Product Security Engineer

ARM (Advanced Resource Managers)

Luton

On-site

GBP 117,000 - 128,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

ARM (Advanced Resource Managers) in Luton seeks a Product Security Engineer to own security aspects across the product lifecycle. You will conduct security risk assessments, derive requirements, and work closely with development teams to implement robust security controls and artefacts.

The role requires leading security planning, risk mitigation, and collaboration with external authorities, including NCSC, to demonstrate compliance.

Qualifications

  • Graduate degree in relevant engineering, computing or related science.
  • Full membership of a recognised security body (CIISec/ISC2/ISACA).
  • Knowledge of live UK/EU/NATO information security standards and frameworks.
  • Experience producing assurance documentation (Key Management Plans, Security Instructions, SOPs, Security Cases).
  • Knowledge of cryptographic technologies and key management.
  • Understanding MBSE and its role in Product Security.
  • Knowledge of bespoke OS/fw/sw security controls.
  • Knowledge of Quantum Cryptography & Quantum Key management.
  • Experience or knowledge of threat intelligence sources.
  • Knowledge of NATO security policy, risk management and accreditation.

Responsibilities

  • Production of Security Management Plans and cost estimates for bids and proposals.
  • Conduct security risk assessments, risk mitigation plans and analysis.
  • Define product security requirements and advise development teams.
  • Coordinate with internal and external security authorities to demonstrate compliance.
  • Collaborate with authorities such as NCSC to underpin security solutions.
  • Manage security activities across development, testing and manufacturing.
  • Advise on platform lockdown configurations and support penetration testing.
  • Analyse penetration test results and plan remediations.
  • Oversee life cycle security management including obsolescence and patch management.
  • Lead security incident management with senior security leadership as needed.
  • Review and update corporate product security policies.
  • Deliver product security training to project teams.

Skills

Product security
Security risk assessment
MBSE
Cryptography
Vulnerability management
Incident management
Security testing
Policy compliance

Education

Graduate degree in engineering/computing
Membership in security body (CIISec/ISC2/ISACA)

Job description

Product Security Engineer

Luton

6-month contract

Paying up to Circa £93p/h (Inside IR35)

Please note - Due to the nature of the work, you'll be required to hold a high level of UK Security Clearance

Overview

As the Product Security Engineer/Lead security Engineer, you'll take responsibility for all security aspects of product design, development, verification and maintenance through all phases of the product life cycle.

The role will focus on undertaking security risk assessments, preparing security risk mitigation plans, deriving security requirements and working closely and directly with product development teams to design, implement and maintain appropriate security controls and the production of wider security artefacts.

Responsibilities
  • Production of Security Management Plans, work package descriptions and cost estimates in support of product bids, services and proposals.
  • Undertaking security risk assessments, risk mitigation plans, mitigation gap analysis and preparation of security management documentation for system assurance.
  • Defining product security requirements, advising development teams on bespoke implementations for product security control implementations and overseeing product development activities.
  • Liaison with internal and external security assurance authorities to desmontrate product compliance against recognised UK and wider frameworks.
  • Driving collaborative working with external security authorities such as the NCSC to provide underwriting of security solutions.
  • Understanding and management of security activities within development, testing and manufacturing environments.
  • Advising development teams on suitable platform lockdown and configurations, and supporting penetration test activities.
  • Analysing penetration test results and preparation of remedial action plans.
  • Identify, communicate and drive through life security management, including but not limited to obsolescence planning, vulnerability and patch management for all products within area of responsibility.
  • Lead security incident management teams during incident/crisis situations in conjunction with Head of Product Security for EW/FCA.
  • Review, maintain and participate corporate product security policies.
  • Deliver product security training to project engineering teams.
Essential Skills & Experience
  • Experience in the development of besoke product-based security solutions for a military and/or commercial products and systems.
  • Graduate degree in relevant engineering, computing or related scientific discipline, and/or evidence of further professional study.
  • Full membership of an NCSC recognised professional security body organisation (ie CIISec, ISC2 or ISACA).
  • Recent experience and demonstratable knowledge of live and Legacy UK/EU/NATO information security standards and frameworks, including the UK MOD Secure by Design framework, GovS 007, HMG IS1&2, ISO27001, NIST SP800-30/37/53, UK MOD Information Security related JSPs, EU CRA and US DoD information security policies.
  • Practical experience of producing technical assurance documentation such as Key Management Plans, Testing Security Instructions, Security Operating Procedures and Security Cases.
  • Knowledge of current cryptographic technologies and key management systems.
  • Understanding of Model Based System Engineering (MBSE) and how Product Security directly inputs into the process.
  • Knowledge and understanding of bespoke product-specific Operating Systems, Firmware and Software security controls and how to apply them.
  • Knowledge of Quantum Cryptography & Quantum Key management.
  • Experience or knowledge of existing threat intelligence sources.
  • Knowledge of NATO security policy, risk management and Accreditation.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Product Security Engineer
Product Security Engineer

ARM • Caddington

On-site
GBP 190,000 - 195,000
Product Security Engineer
Product Security Engineer

Advanced Resource Managers Ltd • Luton

On-site
GBP 77,000 - 128,000
Product Security Engineer
Product Security Engineer

CBSbutler Ltd. • Luton

On-site
GBP 229,233,000 - 257,887,000
Product Security Engineer
Product Security Engineer

CBS Butler • Luton

On-site
GBP 110,000 - 124,000
Product Security Engineer
Product Security Engineer

CBSbutler Holdings Limited trading as CBSbutler • Caddington

On-site
GBP 110,000 - 124,000
Product Security Engineer
Product Security Engineer

CBSbutler Holdings Limited trading as CBSbutler • Luton

On-site
GBP 140,000 - 180,000
Lead Product Security Engineer
Lead Product Security Engineer

Synergize Consulting Ltd • Luton

On-site
GBP 234,192,000 - 275,520,000
Security Engineer
Security Engineer

Technify Talent Limited • Greater London

On-site
GBP 55,000 - 90,000
Lead Product Security Engineer – UK Clearance
Lead Product Security Engineer – UK Clearance

Advanced Resource Managers Ltd • Luton

On-site
GBP 77,000 - 128,000
Principal Product Security Engineer
Principal Product Security Engineer

Expleo Group • Bath

Hybrid
GBP 90,000 - 120,000