Principal Security Engineer, Luton
Principal Security Engineer, Luton
-
Luton, United Kingdom
-
Last edited: less than a week ago
-
Save
Description
Leonardo is seeking a product security engineer with expertise in developing and maintaining product security management systems for defence and government customers. The role is focused on undertaking security risk assessments for products, preparing security risk mitigation plans, deriving security requirements and working with product development teams to design and implement appropriate security controls. This position will require the job holder to perform validation and verification of the security requirements, including supporting independent Penetration Test and System Health Check test activities, and managing remedial action plans. Where products require security evaluation and/ or TEMPEST certification, the security engineer will prepare Security Targets and /or TEMPEST Control Plans and work with the customer authorities to achieve the necessary certifications. The security engineer will work customer Accreditors and security SMEs to ensure products compliance with customer security policies and any residual security risks are adequately defined and managed. This vacancy can be based in the south of the UK (apart from our Bristol site) and will involve occasional travel throughout the UK and abroad Key Responsibility Areas The successful candidate will report to the Product Security Team Leader and be responsible for providing security advice to product development teams in a range areas including: Production of Security Managements Plans, work package descriptions and cost estimates in support of product bids, services and proposals. Undertaking security risk assessments, risk mitigation plans, mitigation gap analysis and preparation of security management documentation for system Accreditation. Defining product security requirements, advising development teams on suitable implementation standards and techniques and overseeing product development activities. Liaison with Security Accreditors and Security Assurance Coordinators in support of security accreditation. Preparation of Security Targets and Evaluation Management Plans, and liaison with NCSC and commercial evaluation teams in support of evaluation activities. Preparation of TEMPEST Control Plans, advising development teams on appropriate implementation techniques and liaising with TEMPEST test facilities. Advising development teams on suitable platform lockdown and configurations, and supporting Penetration test activities. Analysing penetration test results and preparation of remedial action plans. Skills, Qualifications & Knowledge Required Essential Experience in the development of security solutions for a military &/or commercial products and systems. Graduate degree in relevant engineering, computing or related scientific discipline, and/or evidence of further professional study. Registered NCSC Certified Professional at senior level or above, or NCSC recognised qualification, e.g. ISC2 Certified Information System Security Professional. Knowledge of UK/NATO Information Assurance standards, procedures & systems, including HMG Security Policy Framework, HMG IS1&2 , ISO27001, JSP440, JSP604, guidance material provided by NCSC, CPNI and NIST. Practical experience of producing documentation to support Security Accreditation of products and systems Practical experience of NCSC and Common Criteria security evaluation techniques and requirements up to High Grade. Knowledge of current Crypto technologies, Key Management Systems & practical COMSEC implementations. Good understanding of technical, procedural and administrative security controls and how to apply them. Knowledge of communications system architectures (OSI 7 layer model). Understanding of the security issues in IP & other WAN/LAN technologies. Ability to obtain SC clearance with UK-eyes only caveat. Excellent verbal & written communication skills. Good team worker with ability to influence and motivate. Positive attitude and drive to improve the business. Desirable DV Clearance
Highlights
-
Company nameName Confidential
-
Job positionJobs: Principal Security Engineer
Safety Tips
If the salary for a position is far above normal, proceed with caution.
More info about this ad
Principal Security Engineer has been posted in the Luton Information Technology category on Locanto.
In this category, there are no other ads right now posted in Luton.
Interested in more? Widen your search to view ads in nearby areas of Luton. This includes Information Technology in Dunstable, Stevenage and Hemel Hempstead. There are more ads within a 10 mi radius for this category. If you want to view those ads, click here.