At a Glance
- Tasks: Lead security aspects of product design and development for defence and government projects.
- Company: Join a top-tier defence and security company making a real impact in national safety.
- Benefits: Enjoy competitive pay, professional development opportunities, and a diverse workplace culture.
- Why this job: Be at the forefront of security innovation while working with cutting-edge technologies.
- Qualifications: Experience in military or commercial security solutions; relevant degree and certifications required.
- Other info: Must be able to obtain SC clearance; commitment to equality and diversity is paramount.
The predicted salary is between 48000 - 84000 £ per year.
Our client, a leading defence and security company, is seeking to recruit experienced security engineers with expertise in developing and maintaining product security management systems for defence and government customers.
About the Role
This position will report to the Head of Engineering Projects and will take responsibility for all security aspects of product design, development, verification and maintenance through all phases of the product lifecycle. The role will focus on undertaking security risk assessments for products, preparing security risk mitigation plans, deriving security requirements and working with product development teams to design, implement and maintain appropriate security controls and production of Product Security Artefacts.
Responsibilities
- The successful candidate will report to the Head of Engineering Products and be responsible for providing security advice to product development teams in a range of areas including:
- Production of Security Management Plans, work package descriptions and cost estimates in support of product bids, services and proposals.
- Undertaking security risk assessments, risk mitigation plans, mitigation gap analysis and preparation of security management documentation for system Accreditation.
- Defining product security requirements, advising development teams on suitable implementation standards and techniques and overseeing product development activities.
- Liaison with Security Accreditors and Security Assurance Coordinators in support of security accreditation.
- Preparation of Protection Profiles, Security Targets and Evaluation Management Plans, and liaison with NCSC and commercial evaluation teams in support of evaluation activities.
- Preparation of TEMPEST Control Plans, advising development teams on appropriate implementation techniques and liaising with TEMPEST test facilities.
- Advising development teams on suitable platform lockdown and configurations, and supporting Penetration test activities.
- Analysing penetration test results and preparation of remedial action plans.
- Prepare and implement through life support and maintenance for product security including vulnerability and patch management plans.
- Lead security incident management teams during incident/crisis situations in conjunction with Head of Product Security for EW/FCA.
- Review and maintain corporate product security policies.
- Deliver product security training to project engineering teams.
Qualifications
- Experience in the development of security solutions for military and/or commercial products and systems.
- Graduate degree in relevant engineering, computing or related scientific discipline, and/or evidence of further professional study.
- Registered NCSC certified professional at senior level or above, or NCSC recognised qualification, e.g. ISC2 Certified Information System Security Professional.
- Knowledge of UK/NATO Information Assurance standards, procedures & systems, including Government Functional Standard GovS 007: Security, HMG IS1&2, ISO27000 series standards, NIST SP800 series standards, JSP440, JSP604, guidance material provided by NCSC, CPNI and NIST.
- Practical experience of producing Security Accreditation documentation.
- Practical experience of NCSC and Common Criteria security evaluation techniques.
- Knowledge of current crypto technologies and key management systems.
- Model Base System Engineering (MBSE) knowledge.
- Understanding operating systems, firmware and software security controls and how to apply them.
- Understanding of existing, current and emerging technologies including cloud, virtualisation and web.
- Excellent verbal and written communication skills.
- Good team worker with ability to influence and motivate.
- Positive attitude and drive to improve the business.
- Ability to obtain SC clearance with UK-eyes only caveat.
- Enterprise Security Architectures (SABSA, MODAF).
Synergize Consulting is committed to equality and diversity in our workplace. Synergize Consulting provides equal employment opportunity to all employees and applicants without regard to an individual's protected status, including race/ethnic origin, colour, nationality, national origin, ancestry, sex/gender, gender identity/expression, gender reassignment, sexual orientation, marriage/civil partnership, pregnancy/maternity, religion or belief, age, disability, or any other protected status or characteristic.
Contact Detail:
Synergize Consulting Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Lead Security Engineer
✨Tip Number 1
Network with professionals in the defence and security sector. Attend industry conferences, webinars, or local meetups to connect with individuals who work in similar roles. This can help you gain insights into the company culture and potentially get a referral.
✨Tip Number 2
Stay updated on the latest security technologies and standards relevant to the role. Familiarise yourself with UK/NATO Information Assurance standards and current crypto technologies, as this knowledge will be crucial during interviews and discussions with potential employers.
✨Tip Number 3
Prepare to discuss your experience with security risk assessments and mitigation plans. Be ready to provide examples of how you've successfully implemented security controls in past projects, as this will demonstrate your practical expertise to the hiring team.
✨Tip Number 4
Showcase your ability to work collaboratively with product development teams. Highlight any previous experiences where you provided security advice or training, as this will illustrate your capability to influence and motivate others in a team setting.
We think you need these skills to ace Lead Security Engineer
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in security engineering, particularly in developing and maintaining product security management systems. Use specific examples that align with the responsibilities outlined in the job description.
Craft a Strong Cover Letter: Write a cover letter that addresses the key qualifications mentioned in the job description. Emphasise your experience with security risk assessments, security management documentation, and your ability to work with development teams.
Highlight Relevant Qualifications: Clearly list any relevant certifications, such as NCSC certified professional status or ISC2 Certified Information System Security Professional. Mention your knowledge of UK/NATO Information Assurance standards and any practical experience you have in producing Security Accreditation documentation.
Showcase Communication Skills: Since excellent verbal and written communication skills are essential for this role, consider including examples of how you've effectively communicated complex security concepts to non-technical stakeholders or led training sessions.
How to prepare for a job interview at Synergize Consulting
✨Showcase Your Technical Expertise
Be prepared to discuss your experience with security solutions, particularly in military or commercial contexts. Highlight specific projects where you developed or maintained product security management systems, and be ready to explain the methodologies you used.
✨Understand the Regulatory Landscape
Familiarise yourself with UK/NATO Information Assurance standards and other relevant regulations. During the interview, demonstrate your knowledge of these standards and how they apply to the role, especially in relation to security accreditation documentation.
✨Prepare for Scenario-Based Questions
Expect questions that assess your problem-solving skills in real-world scenarios. Think about past experiences where you conducted risk assessments or managed security incidents, and be ready to articulate your thought process and the outcomes.
✨Communicate Clearly and Confidently
Since excellent verbal and written communication skills are crucial for this role, practice articulating your thoughts clearly. Be concise but thorough when discussing your qualifications and experiences, ensuring you convey your enthusiasm for the position.