Principal Cyber Security Architect - Appcast Enterprise : Job Details

Principal Cyber Security Architect

Appcast Enterprise

Job Location : Farnborough, UK

Posted on : 19/01/2025 - Valid Till : 02/03/2025

Job Description :

Description

Principal Cyber Security Architect

Location: Farnborough, UK - You may need to work on customer locations or one of our secure development locations, or a mix of both, as well as an element of working from home.

Looking for an opportunity to make an impact?

Role Overview:

Leidos is expanding in the National Security and Defence domain and are looking for a Principal Cyber Security Architect to support new pursuits, bids, captures and existing delivery programmes based in the UK working at our Farnborough site and remotely.

Leidos has more than 30 years’ experience of developing and running some of the largest government systems in the world.

Come join our team and further develop your skills as we deliver and support systems key to the defence of the UK and partner nations.

Being part of the Leidos team is a commitment to push yourself and those around you to do better, constantly adapt and learn new technologies. We’re a passionate team and are committed to developing and growing our staff.

Leidos is a global science and technology solutions leader working to solve the world's toughest challenges in the defence, intelligence, homeland security, civil, and health markets.

What Will you Be Doing?

As a result of some exciting programme wins and active new pursuits, Leidos is seeking an enthusiastic proactive Principal Cyber Security Architect to lead the implementation and assurance of security within key defence bids, growth opportunities and project deliveries.

You will possess specialist skills in all areas of protective and information security and have demonstrable experience of applying security frameworks such as Government Functional Standard 007 and the MoD Secure by Design approach

You will be joining a team of highly skilled and highly motivated individuals delivering solutions based on a large range of technical capabilities and technologies including hardware, software, networks, cloud, IT services and cyber security.

Note: The National Security and Defence (NS&D) portfolio includes programmes and opportunities that cover a range of customers focused on the operational and mission areas of UK MOD and UK Homeland security. It would be beneficial if you have prior experience in these domains.

What does Leidos need from me?

As the Principal Cyber Security Architect, you will be able to work with minimal direction on a specific MOD programme or bid or across a range of bids. You will ensure that the solution security design meets the customer functional and non-functional security requirements and provides the necessary assurance to our client, highly likely to be backed up by rigorous assurance and certification processes, normally HMG standards (including MOD-specific JSP), NCSC and NIST 800 standards.

You will have responsibility for interfacing to security design partners across the programme or bid, both customer and supplier representatives, and colleagues within our engineering, service, and business development teams. You will ensure that Leidos can establish and maintain an effective and efficient security architecture for the programme or bid solution, and that the designs will be able to adapt as customer requirements, legislation and assurance standards change over the programme lifespan.

Within the programme or bid, the role will primarily be responsible to a solution architect and Chief Engineer for developing and delivering the relevant elements of the solution, whilst understanding the whole.

You will have a complete understanding of cyber risk and treatment approaches. Based on a strong ability to communicate risk and its proportionate management, you will know how this issue is addressed both in traditional ‘on-premise’ highly sensitive platforms, and in private and public cloud technologies. You will be experienced and accomplished in meeting the challenges associated with assuring systems in public and private cloud environments.

You will be required to develop high- and low-level security architecture designs for systems intended for secure/sensitive environments, with appropriate security based on detailed risk analysis. SABSA qualifications and experience would be desirable.

You will be required to hold security clearance under National Security Vetting processes.

Essential:

  • British - Non-dual national – many of our projects have nationality restrictions
  • Willing and able to hold and maintain DV clearance

Process Skills/Experience:

  • Experience of a taking a defence in depth and multi layered approach to security architecture
  • Experience of applying commensurate detective and protective security controls to reduce risk to an acceptable level
  • Understanding of the controlling processes for, and experience of a significant portion of, the systems engineering lifecycle (e.g. requirements management, configuration management)
  • Understanding of different lifecycles/methodologies (incremental, SAFe agile, DevOps)
  • Experience of the key engineering lifecycle reviews – e.g. System Requirements Review (SRR), Critical Design Review (CDR)
  • Experience in performing design trade off working with other architects and engineers to deliver an integrated and coherent solution
  • Understanding of service operations and security operational management planning
  • Experience working in both delivery and proposal environments and leading key elements of a bid response
  • Experience of Defence Digital and relevant solutions and approaches across MOD
  • Ability to generate Basis of Estimates and schedules for security aspects of delivery
  • Experience of designing a secure software development lifecycle (SDLC) for a customer that's transitioning to a DevOps model

Technology skills/Experience:

  • Excellent understanding of Confidentiality, Integrity and Availability (CIA) and practical experience in applying that
  • Experience in defining derived security requirements for a system, and managing traceability
  • Experience of gaining and maintaining accreditation or assurance for secure/sensitive systems
  • Experience of security infrastructure in Public and Private cloud, e.g. virtual network infrastructure, hybrid IaaS/PaaS/SaaS solutions.
  • Understanding of MOD ISN 23/09 Secure by Design
  • Experience in producing security assurance documentation sets (such as SyOPS, Security Management Plan, ISMS, and to support DART submissions)Experience in producing security bid artefacts (such as security responses to PQQ/ITN questions, creation of Pro
  • Salary : -

    Apply Now!

    Similar Jobs ( 0)