Principal Engineer - Product Security

Morson Group
Barrow-in-Furness, UK
17 days ago
Apply on www.totaljobs.com
Prepare application

Role details

Contract type
Contract
Employment type
Full-time (> 32 hours)
Compensation
£177,632.0
Working hours
Regular working hours

Tech stack

Systems Engineering Cyber Security Javaserver Pages Software Security

Job description

We are recruiting for an experienced Principal Product Security Engineer to support a major UK defence engineering programme.

You will take a senior technical role within the Product Security team, providing security assurance across the engineering lifecycle of a complex, safety-critical system. The position involves Security Cases, information risk, security requirements and design assurance, working closely with engineering teams, programme stakeholders and external suppliers.

This is a Product / Systems Security engineering role supporting a complex defence platform - it is not an enterprise IT, SOC or corporate cyber security position., * Lead the development and delivery of Interim and Final Security Cases

  • Identify, assess and manage Product Security and Information Assurance risks
  • Maintain security risk evidence and contribute to programme-level risk registers
  • Identify security requirement gaps and support appropriate risk treatment
  • Provide Product Security input throughout the systems engineering lifecycle
  • Support design reviews, engineering maturity gates and technical assurance activities
  • Review and assure security evidence and deliverables produced by suppliers
  • Manage security-related technical queries and formal communications
  • Support security verification and testing activities
  • Work across Product Security, engineering and programme teams to ensure system-level security aligns with wider platform requirements
  • Provide technical leadership, guidance and mentoring to other engineers, Relevant experience is likely to include:
  • Security Case development and/or ownership
  • Security risk assessment, risk registers and risk management
  • Secure by Design
  • Security requirements capture, validation and gap analysis
  • Systems engineering lifecycle and design assurance
  • Supplier security assurance and technical reviews
  • Security verification/testing scope and assurance evidence
  • Defence, maritime, aerospace, nuclear or another highly regulated engineering environment
  • Experience applying relevant UK Government / defence security standards and frameworks, for example JSP 440, JSP 604, HMG IS1 & IS2, RMADS, Defence Standards (Def Stan), ISO 27000 and/or IEC 62443
  • Senior stakeholder engagement and the ability to operate as a Product Security SME

Requirements

We are looking for someone with strong experience in Product Security, Systems Security or Information Assurance within complex engineered systems, rather than traditional enterprise IT security., A relevant STEM, Cyber Security or Information Security qualification is desirable, alongside NCSC CCP SIRA or an equivalent professional security qualification.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.totaljobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:30 min

The universal and shared team responsibility of software security

Julia Wilson Julia Wilson +1 · World Congress 2025

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

43 sec

Software engineering journey and local Manchester roots

Jonathan Tang · Coffee With Developers

3:55 min

Establishing blameless dialogue surrounding critical software security vulnerabilities

Chris Heilmann Chris Heilmann +2 · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all