> Markdown version of [/jobs/ext/1961432-senior-cybersecurity-consultant-secure-by-design-lead](https://www.wearedevelopers.com/jobs/ext/1961432-senior-cybersecurity-consultant-secure-by-design-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cybersecurity Consultant (Secure by Design Lead) - **Company:** Expleo - **Location:** Gloucester, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Systems Engineering, Cyber Security, Decision Support Systems, Sherwood Applied Business Security Architecture, Software Security, Togaf - **Published:** August 7, 2026 - **Apply:** https://find.jobs/jobs-near-me/apply/ats-redirect/?id=2912601161-2 ## About the Role This is a senior, client-facing role requiring strong cybersecurity leadership, defence assurance experience, maritime or shipbuilding awareness, and the ability to embed security into complex engineering, platform, IT and OT environments. The platform is designed to operate crewless, which shifts the security centre of gravity from information confidentiality towards the safety and availability of operational technology, and makes the remote command-and-control link and position, navigation, and timing resilience the assets that matter most., * Relevant education or industry-recognised certifications in cybersecurity, information assurance, secure engineering, security architecture, risk management or a related discipline. * Suitable qualifications may include BSc, MSc, CISSP, CISM, CRISC, CISA, CCP, ISO 27001 Lead Implementer/Lead Auditor, Security+, CySA+, SABSA, TOGAF, IEC 62443, NCSC CAF-related experience or equivalent professional experience. * Experience working within UK MOD, defence, maritime, shipbuilding, naval, critical national infrastructure or operationally critical environments would be highly beneficial. ## Description You will act as the cyber authority within the client's integrated design team, owning the Security Management Plan and the coherence of the wider security artefact set, and directing the work of a security architect and a cybersecurity consultant. The role sits at the intersection of naval architecture, systems engineering, product security, information assurance and MOD/maritime cyber compliance. The role requires a strong blend of cybersecurity leadership, secure engineering, technical assurance, stakeholder management, governance, supplier oversight and defence regulatory experience. You will need to operate with autonomy, technical credibility and the ability to provide clear decision support to senior leaders. * Own and maintain the Security Management Plan covering OT, IT and physical security, including the assurance and acceptance strategy, management of the supply chain and the route to demonstrating secure by design in accordance with UK MOD requirements. * Act as the senior security authority within the client's integrated design team, providing direction, challenge and assurance across engineering and delivery activity. * Develop the threat assessment and a proposed security risk appetite for agreement, in lieu of customer-supplied statements. * Lead the preliminary security risk assessment and manage design risk exposure, proportionate to the design's maturity, through a live design risk register owned by and reported to the client delivery team. * Produce the preliminary specification of security requirements and appropriate standards for OT, IT and physical security, including security classification and criticality assessment. * Maintain traceability from threat to risk to control to requirement, so that every security requirement is justified and evidenced. * Define supplier and supply chain security requirements and ensure they are embedded in specifications, delivery expectations and technical acceptance criteria. * Review and assess supplier security deliverables, including security claims, compliance evidence, technical designs, assurance artefacts and software bills of materials. * Direct and quality-assure the work of the security architect and cybersecurity consultant, ensuring the artefact set is coherent, traceable and defensible. * Provide security input to formal engineering design reviews, including system design reviews and equivalent programme governance gates, prepare and present material, and close out resulting actions. * Manage meetings with security stakeholders and represent the security position to senior client stakeholders and independent technical governance. * Apply relevant MOD, NCSC, defence and maritime security frameworks to support assurance, accreditation and compliance activities, and reconcile the security position with the platform safety case. * Generate a detailed scope of work for subsequent programme phases, and an outline scope for later phases. * Produce clear technical assurance outputs, security design material, decision papers, risk statements, briefing notes and governance updates. * Work independently as a senior subject matter expert, determining the day-to-day technical approach, stakeholder engagement and assurance rhythm required to achieve agreed outcomes. ## Related Videos - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)