Principal Engineer - Product Security
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
We are recruiting for an experienced Principal Product Security Engineer to support a major UK defence engineering programme.
You will take a senior technical role within the Product Security team, providing security assurance across the engineering lifecycle of a complex, safety-critical system. The position involves Security Cases, information risk, security requirements and design assurance, working closely with engineering teams, programme stakeholders and external suppliers.
This is a Product / Systems Security engineering role supporting a complex defence platform - it is not an enterprise IT, SOC or corporate cyber security position., * Lead the development and delivery of Interim and Final Security Cases
- Identify, assess and manage Product Security and Information Assurance risks
- Maintain security risk evidence and contribute to programme-level risk registers
- Identify security requirement gaps and support appropriate risk treatment
- Provide Product Security input throughout the systems engineering lifecycle
- Support design reviews, engineering maturity gates and technical assurance activities
- Review and assure security evidence and deliverables produced by suppliers
- Manage security-related technical queries and formal communications
- Support security verification and testing activities
- Work across Product Security, engineering and programme teams to ensure system-level security aligns with wider platform requirements
- Provide technical leadership, guidance and mentoring to other engineers, Relevant experience is likely to include:
- Security Case development and/or ownership
- Security risk assessment, risk registers and risk management
- Secure by Design
- Security requirements capture, validation and gap analysis
- Systems engineering lifecycle and design assurance
- Supplier security assurance and technical reviews
- Security verification/testing scope and assurance evidence
- Defence, maritime, aerospace, nuclear or another highly regulated engineering environment
- Experience applying relevant UK Government / defence security standards and frameworks, for example JSP 440, JSP 604, HMG IS1 & IS2, RMADS, Defence Standards (Def Stan), ISO 27000 and/or IEC 62443
- Senior stakeholder engagement and the ability to operate as a Product Security SME
Requirements
We are looking for someone with strong experience in Product Security, Systems Security or Information Assurance within complex engineered systems, rather than traditional enterprise IT security., A relevant STEM, Cyber Security or Information Security qualification is desirable, alongside NCSC CCP SIRA or an equivalent professional security qualification.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Is Software Engineering Hard?
The 12 Best Jobs for Software Engineers
Where To Find Software Engineering Jobs
Understanding and Mitigating Common Web Vulnerabilities