Overview
As a Principal Product Security Engineer, you guide information assurance, cyber and physical security across the Secure by Design lifecycle. You’ll influence security requirements from concept to in-service support, working with SDA, product teams and assessors to embed security into designs. You lead threat modelling, risk assessments and vulnerability analyses to pre-empt cyber threats and ensure compliance with standards. This role drives secure product delivery and robust security documentation for acceptance and operation.
Pay / Benefits
- Rewards tailored to you and your family
- Support for financial and personal wellbeing
- Balanced lifestyle
- Hybrid/flexible working options
- Opportunities for career development
Responsibilities
- Incorporate security considerations and controls in designs prior to production
- Represent projects at Security Working Groups and report on Secure by Design and risk profiles
- Undertake functional design qualification and evidence for acceptance and compliance
- Support design reviews by evidencing security maturity and design robustness
Key requirements
- CISSP or CISM or equivalent certification
- Deep knowledge of security standards/frameworks (NIST, ISO 27000, Defence Standards)
- Knowledge of security analysis techniques (threat modelling, risk assessment, encryption, penetration testing)
- Extensive practical security expertise in a product development environment
- Knowledge of security tools and processes supporting Product Security Assurance and Security Cases
- Threat modelling
- Risk assessment
- Security controls design and implementation
- Security evidence and assurance documentation
- SbD Principles and Security Cases (including Security Management Plans, Security Impact Assessments)
- MoD Processes and procedures
…
