Lead Security Engineer

Morson Group
Luton, UK
3 days ago
Apply on www.careerboard.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
£62,400.0
Working hours
Regular working hours

Tech stack

Software System Penetration Testing Computing Platforms Cyber Security Firmware Key Management Software Vulnerability Management Software Security SC Clearance Information Technology Patch Management

Job description

We are seeking an experienced Product Security Engineer with expertise in developing and maintaining bespoke security management solutions for Defence and Government customers. Reporting to the Head of Engineering Projects, you will take ownership of all security aspects of product design, development, verification, and maintenance throughout the product life cycle. You will be responsible for conducting security risk assessments, developing mitigation strategies, deriving security requirements, and working closely with engineering teams to design, implement, and maintain effective security controls. This is an exciting opportunity to play a key role in delivering secure, high-assurance solutions while working alongside customers, security authorities, and multidisciplinary engineering teams., As Product Security Engineer, you will: Produce Security Management Plans, work package descriptions, and cost estimates to support bids, proposals, and service delivery activities. Conduct security risk assessments, mitigation planning, gap analyses, and prepare security assurance documentation. Define security requirements and provide guidance to development teams on implementing bespoke security controls. Work with internal and external security assurance authorities to demonstrate compliance with customer, regulatory, and industry security standards. Build relationships with organisations such as the NCSC and other relevant security bodies to support assurance and accreditation activities. Oversee and manage security activities across development, testing, and manufacturing environments. Advise teams on platform hardening, secure configurations, and penetration testing activities, including analysing results and defining remediation plans. Drive through-life security management activities, including vulnerability management, patch management, and obsolescence planning. Support and lead security incident response activities during security incidents or crisis situations. Review, contribute to, and maintain corporate product security policies and standards. Deliver product security training and awareness sessions to engineering and project teams.

Requirements

Essential Skills, Experience & Qualifications Proven experience developing bespoke product security solutions within defence, government, military, or highly regulated commercial environments. Degree in Engineering, Computer Science, Cyber Security, or a related discipline, and/or equivalent professional experience. Full membership of a recognised professional security organisation such as CIISec, ISC2, or ISACA. Strong knowledge of UK, EU, NATO, and international security standards and frameworks, including: o UK MOD Secure by Design o GovS 007 o HMG IS1 & IS2 o ISO 27001 o NIST SP 800-30, SP 800-37 and SP 800-53 o MOD Information Security JSPs o EU Cyber Resilience Act (CRA) o US DoD Information Security Policies Experience producing technical assurance documentation, including: o Security Cases o Security Operating Procedures o Testing Security Instructions o Key Management Plans Knowledge of cryptographic technologies and key management systems. Understanding of Model-Based Systems Engineering (MBSE) and the integration of security into engineering life cycles. Experience applying security controls across operating systems, firmware, and software platforms. Excellent written and verbal communication skills. Strong stakeholder engagement and influencing skills. A proactive mindset with a passion for continuous improvement. Eligibility to obtain UK Security Clearance (SC), including UK Eyes Only requirements.

Desirable Skills & Experience Current DV clearance. Experience with Common Criteria security evaluation methodologies. Knowledge of quantum cryptography and quantum key management principles. Familiarity with threat intelligence sources and threat-informed security practices. Knowledge of NATO security policies, risk management, and accreditation processes. Understanding of government and NATO security advisory boards and governance structures.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerboard.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:19 min

Orchestrating over-the-air firmware updates for vehicle modules

Denis Grahovac · World Congress 2021

3:21 min

Introduction to automotive security and digital forensics

Martin Schmiedecker · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all