Cybersecurity Consultant (Discovery, Threat and Requirements)

Expleo Group

West of England

Hybrid

GBP 70,000 - 100,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Collaborative working environment
ExpleoAcademy
Competitive company benefits
Disability Confident commitment

Job summary

Expleo Group is delivering cybersecurity consultancy for a major UK defence maritime programme. You will work in a small, security-cleared team to establish asset baselines, model threats, and define security requirements embedded in the design team’s workstreams.

You will document evidence packs, support risk assessment using NIST/ISO standards, and coordinate with engineering, architecture, IT, OT, and assurance colleagues to meet fixed milestones.

Qualifications

  • Education or certifications in cybersecurity, information assurance, risk management or related discipline.
  • Experience with threat modelling and risk assessment in complex systems.
  • Experience in UK MOD/defence/maritime environments is beneficial.
  • Ability to produce evidence for design reviews and client assessments.

Responsibilities

  • Lead asset discovery across documentary, logical, interview and physical sources to establish an authoritative asset baseline.
  • Populate and maintain the initial asset register with class, ownership, configuration state, dependencies and interfaces.
  • Establish platform threat landscape using credible threat information and STRIDE/MITRE ATT&CK for ICS.
  • Support preliminary security risk assessment using NIST SP 800-30 and ISO/IEC 27005.
  • Capture security requirements and maintain traceability from threat to risk to control.
  • Prepare clear, well-structured documentation and evidence packs for design reviews and client acceptance.
  • Collaborate with engineering, IT, OT, and assurance teams; escalate issues and risks promptly.

Skills

Threat modelling
IT & OT
MOD/NCSC frameworks
Documentation
Attention to detail
Stakeholder management
Security team delivery
Defence background

Education

BSc in cybersecurity
CISSP/CISM/ISO 27001 certs

Job description

Expleo is a trusted partner for end-to-end, integrated engineering, quality services, and management consulting for digital transformation. We help businesses harness technological change to successfully deliver innovation, improve resilience and support secure, regulated and operationally critical environments.

As part of the Expleo UK Cybersecurity Practice, you will deliver the discovery, threat, risk and requirements activity that underpins the security case for a major UK defence maritime programme, supporting an autonomous surface vessel capability being matured towards a whole-ship system design review.

This is a delivery-focused consultancy role for someone methodical and evidence-driven. You will establish the asset baseline that everything else traces back to, contribute to the threat and risk picture, and capture the security requirements that the design team will build to.

You will work within a small, security-cleared team alongside a Secure by Design lead and a security architect, and directly with the client's design team, in an environment where accuracy, traceability and clear documentation carry real weight.

The role suits a cybersecurity consultant with a solid grounding in threat and risk methods and requirements work, who is looking to apply this in a technically demanding defence maritime programme.

Responsibilities
  • Lead discovery activity across documentary, logical, interview and physical sources to establish an authoritative asset baseline.
  • Populate and maintain the initial asset register, capturing asset class, criticality, ownership, configuration state, dependencies and interfaces.
  • Establish and maintain the platform threat landscape by drawing on credible, up-to-date threat information.
  • Contribute to threat modelling using recognised methods such as STRIDE and MITRE ATT&CK for Industrial Control Systems, expressed as attack paths.
  • Support the preliminary security risk assessment using NIST SP 800-30 and ISO/IEC 27005, and maintain entries in the design risk register.
  • Capture security requirements and maintain the traceability thread from threat to risk to control to requirement.
  • Support security classification and criticality assessment across platform systems and information.
  • Prepare clear, well-structured documentation and evidence packs suitable for design review and client acceptance.
  • Support the compliance crosswalk of programme artefacts against applicable standards and assurance frameworks.
  • Support security stakeholder meetings, capture actions and drive them to closure.
  • Produce knowledge-transfer material to enable the client design team to maintain the artefacts across subsequent phases.
  • Work collaboratively with colleagues in engineering, architecture, IT, OT, and assurance, and promptly escalates issues and risks.
Qualifications
  • Relevant education or industry-recognised certifications in cybersecurity, information assurance, risk management or a related discipline.
  • Suitable qualifications may include BSc, MSc, CompTIA Security+, CySA+, CISM, CISSP (or associate), ISO 27001 Lead Implementer/Lead Auditor, ISO 27005 risk, ISA/IEC 62443 Cybersecurity Fundamentals Specialist, or equivalent professional experience.
  • Candidates working towards relevant certifications alongside strong practical experience are welcome to apply.
  • Experience working within UK MOD, defence, maritime, shipbuilding, naval, critical national infrastructure or operationally critical environments would be highly beneficial.
Essential Skills
  • Working knowledge of threat modelling methods and the ability to express threats as credible attack paths.
  • Understanding of both IT and operational technology environments and the different security considerations each carries.
  • Awareness of MOD, NCSC or defence security frameworks and how they shape assurance evidence.
  • Strong documentation skills, with the ability to produce accurate, well-structured and reviewable technical material.
  • Methodical, detail-focused approach with a strong sense of ownership for the quality and traceability of evidence.
  • Good stakeholder skills, with the ability to gather information effectively from engineers and system owners.
  • Ability to work as part of a small, security-cleared delivery team to fixed milestones.
  • A military or defence background, particularly in communications, information systems or security.
Experience
  • Experience delivering cyber risk, assurance or security requirements work on technical programmes.
  • Experience contributing to threat assessments, threat models or risk assessments for complex systems.
  • Experience producing security documentation and evidence for review by clients, assessors or regulators.
  • Experience working alongside engineering or design teams in a multi-disciplinary environment.
  • Experience of regulated, safety-critical or operationally critical delivery environments.
  • Experience handling sensitive defence or client information in line with UK MOD, NCSC, client security and data protection requirements.
  • Practical cybersecurity consultancy experience in defence, maritime, critical national infrastructure or another regulated or operationally critical environment.
  • Experience conducting discovery and building or maintaining asset registers or configuration baselines.
  • Experience supporting security risk assessment using recognised methods such as NIST SP 800-30 or ISO/IEC 27005.
  • Experience capturing security requirements and maintaining traceability to threat, risk and control.
  • Experience with marine or vessel systems, or with defence communications and information systems.
  • TEMPEST awareness, or experience of emanation security assurance to NATO standards.
  • Experience with IEC 62443, NCSC CAF, MOD Secure by Design, ISO 27001 or Def Stan 05-138.
  • Experience of autonomous, uncrewed or remotely operated systems.
  • Experience supporting design reviews or formal assurance gates.
  • Experience with requirements management or traceability tooling.
What Do I Need Before I Apply
  • Have the right to work in the UK.
  • Hold, or be eligible to obtain, UK Security Check (SC) clearance. Clearance is a mandatory requirement for this programme, and applicants must meet the UK residency criteria for security clearance.
  • Be willing and able to work in a hybrid model, including client site attendance as required.
  • Be comfortable working within secure collaboration environments and handling information marked up to OFFICIAL-SENSITIVE.
  • Be able to work under the terms of applicable confidentiality and non-disclosure arrangements.
Benefits
  • Collaborative working environment – we stand shoulder to shoulder with our clients and ourpeers through good times and challenges
  • We empower all passionate technology loving professionals by allowing them to expand their skills and take part in inspiring projects
  • ExpleoAcademy - enables you to acquire and develop the right skills by delivering a suite of accredited training courses
  • Competitive company benefits
  • Always working as one team, our people are not afraid to think big and challenge the status quo
  • As a Disability Confident Committed Employer we have committed to:
    • Ensure our recruitment process is inclusive and accessible
    • Communicating and promoting vacancies
    • Offering an interview to disabled people who meet the minimum criteria for the job
    • Anticipating and providing reasonable adjustments as required
    • Supporting any existing employee who acquires a disability or long term health condition, enabling them to stay in work at least one activity that will make a difference for disabled people

“We are an equal opportunities employer and welcome applications from all suitably qualified persons regardless of their race, sex, disability, religion/belief, sexual orientation or age”.

We treat everyone fairly and equitably across the organisation, including providing any additional support and adjustments needed for everyone to thrive

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer
Cybersecurity Engineer

Expleo • Belfast

On-site
GBP 40,000 - 70,000
Collaborative working environment
Skills development opportunities
Competitive company benefits
Principal Systems Engineer
Principal Systems Engineer

Expleo • Farnborough

Hybrid
GBP 70,000 - 110,000
ExpleoAcademy
Competitive benefits
Disability Confident Employer
Senior Safety Engineer
Senior Safety Engineer

Expleo Group • Crawley

On-site
GBP 65,000 - 85,000
Collaborative environment
ExpleoAcademy
Competitive benefits
Principal Systems Engineer
Principal Systems Engineer

Expleo • Barnstaple

Hybrid
GBP 85,000 - 120,000
Collaborative environment
ExpleoAcademy training
Competitive benefits
+1
Senior Safety Engineer
Senior Safety Engineer

expleo-jobs-gb-en • Crawley

On-site
GBP 65,000 - 90,000
Competitive benefits
ExpleoAcademy development
Professional growth opportunities
Senior Software Engineers (ADA 95)
Senior Software Engineers (ADA 95)

Expleo • Portsmouth

On-site
GBP 65,000 - 90,000
Collaborative working environment
ExpleoAcademy training
Competitive benefits
+1
Senior Safety Engineer
Senior Safety Engineer

Expleo • Crawley

On-site
GBP 65,000 - 90,000
Expleo Academy
Competitive benefits
Collaborative environment
+1
Principal Systems Engineer / Technical Authority
Principal Systems Engineer / Technical Authority

Expleo • West of England

Hybrid
GBP 90,000 - 120,000
Systems Engineering Delivery Manager
Systems Engineering Delivery Manager

Expleo Group • Belfast

On-site
GBP 60,000 - 80,000
Collaborative working environment
ExpleoAcademy for skills development
Competitive company benefits
Engineering Team Leader
Engineering Team Leader

Expleo Group • East Midlands

On-site
GBP 65,000 - 90,000
Expleo Academy
Competitive benefits
Collaborative environment
+1