At a Glance
- Tasks: Design and enforce security controls in mission-critical environments to protect against cyber threats.
- Company: Join Ocean Infinity, a tech-driven company transforming operations at sea with innovation.
- Benefits: Competitive salary, inclusive culture, and opportunities for personal and professional growth.
- Other info: Dynamic team environment focused on collaboration and continuous improvement.
- Why this job: Make a real impact in cyber security while working with cutting-edge technology.
- Qualifications: Experience in cyber security engineering and governance within regulated environments.
The predicted salary is between 36000 - 60000 £ per year.
We are using and creating technology to transform operations at sea to enable people and the planet to thrive. We are open-minded and fearless in our approach to innovation and don’t believe in boundaries. We challenge everything and have massive ambitions to drag aging industries into the tech era. We take safety, equality and education very seriously, and our responsibilities don’t stop at our front door. Our business is built on the belief that there’s definitely a more environmentally responsible way to operate at sea. We employ people who share our core values. We expect our people to be courageous, trustworthy, and conscientious, driven by a desire to do the right thing. We strive for excellence, work collaboratively, and are genuinely excited by our work. We offer opportunities for our people to develop beyond their role and span a multitude of disciplines. These are open to all, regardless of background and experience level. Working with us means being part of a team that is harnessing technology and creativity to disrupt a traditional industry.
Ocean Infinity is seeking a Cyber Security Engineer with a defence and governance focus to design, enforce, and assure security controls across highly regulated and mission‑critical environments. This role sits at the intersection of security engineering, governance, and operational assurance, ensuring that cyber security controls are not only compliant on paper, but defensible in practice against capable and persistent adversaries. You will support audit, regulatory assurance, defence procurement, and supply chain security activities while acting as a technical authority for risk‑based security decisions across enterprise IT, cloud, and operational technology environments.
What Will You Do
- Defence, Audit and Regulatory Assurance
- Act as a primary cyber security interface for auditors, regulators, defence stakeholders, and customers.
- Maintain and evidence compliance against relevant frameworks such as ISO27001, NIST CSF, NIST SP 800-53, CMMC, DFARS, NIS Regulations, and applicable MOD or defence standards.
- Support compliance with Cyber Essentials and Cyber Essentials Plus where required.
- Coordinate internal and external audits, penetration test remediation, and formal assurance activities.
- Maintain authoritative compliance artefacts including Statements of Applicability, control mappings, risk registers, and remediation plans.
- Translate regulatory and contractual obligations into engineering‑ready security requirements.
- Risk Management and Governance
- Identify, assess, and track cyber security risks across enterprise, cloud, and OT environments.
- Conduct structured risk assessments aligned with ISO27005 or NIST risk management principles.
- Define and maintain security policies, standards, and baselines aligned to defence‑grade threat models.
- Support executive and programme‑level reporting on residual risk, exposure, and operational impact.
- Defence Procurement and Supply Chain Security
- Provide cyber security input to defence, public sector, and critical infrastructure tenders.
- Support secure‑by‑design requirements in procurement, contracts, and supplier onboarding.
- Conduct third‑party and supply chain security assessments covering control assurance, data handling, access, connectivity, and segmentation risks.
- Ensure supplier security controls align with contractual and regulatory obligations.
- Security Engineering and Operational Assurance
- Work with Cyber Security Engineers, Architects, and IT and OT teams to ensure controls are implemented correctly, operating as intended, and continuously monitored.
- Validate logging, monitoring, and incident response capabilities against regulatory and contractual requirements.
- Identify and drive remediation of control weaknesses, security debt, and non‑compliance.
- Support incident response activities, including post‑incident assurance, reporting, and regulatory engagement.
- Awareness and Executive Communication
- Support development and delivery of cyber security awareness training and workshops.
- Assist with phishing simulations and tabletop exercises.
- Prepare concise, decision‑ready briefings for senior leadership on threat posture, compliance status, and risk exposure.
Who You Are
You are a technically credible cyber security professional with strong governance instincts and the confidence to operate in defence‑adjacent environments. You understand that compliance is a baseline, not the objective, and you focus on controls that withstand real‑world adversarial pressure. You are comfortable engaging with engineers, auditors, regulators, and senior stakeholders alike.
Qualifications And Skills
- Strong experience in cyber security engineering, governance, risk, or assurance roles within regulated or defence‑aligned environments.
- Practical experience implementing and assuring controls aligned to ISO27001, NIST, CMMC, DFARS, NIS Regulations, or equivalent frameworks.
- Experience conducting structured cyber risk assessments and maintaining risk registers.
- Familiarity with IT, cloud, and operational technology security environments.
- Ability to translate regulatory requirements into actionable engineering controls.
- Experience supporting audits, penetration testing remediation, and regulatory reporting.
- Strong written and verbal communication skills with the ability to brief senior leadership.
- Comfortable operating in complex, multi‑stakeholder environments.
Security Clearance
Security clearance is not mandatory on appointment; however, candidates must be eligible and willing to undergo UK security vetting should the role or programme require it.
Salary
The salary varies for this position as we are recruiting in multiple regional locations and job grades. The salary process is based on skills, abilities, and experience required.
What You Can Expect
At Ocean Infinity, we believe in creating equal opportunities for all, celebrating each and everyone’s differences. We are driven by transforming the industry, through our technology, thoughts, behaviours and actions. Being inclusive and respectful to all is fundamental to who we are. It is the right thing to do and enables innovation and creativity to thrive. There is more work to be done, and we know that we aren’t perfect, but our commitment to these values is unwavering. They are central to our mission and the impact we have on the industry, meaning, we cannot live without them.
Cyber Security Engineer in Southampton employer: Ocean Infinity
At Ocean Infinity, we pride ourselves on being an innovative employer that champions safety, equality, and environmental responsibility. Our collaborative work culture fosters personal and professional growth, offering diverse opportunities for employees to develop their skills in a dynamic and supportive environment. Join us in transforming the maritime industry through cutting-edge technology while being part of a team that values courage, trust, and conscientiousness.
StudySmarter Expert Advice🤫
We think this is how you could land Cyber Security Engineer in Southampton
✨Tip Number 1
Network like a pro! Get out there and connect with people in the cyber security field. Attend industry events, join online forums, and don’t be shy about reaching out on LinkedIn. You never know who might have the inside scoop on job openings!
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially those related to cyber security. This gives potential employers a tangible look at what you can do and sets you apart from the crowd.
✨Tip Number 3
Prepare for interviews by brushing up on your knowledge of compliance frameworks like ISO27001 and NIST. Be ready to discuss how you've applied these in real-world scenarios. Confidence in your expertise can really impress hiring managers!
✨Tip Number 4
Don’t forget to apply through our website! We’re always looking for passionate individuals who align with our values. Tailor your application to highlight how your skills and experiences match the role of Cyber Security Engineer at Ocean Infinity.
We think you need these skills to ace Cyber Security Engineer in Southampton
Some tips for your application 🫡
Show Your Passion for Cyber Security:When writing your application, let your enthusiasm for cyber security shine through! We want to see how your experiences and interests align with our mission to innovate and transform operations at sea.
Tailor Your Application:Make sure to customise your CV and cover letter to highlight relevant skills and experiences that match the job description. We love seeing candidates who take the time to connect their background with what we do at Ocean Infinity.
Be Clear and Concise:Keep your application straightforward and to the point. Use clear language to describe your achievements and how they relate to the role. We appreciate candidates who can communicate effectively, especially in a technical field like cyber security.
Apply Through Our Website:Don’t forget to submit your application through our website! It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it shows you’re serious about joining our team!
How to prepare for a job interview at Ocean Infinity
✨Know Your Frameworks
Familiarise yourself with the key compliance frameworks mentioned in the job description, like ISO27001 and NIST. Be ready to discuss how you've applied these in past roles, as this will show your technical credibility and understanding of governance.
✨Showcase Your Risk Management Skills
Prepare examples of how you've conducted structured risk assessments and maintained risk registers. Highlight specific instances where your actions led to improved security posture or compliance, as this aligns perfectly with the role's focus on risk management.
✨Communicate Clearly
Practice articulating complex cyber security concepts in simple terms. You’ll need to engage with various stakeholders, so being able to prepare concise, decision-ready briefings for senior leadership is crucial. Think about how you can convey your ideas effectively.
✨Demonstrate Your Collaborative Spirit
This role involves working closely with engineers, auditors, and other teams. Be prepared to discuss how you've successfully collaborated in multi-stakeholder environments. Share examples that highlight your ability to work towards common goals while ensuring security controls are implemented correctly.