IT Security Officer (highly classified systems)

Leonardo DRS
Edinburgh, UK
3 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

CompTIA Security+ Cyber Security

Job description

Experteer Overview In this role you will act as the main security point of contact for highly classified systems and data, ensuring security controls are applied and maintained throughout the system lifecycle. You will provide security architecture support and collaborate with architects, system owners and operations to manage risk and assurance. You will review governance for projects, validate security requirements, and help maintain evidence and readiness for audits. This is a hands-on, across-site role with opportunities to influence security strategy in a regulated, high-stakes environment. Pay / Benefits * Act as the security point of contact for highly classified systems and data * Apply security controls, management plans and assurance arrangements * Provide security architecture support and advice to architects, system owners and operations * Review security governance for project delivery and ensure security requirements and assurance are considered * Manage security risk through the system lifecycle with stakeholders * Review changes for adherence to guardrails and provide informed risk guidance * Support risk assessments, non-compliance reviews and remediation planning * Maintain security evidence, control status and assurance activity for reviews * Escalate significant cyber or information risk changes to stakeholders * Support audits, assurance reviews and continual improvement for highly classified environments Tasks * Experience in information security, cyber security, secure operations or related technical security role * Experience in classified, regulated, defence or government environments * Understanding of MoD and UK government security policy and frameworks * Knowledge of security control frameworks and risk management practices * Practical understanding of risk assessment, residual risk, risk acceptance and non-compliance management * Experience supporting security architecture, design reviews or technical security decision-making * Experience reviewing security governance for project delivery and readiness criteria * Experience maintaining security management plans, assurance evidence and control records * Understanding of secure system operation, change control, access control, monitoring and incident response * Ability to work with technical teams, system owners and security specialists * Willingness and ability to obtain required security clearance (DV) * Professional security qualification such as CISSP, CISM, Security+, ISO 27001, Certified Cyber Professional or equivalent * Knowledge of cyber and information risk frameworks or methodologies Key requirements * generous leave with up to 12 additional flexi-days * pension scheme with up to 15% employer contribution * mental health support and wellbeing resources * bonus scheme for eligible staff * free access to 4,000+ online courses via Coursera and LinkedIn Learning * flexible benefits including private healthcare and discounts

Requirements

Review the system lifecycle with stakeholders * Review changes for adherence to guardrails and provide informed risk guidance * Support risk assessments, non-compliance reviews and remediation planning * Maintain security evidence, control status and assurance activity for reviews * Escalate significant cyber or information risk changes to stakeholders * Support audits, assurance reviews and continual improvement for highly classified environments Tasks * Experience in information security, cyber security, secure operations or related technical security role * Experience in classified, regulated, defence or government environments * Understanding of MoD and UK government security policy and frameworks * Knowledge of security control frameworks and risk management practices * Practical understanding of risk assessment, residual risk, risk acceptance and non-compliance management * Experience supporting security architecture, design reviews or technical security decision-making * aaaaaaaaH _ reviewing security governance for project delivery and readiness criteria * Experience maintaining security management plans, assurance evidence and control records * Understanding of secure system operation, change control, access control, monitoring and incident response * Ability to work with technical teams, system owners and security specialists * Willingness and ability to obtain required security clearance (DV) * Professional security qualification such as CISSP, CISM, Security+, ISO 27001, Certified Cyber Professional or equivalent * Knowledge of cyber and information risk frameworks or methodologies Key requirements * generous leave with up to 12 additional flexi-days * pension scheme with up to 15% employer contribution * mental health support and wellbeing resources * bonus scheme for eligible staff * free access to 4,000+ online courses via Coursera and LinkedIn Learning * flexible benefits including private healthcare and discounts

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on eu.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

3:02 min

Navigating DORA compliance and executive liability in security

Michele Zuccala Michele Zuccala +4 · WWC Europe 2026

4:27 min

Embracing a new perspective on mobile cyber attacks

Tom Tovar · WWC 2023

Videos

See all

Related articles

See all