Overview
In this role you will lead Secure by Design across classified IT systems, ensuring security is integrated throughout the lifecycle and aligned with UK Government, MoD, and Lockheed Martin requirements. You will partner with programme teams, architects, accreditors, and information assurance stakeholders to drive secure design, risk management, and accreditation activities. You will perform threat modelling, risk assessments, and support ATO processes, audits, and incident response. This position offers a meaningful opportunity to shape security in regulated, high-stakes environments.
Responsibilities
- Lead Secure by Design implementations across classified systems and projects
- Provide security engineering guidance throughout concept to disposal
- Perform security architecture reviews, threat assessments, and risk analyses
- Develop and maintain system security documentation, architectures, and operating procedures
- Lead accreditation activities and manage RMADS, Security Cases, and Security Management Plans
- Coordinate with accreditors and customer security representatives to obtain/maintain ATOs
- Ensure ongoing compliance with regulatory, contractual, and customer security requirements
- Identify, assess, and mitigate cybersecurity risks in classified environments
- Conduct security assessments, vulnerability reviews, and audits against standards
- Support risk treatment, remediation, and security monitoring activities
- Provide security guidance to admin and engineering teams
- Collaborate with programme managers, solution architects, IT teams, and customer representatives
- Support customer and regulatory audits and inspections
Key requirements
- Strong understanding of Windows Server, Linux, virtualization, and enterprise networking
- Experience securing classified or highly regulated IT environments
- Knowledge of cloud security (AWS, IaaS, PaaS) where applicable
- Familiarity with endpoint protection, SIEM, vulnerability management, encryption, and identity management
- Experience applying Secure by Design in complex IT systems
- Experience security architecture reviews, threat modelling, and risk assessments
- Experience supporting system engineering and security requirements in regulated environments
- Accreditation & ATO experience and ability to develop accreditation evidence
- Knowledge of UK Government and MoD accreditation processes and assurance frameworks
- Experience working with accrediting authorities, security controllers, or customer assurance teams
- Excellent written and verbal communication; ability to explain security to technical/non-technical stakeholders
- CISSP, CISM, or equivalent certification
- Degree in Cyber Security, Information Security, Computer Science, Engineering, or related discipline
- Experience in Defence, Aerospace, Government, or National Security sectors
- Knowledge of SPF, NCSC guidance, JSP 440, and Defence security requirements
- Ability to obtain and maintain UK Security Check clearance with potential to DV
- Strong communication skills
- Analytical and problem-solving abilities
- Ability to work independently while supporting multiple programmes
- Windows Server
- Linux
- Virtualization
…
