Enable job alerts via email!

Chief Product Security Engineer

TN United Kingdom

Luton

On-site

GBP 60,000 - 100,000

Full time

30+ days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

Ein innovatives Unternehmen sucht einen Chief Product Security Engineer, um die Sicherheit von Produkten und Dienstleistungen zu gewährleisten. In dieser Schlüsselrolle sind Sie verantwortlich für die Entwicklung und Wartung von Sicherheitsmanagementsystemen, die den Anforderungen von Verteidigungs- und Regierungsbehörden entsprechen. Sie arbeiten eng mit Entwicklungsteams zusammen, um sicherzustellen, dass alle Sicherheitsaspekte in jeder Phase des Produktlebenszyklus berücksichtigt werden. Das Unternehmen bietet eine flexible Arbeitsumgebung und eine Vielzahl von Vorteilen, darunter eine umfassende Schulung und Entwicklungsmöglichkeiten. Wenn Sie leidenschaftlich daran interessiert sind, Sicherheitslösungen zu entwickeln und umzusetzen, ist dies die perfekte Gelegenheit für Sie.

Benefits

Flexible Arbeitszeiten
Private Gesundheitsversorgung
25 Tage Urlaub plus Feiertage
Pensionsplan mit bis zu 15% Arbeitgeberbeitrag
Mitarbeiterhilfeprogramm
Rabattierte Fitnessstudio-Mitgliedschaft
Zugang zu über 4000 Online-Kursen
Prämien für Empfehlungen
Bonusprogramm für Mitarbeiter

Qualifications

  • Erfahrung in der Entwicklung robuster Sicherheitsmanagementsysteme für Produkte.
  • Kenntnisse der UK/NATO Informationssicherheitsstandards und Verfahren.

Responsibilities

  • Sicherheitsberatung und Unterstützung für Produktentwicklungsteams bereitstellen.
  • Sicherheitsanforderungen ableiten und Risikobewertungen durchführen.

Skills

Produkt-Sicherheitsmanagement
Risikomanagement
Sicherheitsbewertungstechniken
Kommunikationsfähigkeiten
Kenntnis von Sicherheitsstandards
Incident Management

Education

NCSC Certified Professional
Ähnliche NCSC-anerkannte Qualifikation

Tools

ISO Sicherheitsstandards
HMG Sicherheitsrichtlinien

Job description

At Leonardo, we have a fantastic opportunity for a Chief Product Security Engineer to join our team within the Customer Support and Service Solutions (CS3) line of business. CS3 operates across the UK, providing innovative and invaluable support solutions to our customers. We help to ensure the availability of front-line capability wherever and whenever required.

We are looking for an experienced product security practitioner with expertise in developing and maintaining robust product security management systems for defence and government customers.

Within CS3, the term product can be used to include both in-service equipment, and the support solutions/services provided to customers, which in themselves are developed. The Chief Product Security Engineer will take responsibility for ensuring that all security aspects of the design, development, verification and maintenance of this range of products, through all phases of their lifecycle, have been completed in accordance with policy and process. They will work closely with the development teams to provide guidance in the design, implementation and maintenance of appropriate security controls.

Responsibilities
  • Provide security advice and support to product development teams, including:
  1. Deriving security requirements
  2. Undertaking security risk assessments for products
  3. Preparing security risk mitigation plans
  4. Review and approval of Security Management plans
  • Security policy maintenance and monitoring
  • Production of LoB security metrics
  • Management of attendance at external security forums
  • Attendance and support to the Security Special Interest Group
  • Lead security incident management teams during incident/crisis situations in conjunction with the Lead Product Security Engineer(s)
  • Delegated Authority Responsibilities
    • Security process maintenance and monitoring
    • Security competence framework maintenance and monitoring
    • Assessment of security competence in line with the competency framework
    • Chair and maintenance of a LoB security Community of Interest (CoI)
    • Promoting and sharing knowledge and best practice across the division to improve product security awareness and help embed it within ways of working
    • Training the engineering teams with respect to the security framework, policies and processes
    Minimum Requirements
    • Demonstrated experience of developing robust security risk management systems for a range of pan domain products and services in accordance with customer, regulatory and legislative expectations.
    • Familiarity with Legislation – e.g. IPA, DPA, Official Secrets Act
    • Registered NCSC Certified Professional at lead level, or equivalent NCSC recognised qualification.
    • Knowledge of UK/NATO Information Assurance standards, procedures & systems, including HMG Security Policy Framework, ISO security standards, RTCA DO326A.
    • Familiarity with the principles of incident investigation and knows how to implement an investigation process;
    • Practical experience of NCSC and Common Criteria security evaluation techniques and requirements up to High Grade.
    • Knowledge of current Crypto technologies, Key Management Systems & practical COMSEC implementations.
    • Experience of identifying the future Product Security needs of the company, regularly delivering training courses within a corporate environment and delivering awareness presentations to other groups.
    • Awareness of product security implications relating to safety
    • Excellent communication and interpersonal skills, with the ability to interact with a number of stakeholders from subject matter experts to senior leaders, regarding a wide range of technical and operational topics.
    • Good understanding and experience in delivery and maintenance of products to meet regulatory requirements, for example MAA DAOS, ARP4754
    • Understanding of the concept of operations for products, in order to understand the functional security risks and define/agree the appropriate mitigations
    • Ability to identify and deliver alternative/innovative ways to manage security, including ensuring buy-in from key regulatory bodies
    • Understanding of the role of advisory boards within the UK Government or NATO for security.
    • Active membership of an external security specialist group or forum
    Life at Leonardo

    With a company funded benefits package, a commitment to learning and development, and a flexible approach to working hours focused on the needs of both our employees and customers, a career with Leonardo has never offered as many opportunities or been more accessible to as many people.

    Benefits
    • Flexible Working: Flexible hours with hybrid working options. For part time opportunities, please talk to us.
    • Company funded flexible benefits: Access to private healthcare, dental schemes, Workplace ISA, Go Green Car Scheme, technology and lifestyle options (£500 annual allowance).
    • Holidays: 25 days plus bank holidays, option to buy/sell leave and to accrue up to 12 additional flexi leave days per year.
    • Pension: Award winning pension scheme (up to 15% employer contribution).
    • Wellbeing: Employee Assistance Programme with access to free mental health support, financial wellbeing support and network groups to demonstrate our ongoing commitment to diversity & inclusion (Enable, Pride, Equalise, Reservists, Carers).
    • Lifestyle: Discounted Gym membership, Cycle to work scheme.
    • Training: Free access to more than 4000 online courses via Coursera.
    • Referral Incentive: You can earn a reward for successfully referring a friend or family member.
    • Bonus: Scheme in place for all employees at management level and below.
    Get your free, confidential resume review.
    or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

    Similar jobs

    Lead IT Security Engineer

    ZOE

    Remote

    GBP 60,000 - 90,000

    Yesterday
    Be an early applicant

    Lead Security Engineer

    TieTalent

    Luton

    On-site

    GBP 80,000 - 100,000

    6 days ago
    Be an early applicant

    Lead Security Engineer (contract)

    JR United Kingdom

    Luton

    On-site

    GBP 55,000 - 85,000

    5 days ago
    Be an early applicant

    Lead Security Engineer (contract)

    ZipRecruiter

    Luton

    On-site

    GBP 80,000 - 100,000

    Yesterday
    Be an early applicant

    Lead Product Security Engineer

    TN United Kingdom

    Basildon

    On-site

    GBP 55,000 - 95,000

    30+ days ago

    Principal Infrastructure Security Engineer - Platform

    Palantir Technologies

    London

    Hybrid

    GBP 80,000 - 120,000

    Yesterday
    Be an early applicant

    Lead Product Security Engineer

    Tricentis

    London

    Hybrid

    GBP 50,000 - 90,000

    30+ days ago

    Principal Product Security Engineer

    Arm Limited

    Cambridge

    On-site

    GBP 60,000 - 80,000

    30+ days ago

    Lead Security Engineer

    ZipRecruiter

    London

    On-site

    GBP 90,000 - 100,000

    3 days ago
    Be an early applicant