UK Head of Product Security Capability for metrics and compliance reporting.
  • The HoPS has delegated authority from the RATS CE DI and is responsible for the following elements on their behalf:
  • Manage Product Security processes, templates and guidance and oversee implementation.
  • Use of KPIs to improve compliance, effectiveness and efficiency of the Product Security Management.
  • Support sufficient and appropriate competency of PCRM or Product Security Management Specialist (PSMS) to meet RATS current and future needs.
  • Advocate Product Security within DI and the wider RATS community.
  • Production and reporting of RATS Product Security metrics as requested and directed by the Head of Product Security Capability.
  • Attendance and support to the Product Security Special Interest Groups (SIG) and sub-groups covering Governance and Technical topics.
  • Assist the CE DI in performing their Governance responsibilities by supporting Design Maturity Reviews and the design certification process.
  • Assist the CE DI in the management of current and future resourcing demands to meet RATS needs.
  • Oversee the management of Product Security events or incidents within RATS.
  • The HoPS also supports the CE DI as a delegated signatory for product security, by undertaking the oversight of ensuring the correct design assurance, is applied to Leonardo products.
  • The HoPS acts as a security assessor or security specialist.
  • The HoPS will be required to have the relevant levels of independence from the delivery teams hence will be a core member of the DI function.
  • This role supports the capability responsibilities of the Head of Product Security Capability and other LoB HoPS in maintaining a centre of expertise for Product Security and Cyber Resilience matters through a core functional discipline.
  • You’ll be working closely with supportive, talented and innovative engineers across the engineering delivery disciplines, contributing to continual improvement of the engineering capability of RATS, whilst also building strong relationships with our customers, partners and the specialist agencies within the UK and globally.
  • What you will do

    Day to day, you will be working closely with the CE DI, the PCRMs, PSMSs, Product Safety Engineers, Independent Technical Assessors and other Engineering disciplines to identify and satisfy the contractual and regulatory cyber resilience requirements of systems. You will also select, plan and support the assurance activities necessary for airborne systems, including Mission Critical and Flight Safety involved systems, often with demanding safety and security requirements themselves.

    • You will:
    • Create and maintain processes, templates and guidance, which forms the Product Security Management System, in collaboration with other LoB HoPS and the Head of Product Security Capability.
    • Select, measure, collect and analyse metrics relating to the Product Security Management System to improve compliance, effectiveness and efficiency through KPIs.
    • Propose Product Security competence framework development, maintenance, monitoring and evolution to meet RATS needs in collaboration with other LoB HoPS and the Head of Product Security Capability.
    • Perform assessment of PCRM or Product Security Management Specialist (PSMS) competence in line with the Product Security competency framework.
    • Identify and select training or trade related conferences to ensure the maintenance of competency and the sufficiency of experience across the PCRMs and PSMSs to meet the evolving RATS needs.
    • Chair and administration of a RATS security Community of Interest (CoI).
    • Deliver awareness and training of the security framework, policies and processes to the Engineering disciplines.
    • The production and reporting of RATS Product Security metrics as requested and directed by the Head of Product Security Capability.
    • Management of attendance of RATS personnel at external security forums of interest and Business relevance.
    • Attend and support the Product Security Special Interest Groups (SIG) and sub-groups covering Governance and Technical topics.
    • Allocate competent persons, such as a PSMS, to perform the duties of a Design Review Assessor as requested by a Design Review Chairperson to support Design Maturity Reviews.
    • Allocate competent persons to perform the duties of the PSMS to support and advise the CE DI in the certification of designs.
    • The identification of future resourcing demands to meet RATS business execution and the necessary provision of those resources through recruitment or sub-contracting.
    • Oversee the assessment of general Security events/incidents for any Product Security concerns and ensure the thorough identification, containment, eradication and recovery from any Product Security event/incident and lead any post event/activity from lessons learnt.

    What you’ll bring

    In broad terms, you shall have as many of the following as possible:

    • Evidence of comprehensive practical experience in the development of a security or safety risk management system for complex products based on a recognised framework in a highly regulated industry such as aerospace, nuclear, automotive, rail or oil & gas.
    • Demonstratable experience of the System Development Life Cycle, Software Development Life Cycle, V-Models and Agile frameworks.
    • Effective and flexible communication and interpersonal skills.
    • Demonstratable ability to interact with subject matter experts on a wide range of technical and operational topics.
    • Excellent written and verbal communication skills, with the ability to coach and develop others.
    • Ability to obtain SC security clearance and work within UKEO and US ITAR TAA restrictions.
    • The ability to understand complex engineering processes and the inter-dependency of the process components.
    • A passion for promoting and improving the safety and security of complex systems.

    You should have one or more of:

    • Evidence of comprehensive practical experience in ISO27001/27004/27005 or the NIST Risk Management Framework (RMF) and NIST SP800-30/SP800-53.
    • Knowledge of UK/NATO Information Assurance/Accreditation frameworks.
    • Demonstratable familiarity with the application of cyber resilience controls to embedded systems.

    It would be desirable, but not essential, if you also had one or more of:

    • Knowledge of EASA/FAA Airworthiness Certification frameworks.
    • Awareness of current crypto technologies, Key Management Systems & practical COMSEC.
    • Chartered Engineer status with a recognised body, preferably the UK Cyber Security Council.
    • Awareness of Information Security (INFOSEC), Communications Security (COMSEC), Transmission Security (TRANSEC), Product Safety and their inter-relationship.
    • Experience of producing and delivering training/awareness material within a corporate environment.
    • Familiarity with incident investigation and implementation of an investigation process such as used by the Air Accidents Investigation Branch (AAIB).
    • Familiarity with assessing the consequences of emergent security vulnerabilities.
    • Familiarity of planning and executing assurance activities required to provide the necessary assurances to security authorities and agencies.
    • Familiarity with the planning and conduct of penetration testing and/or vulnerability assessments.
    • Familiarity with planning, costing, financial forecasting and risk/opportunity management activities associated with project planning and execution.

    Security Clearance

    This role is subject to pre-employment screening in line with the UK Government’s Baseline Personnel Security Standard (BPSS). An additional range of Personnel Security Controls referred to as National Security Vetting (NSV) may apply, this could include meeting the eligibility requirements for The Security Check (SC) or Developed Vetting (DV).

    Why join us

    At Leonardo, our people are at the heart of everything we do. We offer a comprehensive, company-funded benefits package that supports your wellbeing, career development, and work–life balance. Whether you're looking to grow professionally, care for your health, or plan for the future, we’re here to help you thrive.

    Head of Product Security (RATS) in Edinburgh employer: Leonardo

    Leonardo is an exceptional employer, offering a dynamic work environment where innovation meets security in the aerospace sector. With a strong focus on employee development and a comprehensive benefits package, we empower our team to thrive while working on cutting-edge technologies that shape the future of airborne systems. Our collaborative culture fosters continuous improvement and provides opportunities to engage with major global programmes, ensuring that every employee can make a meaningful impact.
    L

    Contact Detail:

    Leonardo Recruiting Team

    StudySmarter Expert Advice 🤫

    We think this is how you could land Head of Product Security (RATS) in Edinburgh

    ✨Network Like a Pro

    Get out there and connect with people in the industry! Attend events, join online forums, and don’t be shy about reaching out to professionals on LinkedIn. Building relationships can open doors that a CV just can’t.

    ✨Ace the Interview

    Prepare for your interviews by researching the company and the role inside out. Practice common interview questions and think about how your experience aligns with what they’re looking for. Confidence is key, so show them you’re the right fit!

    ✨Showcase Your Skills

    Don’t just talk about your skills—show them! Bring examples of your work or projects to interviews. If you’ve got relevant certifications or training, flaunt them! This is your chance to shine and prove you’re the best candidate.

    ✨Apply Through Our Website

    When you find a role that excites you, apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining our team at Leonardo.

    We think you need these skills to ace Head of Product Security (RATS) in Edinburgh

    UK MOD Secure-by-Design
    ISO27001
    ISO27004
    ISO27005
    NIST Risk Management Framework (RMF)
    NIST SP800-30
    NIST SP800-53
    UK/NATO Information Assurance/Accreditation frameworks
    Cyber resilience controls
    System Development Life Cycle
    Software Development Life Cycle
    V-Models
    Agile frameworks
    Effective communication skills
    Interpersonal skills

    Some tips for your application 🫡

    Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience with security frameworks like ISO27001 or NIST. We want to see how your skills align with the specific needs of the Head of Product Security role.

    Showcase Your Experience: Don’t just list your previous roles; explain how your past experiences relate to the responsibilities outlined in the job description. We love seeing concrete examples of how you've managed product security processes or improved compliance.

    Be Clear and Concise: When writing your application, keep it straightforward and to the point. Use clear language to convey your ideas, as we appreciate strong communication skills. Remember, clarity is key!

    Apply Through Our Website: We encourage you to submit your application through our website for a smoother process. It helps us keep track of your application and ensures you don’t miss any important updates from us!

    How to prepare for a job interview at Leonardo

    ✨Know Your Frameworks

    Make sure you brush up on the UK MOD Secure-by-Design, ISO27001/27004/27005, and NIST Risk Management Framework. Be ready to discuss how you've applied these frameworks in your previous roles, as this will show your practical experience and understanding of the security landscape.

    ✨Showcase Your Communication Skills

    As a Head of Product Security, you'll need to interact with various stakeholders. Prepare examples that demonstrate your effective communication and interpersonal skills. Think about times when you had to explain complex technical concepts to non-technical audiences or coach team members.

    ✨Demonstrate Continuous Improvement Mindset

    Leonardo values continuous improvement in cyber resilience. Be prepared to discuss how you've contributed to enhancing security processes or systems in your past roles. Highlight any initiatives you've led or participated in that resulted in measurable improvements.

    ✨Prepare for Scenario-Based Questions

    Expect scenario-based questions that assess your problem-solving abilities in real-world situations. Think about potential security incidents you might face in this role and how you would manage them. This will help you showcase your strategic thinking and ability to handle pressure.

    Head of Product Security (RATS) in Edinburgh
    Leonardo
    Location: Edinburgh
    Go Premium

    Land your dream job quicker with Premium

    You’re marked as a top applicant with our partner companies
    Individual CV and cover letter feedback including tailoring to specific job roles
    Be among the first applications for new jobs with our AI application
    1:1 support and career advice from our career coaches
    Go Premium

    Money-back if you don't land a job in 6-months

    L
    • Head of Product Security (RATS) in Edinburgh

      Edinburgh
      Full-Time
      48000 - 72000 £ / year (est.)
    • L

      Leonardo

      1000-5000
    Similar positions in other companies
    UK’s top job board for Gen Z
    discover-jobs-cta
    Discover now
    >