Principal Engineer – Product Security

Company: BAE Systems
Apply for the Principal Engineer – Product Security
Location: Portsmouth
Job Description:

Overview

In this role you define and implement risk-based cybersecurity requirements for systems and subsystems, guiding across cyber security and resilience. You conduct in-depth analysis, develop threat taxonomies and security artefacts, and drive security testing and assurance. You support secure engineering lifecycle reviews to embed security in development. You’ll work with cross-functional teams to shape secure submarine platform solutions and risk management. This is a hands-on, impact-focused opportunity in a mission-driven, defence context.

Pay / Benefits

  • hybrid working options
  • relocation support packages for submarine roles
  • competitive salary
  • lifelong learning and personal development
  • support for wellbeing
  • inclusive culture

Responsibilities

  • Define and implement risk-based cybersecurity requirements for systems and subsystems
  • Conduct cybersecurity analysis, develop threat taxonomies, security architectures, baselines, and risk mitigation strategies
  • Develop and execute cybersecurity test plans and formal/informal testing activities
  • Support engineering lifecycle reviews and design assurance for security integration
  • Produce and maintain security artefacts (risk registers, assurance cases, plans, schedules) and contribute to broader engineering documentation
  • Engage with customers, users, and stakeholders to explain risk causes, likelihood, and operational impact
  • Identify, analyse, evaluate and manage information security risks for submarine products
  • Provide security input to engineering documentation and cross-functional teams

Key requirements

  • Degree in a relevant STEM subject or recognised Industry Security Qualifications (e.g., CCP, CISSP)
  • Proven experience assessing and managing risk per industry practices (NIST, ISO 27001)
  • Extensive experience with security baselines, mitigations and controls
  • Familiarity with a life cycle phased (systems engineering) approach
  • Credible communication with customers and stakeholders
  • Collaborative cross-functional teamwork
  • Analytical and problem-solving mindset
  • Risk-based cybersecurity
  • Security architectures and baselines
  • Threat modelling and security testing

…

Posted: September 25th, 2026