Senior Cybersecurity Consultant (Secure by Design Lead)
HybridBristol, England, United Kingdom
Job Summary
Own and maintain the Security Management Plan covering OT, IT, and physical security, including the assurance and acceptance strategy in accordance with UK MOD requirements. Act as the senior security authority within the client's integrated design team, directing the work of the security architect and cybersecurity consultant while developing threat assessments and managing design risk exposure through a live risk register. Produce preliminary security requirements and standards for OT, IT, and physical security, ensuring traceability from threat to control and embedding supplier security requirements into delivery expectations. Provide security input to formal engineering design reviews, manage stakeholder meetings, and represent the security position to senior client and independent technical governance bodies. Apply MOD, NCSC, and defence security frameworks to support assurance, accreditation, and compliance activities, reconciling the security position with the platform safety case for an autonomous surface vessel programme.
Required Qualifications
- Relevant education or industry-recognised certifications in cybersecurity, information assurance, secure engineering, security architecture, risk management or a related discipline
- Suitable qualifications may include BSc, MSc, CISSP, CISM, CRISC, CISA, CCP, ISO 27001 Lead Implementer/Lead Auditor, Security+, CySA+, SABSA, TOGAF, IEC 62443, NCSC CAF-related experience or equivalent professional experience
- Demonstrable ownership of a Security Management Plan, product security management plan, security case or equivalent controlling assurance artefact
- Strong understanding of secure-by-design principles and their application across complex engineering lifecycles
- Ability to lead security input into formal engineering design reviews and technical governance forums
- Ability to translate security risks and regulatory expectations into practical engineering, architecture and delivery actions
- Strong stakeholder management skills, including the ability to influence senior technical and programme stakeholders
- Strong written and verbal communication skills, with the ability to produce concise technical assurance material, risk statements, executive briefings and decision papers
- Ability to work independently and provide senior technical direction without day-to-day supervision, and to direct the work of other consultants
- Awareness of maritime cyber assurance benchmarks such as IACS Unified Requirements E26 and E27, and of the Defence Maritime Regulator's assurance framework
- Proven experience in a senior cybersecurity, product security, information assurance, or secure engineering role
- Experience supporting major defence, maritime, naval, shipbuilding, CNI or complex engineering programmes
- Experience defining or maintaining a Security Management Plan, Product Security Management Plan, Security Case, accreditation pack or equivalent assurance artefact
- Experience embedding cybersecurity across the full engineering lifecycle, from requirements and design through to build, integration, validation and acceptance
- Experience leading security input into design reviews, technical governance forums and assurance gates
- Experience developing and maintaining security risk registers, treatment plans, control evidence and assurance records
- Experience supporting MOD, NCSC, defence or maritime compliance activity
- Experience defining supplier security requirements and assessing third-party security evidence
- Experience operating within Integrated Project Teams or multi-disciplinary engineering delivery environments
- Experience handling sensitive defence information in line with UK MOD, NCSC, client security and data protection requirements
- Practical experience applying MOD Secure by Design, NCSC, defence security, information assurance or risk management frameworks
- Experience conducting threat modelling, security risk assessment and security requirements definition, using recognised methods such as STRIDE, MITRE ATT&CK for Industrial Control Systems, NIST SP 800-30 or ISO/IEC 27005
- Experience securing complex IT and OT systems, including platform systems, industrial control systems, networks, communications and support environments
- Experience supporting security accreditation, assurance, compliance or certification activities in a UK defence or similarly regulated environment
- Cybersecurity experience within defence, maritime, shipbuilding, critical national infrastructure, or operationally critical environments
- Strong supplier and third-party oversight experience, including security requirements definition, deliverable review, dependency management and acceptance criteria
- Experience with MOD security policy, defence standards, JSPs, Secure by Design, NCSC guidance or equivalent assurance frameworks
- Experience with autonomous, uncrewed or remotely operated platforms, and the safety and availability considerations these create
- Experience with IEC 62443, NIST CSF, ISO 27001, NCSC CAF, Def Stan 05-138 or DEFCON security conditions
- TEMPEST awareness or experience, particularly as it relates to defence standards, secure design and NCSC guidance
- Experience contributing to executive-level security reporting, assurance dashboards, risk briefings or programme decision packs
- Experience scoping IT health checks, penetration testing or technical assurance activity as follow-on work
- Strong experience operating in a senior product security, cyber assurance, information assurance, secure engineering or security architecture role
- Have the right to work in the UK
- Hold, or be eligible to obtain, UK Security Check (SC) clearance
- Be willing and able to work in a hybrid model, including client site attendance as required
- Be comfortable working within secure collaboration environments and handling information marked up to OFFICIAL-SENSITIVE
- Be able to work under the terms of applicable confidentiality and non-disclosure arrangements
Desired Qualifications
- Experience working within UK MOD, defence, maritime, shipbuilding, naval, critical national infrastructure or operationally critical environments would be highly beneficial
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.