Principal Product Security Engineer in Bristol

Principal Product Security Engineer in Bristol

Bristol Full-Time 60000 - 80000 € / year (est.) No home office possible
N

At a Glance

  • Tasks: Lead security strategy for advanced naval ships and ensure cyber safety.
  • Company: Join Navantia UK, a pioneer in defence and maritime innovation.
  • Benefits: Enjoy competitive pay, 33 days holiday, and a company pension.
  • Other info: Inclusive workplace committed to equal opportunity and career growth.
  • Why this job: Make a real impact on national security while working with cutting-edge technology.
  • Qualifications: Experience in cyber security and knowledge of secure systems engineering required.

The predicted salary is between 60000 - 80000 € per year.

Navantia UK is a new force in British industry, supporting the UK’s defence, security and energy transition ambitions. We’re doing this by creating state-of-the-art sovereign defence capabilities, investing in the UK to modernise industrial facilities, and bolstering the nation’s energy security. Established in 2022, Navantia UK is a subsidiary of Navantia SA, a Spanish state-owned company with over 300 years of naval shipbuilding history. In January 2025, Navantia UK completed the acquisition of Harland & Wolff and its four historic facilities in Belfast, Appledore, Methil, and Arnish. By combining Harland & Wolff’s proud heritage and facilities with Navantia’s global expertise, Navantia UK is well-positioned to strengthen Britain’s defence, maritime and energy industrial capabilities, supporting jobs and economic growth across the UK.

Navantia UK is a leading provider of innovative naval solutions, specialising in the design, construction, and lifecycle support of naval ships. As part of the global Navantia Group, we are committed to delivering cutting-edge technologies and world-class services across the maritime sector. Based in Bristol, we are seeking a passionate Principal Product Security Engineer to join our team and play a pivotal role in the security of our designs and related current and emerging technology solutions on advanced next generation naval and government ships. This role is offered on a full-time basis, but we also welcome applications from candidates with the right skills who are interested in part-time working.

The Principal Product Security Engineer is responsible for defining, implementing, and assuring the security strategy for defence shipping and Fleet Solid Support Programme. This role ensures that cyber security, information assurance, and secure-by-design principles are embedded across both the platform (ship) design and the IT/OT architecture throughout the full engineering lifecycle. The role operates at the intersection of naval architecture, marine systems engineering, combat/logistics support systems, and enterprise IT/operational technology (OT), ensuring compliance with MOD security policies and relevant maritime cyber regulations.

Duties

  • Security Leadership & Strategy
    • Develop and maintain the Product Security Management Plan (PSMP) for the vessel programme, covering all aspects of security.
    • Define the security architecture strategy for both ship systems (OT) and IT networks.
    • Act as the security authority within the Integrated Project Team (IPT).
  • Secure Ship Design Integration
    • Ensure security requirements are embedded into programmable elements and systems including but not limited to:
      • Platform management systems
      • Navigation systems
      • Propulsion and machinery control systems
      • Communications systems (internal & external)
      • Mission/logistics systems (if applicable)
    • Conduct threat modelling and risk assessments for marine and hybrid IT/OT environments.
    • Define physical security requirements and access controls.
    • Support management of TEMPEST where required.
    • Support design reviews (SRR, PDR, CDR) with formal security assurance inputs.
    • Ensure compliance with relevant standards (e.g., Def Stan, NCSC guidance, IEC 62443, NIST, IMO cyber guidance).
    • Define secure network zoning and segregation between:
      • Operational Technology (OT)
      • Information Technology (IT)
      • Communications systems
    • Approve system boundary definitions and trust zones.
    • Ensure secure configuration baselines for onboard systems.
    • Oversee secure integration of third-party vendors and subcontractors.
    • Define Identity and Access Management (IAM) and privileged access strategies for afloat systems.
  • Risk, Assurance & Compliance
    • Lead security risk management in alignment with MOD/NCSC frameworks.
    • Manage security risk registers and treatment plans.
    • Coordinate accreditation and authority-to-operate activities.
    • Support JSP 440 / JSP 604 compliance activities.
    • Provide evidence for security case development and formal assurance reviews.
  • Supply Chain & Third-Party Security
    • Define security requirements within supplier contracts.
    • Conduct supplier security assessments.
    • Ensure secure development practices across the supply chain.
    • Validate SBOMs (Software Bill of Materials) where required.
  • Testing & Validation
    • Define security test strategies including:
      • Vulnerability assessments
      • Penetration testing
      • Factory Acceptance Testing (FAT) security scope
      • Harbour and Sea Trial cyber validation
    • Oversee remediation of identified vulnerabilities.
    • Ensure secure configuration prior to vessel acceptance.
  • Incident Preparedness & Operational Security
    • Define onboard cyber incident response requirements.
    • Ensure monitoring and logging architecture supports detection and forensic investigation.
    • Contribute to lifecycle security planning, including in-service support.

Qualifications

  • Significant experience in cyber security within defence, maritime, or critical infrastructure environments.
  • Experience in both the application of security accreditation and Secure by Design in a UK MOD environment.
  • Experience securing complex IT/OT systems.
  • Strong understanding of secure systems engineering principles.
  • Experience working within MOD or defence regulatory frameworks.
  • Demonstrated experience leading security through engineering design reviews.
  • Knowledge of maritime systems and shipboard integration challenges.
  • Strong understanding of network architectures, design and operation.
  • Experience in the application of TEMPEST measures to design including use of Def-Stan 08-050 and 59-411, NCSC GPG14 and SDIP-29.
  • Knowledge of maritime facility requirements for handling of high and extremely high classified data, e.g. STRAP, in line with UK MOD and NCSC requirements.

Additional Information On Offer

  • Competitive base pay
  • Company pension
  • 33 days holiday
  • Life assurance
  • Cycle to work scheme (optional)

We are an Opening Doors employer, committed to equal opportunity and an inclusive workplace. Our approach, shaped by our values of service, trust, excellence, agility, dedication, and you, we focus on removing barriers and recognising potential. We are committed to fairness at every stage, including providing reasonable adjustments and actively working to eliminate discrimination. We believe talent is everywhere, and by widening access to opportunity and welcoming diverse experiences, we aim to create a workplace where every person feels valued and has an equal chance.

If you experience difficulties or are unable to apply for a role online please contact us at people.skills@harland-wolff.com and one of the team will be in contact to help you.

Principal Product Security Engineer in Bristol employer: Navantia Group

Navantia UK is an exceptional employer, offering a dynamic work environment in Bristol where innovation meets tradition. With a strong commitment to employee growth and inclusivity, we provide competitive benefits such as 33 days of holiday, a company pension, and opportunities for professional development in the cutting-edge field of naval security. Join us to be part of a team that values service, trust, and excellence while contributing to the UK's defence and energy ambitions.

N

Contact Detail:

Navantia Group Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land Principal Product Security Engineer in Bristol

Tip Number 1

Network like a pro! Get out there and connect with folks in the industry. Attend events, join online forums, and don’t be shy about reaching out on LinkedIn. You never know who might have the inside scoop on job openings!

Tip Number 2

Prepare for interviews by researching the company and its projects. Understand their values and how your skills align with their mission. This will help you stand out and show that you're genuinely interested in being part of their team.

Tip Number 3

Practice makes perfect! Do mock interviews with friends or use online resources to get comfortable with common questions. The more you practice, the more confident you'll feel when it’s time to shine in front of the real interviewers.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who are proactive and take the initiative to reach out directly.

We think you need these skills to ace Principal Product Security Engineer in Bristol

Cyber Security
Information Assurance
Secure-by-Design Principles
Risk Management
Threat Modelling
Security Architecture Strategy
Compliance with MOD Security Policies

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Principal Product Security Engineer role. Highlight your relevant experience in cyber security, especially within defence or maritime environments. We want to see how your skills align with our needs!

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about this role and how your background makes you a perfect fit. Don’t forget to mention your understanding of secure systems engineering principles.

Showcase Your Achievements:When detailing your experience, focus on specific achievements that demonstrate your expertise in security risk management and compliance. We love seeing quantifiable results that show how you've made an impact in previous roles.

Apply Through Our Website:We encourage you to apply directly through our website for the best chance of getting noticed. It’s the easiest way for us to keep track of your application and ensure it reaches the right people!

How to prepare for a job interview at Navantia Group

Know Your Stuff

Make sure you brush up on your knowledge of cyber security principles, especially in the context of defence and maritime environments. Familiarise yourself with relevant standards like Def Stan and NIST, as well as the specific technologies mentioned in the job description.

Showcase Your Experience

Prepare to discuss your past experiences in securing complex IT/OT systems and leading security through engineering design reviews. Use specific examples that highlight your problem-solving skills and how you've successfully implemented security strategies in previous roles.

Understand the Company’s Mission

Research Navantia UK and its role in the defence and maritime sectors. Be ready to explain how your skills align with their mission of delivering innovative naval solutions and how you can contribute to their goals, particularly in enhancing security measures.

Ask Insightful Questions

Prepare thoughtful questions about the role, team dynamics, and the company's approach to security challenges. This shows your genuine interest in the position and helps you gauge if the company culture aligns with your values.