29 Email Security Solutions Architect jobs in Bath
Job No Longer Available
This position is no longer listed on WhatJobs. The employer may be reviewing applications, filled the role, or has removed the listing.
However, we have similar jobs available for you below.
Cloud Security Engineer
Posted 8 days ago
Job Viewed
Job Description
Cloud Security Engineer required by market leading, award winning organisation based in Central Bristol (5 minute walk from Bristol Temple Meads).
The successful Cloud Security Engineer will join a small, collaborative security team within a large, people-focused organisation. This is a hybrid role requiring 2 days a week in a vibrant Central Bristol office.
This is a fantastic opportunity to play a key role in shaping the security operations of a national business that places wellbeing, innovation, and employee development at the heart of its culture. You'll be working alongside passionate professionals who are committed to building secure, scalable, and resilient systems that support a positive end-user experience.
The Role: What You’ll Be Doing
- Network Security – Design and maintain secure network infrastructures, monitor traffic, respond to suspicious activity, and conduct audits to ensure compliance. li>Vulnerability Analysis – Carry out regular assessments and penetration tests, develop mitigation strategies, and report on remediation progress. < i>Incident Response – Lead incident detection, containment, and recovery efforts; conduct post-incident reviews and recommend improvements. < i>Forensic Analysis – Investigate incidents, perform root cause analysis, preserve digital evidence, and produce forensic reports. < i>Security Tools – Manage tools such as firewalls, IDS/IPS systems, and endpoint protection solutions; evaluate and recommend new technologies. < i>Documentation – Maintain detailed logs and reports of incidents, assessments, and analyses for internal stakeholders. < i>Collaboration – Partner with IT, development, and digital teams to embed security across all initiatives. < i>Ongoing Development – Stay current with emerging threats and industry best practices through regular training and self-development.
What We’re Looking For
- < i>Security Tools Proficiency – Hands-on experience with Palo Alto firewalls, IDS/IPS, and endpoint protection. < i>Network Security Knowledge – Deep understanding of VPNs, network protocols, and security architecture. < i>Incident Management – Proven ability to detect, analyse, and resolve security threats and malware. < i>Vulnerability Management – Experience in identifying and mitigating system vulnerabilities. < i>Automation Skills – Proficiency in security automation using scripting tools like Python or PowerShell. < i>Frameworks & Compliance – Familiarity with ISO 27001, NIST 800-53, Cyber Essentials, and GDPR. < i>Risk Management – Strong grasp of risk assessment methodologies and security control frameworks. < i>Communication – Able to communicate technical concepts clearly to both technical and non-technical stakeholders. < i>Project Management – Experience managing security projects and working with cross-functional teams. < i>Certifications – Relevant qualifications such as CEH, CCSP, CompTIA Security+, or AWS/Azure certs are highly desirable.
This fantastic role come with a highly competitive salary which is reviewed annually, and comes with an excellent benefits package which includes a 10% annual bonus, 25 days paid holiday, a flexible pension scheme, flexible working opportunities, shared Parental Leave - 18 weeks full pay, continued investment in your career, Bike to Work, discounts and many more.
Cloud Security Engineer
Posted 1 day ago
Job Viewed
Job Description
Cloud Security Engineer required by market leading, award winning organisation based in Central Bristol (5 minute walk from Bristol Temple Meads).
The successful Cloud Security Engineer will join a small, collaborative security team within a large, people-focused organisation. This is a hybrid role requiring 2 days a week in a vibrant Central Bristol office.
This is a fantastic opportunity to play a key role in shaping the security operations of a national business that places wellbeing, innovation, and employee development at the heart of its culture. You'll be working alongside passionate professionals who are committed to building secure, scalable, and resilient systems that support a positive end-user experience.
The Role: What You’ll Be Doing
- Network Security – Design and maintain secure network infrastructures, monitor traffic, respond to suspicious activity, and conduct audits to ensure compliance. li>Vulnerability Analysis – Carry out regular assessments and penetration tests, develop mitigation strategies, and report on remediation progress. < i>Incident Response – Lead incident detection, containment, and recovery efforts; conduct post-incident reviews and recommend improvements. < i>Forensic Analysis – Investigate incidents, perform root cause analysis, preserve digital evidence, and produce forensic reports. < i>Security Tools – Manage tools such as firewalls, IDS/IPS systems, and endpoint protection solutions; evaluate and recommend new technologies. < i>Documentation – Maintain detailed logs and reports of incidents, assessments, and analyses for internal stakeholders. < i>Collaboration – Partner with IT, development, and digital teams to embed security across all initiatives. < i>Ongoing Development – Stay current with emerging threats and industry best practices through regular training and self-development.
What We’re Looking For
- < i>Security Tools Proficiency – Hands-on experience with Palo Alto firewalls, IDS/IPS, and endpoint protection. < i>Network Security Knowledge – Deep understanding of VPNs, network protocols, and security architecture. < i>Incident Management – Proven ability to detect, analyse, and resolve security threats and malware. < i>Vulnerability Management – Experience in identifying and mitigating system vulnerabilities. < i>Automation Skills – Proficiency in security automation using scripting tools like Python or PowerShell. < i>Frameworks & Compliance – Familiarity with ISO 27001, NIST 800-53, Cyber Essentials, and GDPR. < i>Risk Management – Strong grasp of risk assessment methodologies and security control frameworks. < i>Communication – Able to communicate technical concepts clearly to both technical and non-technical stakeholders. < i>Project Management – Experience managing security projects and working with cross-functional teams. < i>Certifications – Relevant qualifications such as CEH, CCSP, CompTIA Security+, or AWS/Azure certs are highly desirable.
This fantastic role come with a highly competitive salary which is reviewed annually, and comes with an excellent benefits package which includes a 10% annual bonus, 25 days paid holiday, a flexible pension scheme, flexible working opportunities, shared Parental Leave - 18 weeks full pay, continued investment in your career, Bike to Work, discounts and many more.
Solutions Architect
Posted 6 days ago
Job Viewed
Job Description
People are our greatest asset, and we offer a competitive package to retain and attract the best talent.
In addition to the benefits you'd expect, UK employees also receive free single medical cover and digital GP service, family-friendly benefits such as enhanced parental leave pay and free membership of employee assistance and parental programmes, plus reimbursement towards relevant professional development and memberships. We also give back to our communities through our Collectively program which incorporates matched-funding, paid volunteering time and charitable donations.
**About the Opportunity**
We are looking for an individual to join our team in **Bristol** or **Cardiff** , to supporting ICT infrastructure design activities for a UK defence project. You will act as the bridge between business needs and technical solutions, ensuring that the ICT system design aligns with the client's organisational goals and effectively supports their business operations. Key responsibilities:
+ Defining IT architecture: Analyse business requirements, identify technical solutions, and create comprehensive IT architecture blueprints. Document the overall structure, components, and interactions of the IT system, ensuring that it aligns with the organisation's overall strategy and objectives.
+ Designing and developing IT systems: Translate IT architecture blueprints into tangible IT systems. Design, develop, and implement software applications, network infrastructure, and data management systems, ensuring that they meet performance, security, and scalability requirements.
+ Overseeing system performance: Monitor the performance of IT systems, identify potential bottlenecks, and implement corrective measures. Ensure that systems are scalable and can handle increasing workloads without compromising performance or stability.
+ Enhancing security and compliance: Implement security protocols, data encryption, and access controls to protect sensitive information and comply with industry regulations. Stay abreast of emerging security threats and vulnerabilities, ensuring that systems are adequately protected.
+ Communicating technical concepts: Effectively communicate complex technical concepts to both technical and non-technical stakeholders. Explain technical designs, provide project updates, and resolve technical issues in a clear and concise manner.
+ Staying up-to-date with technology: Constantly research and evaluate new technologies, trends, and industry standards. Incorporate the latest advancements into their designs and implementations, ensuring that IT systems remain relevant and effective.
**Here's What You'll Need**
+ Extensive IT knowledge: Possess deep expertise in a wide range of IT domains, including software development, network infrastructure, data management, virtualisation, and cloud computing.
+ Strong analytical and problem-solving skills: Be able to analyse complex problems, identify root causes, and devise effective solutions. Be able to think creatively and adapt to changing requirements.
+ Exceptional communication and collaboration skills: Effectively communicate technical concepts to both technical and non-technical audiences. Collaborate with team members, stakeholders, and external vendors to achieve common goals.
+ Continuous learning: Stay up-to-date with the rapidly evolving IT landscape, which requires continuous learning and adaptation. Be eager to learn new technologies and trends.
+ Customers/sectors: Experience working within the UK MOD
+ Experience: multiple years experience working on Defence IT systems
**Our Culture:**
Our values stand on a foundation of safety, integrity, inclusion and diversity. We put people at the heart of our business, and we genuinely believe that we all succeed by supporting one another through our culture of caring. We value positive mental health and a sense of belonging for all employees.
We aim to embed inclusion and diversity in everything we do. We know that if we are inclusive, we're more connected, and if we are diverse, we're more creative. We accept people for who they are, regardless of age, disability, gender identity, gender expression, marital status, mental health, race, faith or belief, sexual orientation, socioeconomic background, and whether you're pregnant or on family leave. This is reflected in our wide range of Global Employee Networks centered on inclusion and diversity.
We partner with VERCIDA to help us attract and retain diverse talent. For greater online accessibility, please visit to view and access our roles. As a Disability Confident employer, we will interview all disabled applicants who meet the minimum criteria for a vacancy. We welcome applications from candidates who are seeking flexible working and from those who may not meet all the listed requirements for a role.
If you require further support or reasonable adjustments with regards to the recruitment process (for example, you require the application form in a different format), please contact the
Amentum is proud to be an Equal Opportunity Employer. Our hiring practices provide equal opportunity for employment without regard to race, sex, sexual orientation, pregnancy (including pregnancy, childbirth, breastfeeding, or medical conditions related to pregnancy, childbirth, or breastfeeding), age, ancestry, United States military or veteran status, color, religion, creed, marital or domestic partner status, medical condition, genetic information, national origin, citizenship status, low-income status, or mental or physical disability so long as the essential functions of the job can be performed with or without reasonable accommodation, or any other protected category under federal, state, or local law. Learn more about your rights under Federal laws and supplemental language at Labor Laws Posters ( .
Solutions Architect
Posted 6 days ago
Job Viewed
Job Description
People are our greatest asset, and we offer a competitive package to retain and attract the best talent.
In addition to the benefits you'd expect, UK employees also receive free single medical cover and digital GP service, family-friendly benefits such as enhanced parental leave pay and free membership of employee assistance and parental programmes, plus reimbursement towards relevant professional development and memberships. We also give back to our communities through our Collectively program which incorporates matched-funding, paid volunteering time and charitable donations.
**About the Opportunity**
We are looking for an individual to join our team in **Bristol** or **Cardiff** , to supporting ICT infrastructure design activities for a UK defence project. You will act as the bridge between business needs and technical solutions, ensuring that the ICT system design aligns with the client's organisational goals and effectively supports their business operations. Key responsibilities:
+ Defining IT architecture: Analyse business requirements, identify technical solutions, and create comprehensive IT architecture blueprints. Document the overall structure, components, and interactions of the IT system, ensuring that it aligns with the organisation's overall strategy and objectives.
+ Designing and developing IT systems: Translate IT architecture blueprints into tangible IT systems. Design, develop, and implement software applications, network infrastructure, and data management systems, ensuring that they meet performance, security, and scalability requirements.
+ Overseeing system performance: Monitor the performance of IT systems, identify potential bottlenecks, and implement corrective measures. Ensure that systems are scalable and can handle increasing workloads without compromising performance or stability.
+ Enhancing security and compliance: Implement security protocols, data encryption, and access controls to protect sensitive information and comply with industry regulations. Stay abreast of emerging security threats and vulnerabilities, ensuring that systems are adequately protected.
+ Communicating technical concepts: Effectively communicate complex technical concepts to both technical and non-technical stakeholders. Explain technical designs, provide project updates, and resolve technical issues in a clear and concise manner.
+ Staying up-to-date with technology: Constantly research and evaluate new technologies, trends, and industry standards. Incorporate the latest advancements into their designs and implementations, ensuring that IT systems remain relevant and effective.
**Here's What You'll Need**
+ Extensive IT knowledge: Possess deep expertise in a wide range of IT domains, including software development, network infrastructure, data management, virtualisation, and cloud computing.
+ Strong analytical and problem-solving skills: Be able to analyse complex problems, identify root causes, and devise effective solutions. Be able to think creatively and adapt to changing requirements.
+ Exceptional communication and collaboration skills: Effectively communicate technical concepts to both technical and non-technical audiences. Collaborate with team members, stakeholders, and external vendors to achieve common goals.
+ Continuous learning: Stay up-to-date with the rapidly evolving IT landscape, which requires continuous learning and adaptation. Be eager to learn new technologies and trends.
+ Customers/sectors: Experience working within the UK MOD
+ Experience: multiple years experience working on Defence IT systems
**Our Culture:**
Our values stand on a foundation of safety, integrity, inclusion and diversity. We put people at the heart of our business, and we genuinely believe that we all succeed by supporting one another through our culture of caring. We value positive mental health and a sense of belonging for all employees.
We aim to embed inclusion and diversity in everything we do. We know that if we are inclusive, we're more connected, and if we are diverse, we're more creative. We accept people for who they are, regardless of age, disability, gender identity, gender expression, marital status, mental health, race, faith or belief, sexual orientation, socioeconomic background, and whether you're pregnant or on family leave. This is reflected in our wide range of Global Employee Networks centered on inclusion and diversity.
We partner with VERCIDA to help us attract and retain diverse talent. For greater online accessibility, please visit to view and access our roles. As a Disability Confident employer, we will interview all disabled applicants who meet the minimum criteria for a vacancy. We welcome applications from candidates who are seeking flexible working and from those who may not meet all the listed requirements for a role.
If you require further support or reasonable adjustments with regards to the recruitment process (for example, you require the application form in a different format), please contact the
Amentum is proud to be an Equal Opportunity Employer. Our hiring practices provide equal opportunity for employment without regard to race, sex, sexual orientation, pregnancy (including pregnancy, childbirth, breastfeeding, or medical conditions related to pregnancy, childbirth, or breastfeeding), age, ancestry, United States military or veteran status, color, religion, creed, marital or domestic partner status, medical condition, genetic information, national origin, citizenship status, low-income status, or mental or physical disability so long as the essential functions of the job can be performed with or without reasonable accommodation, or any other protected category under federal, state, or local law. Learn more about your rights under Federal laws and supplemental language at Labor Laws Posters ( .
Security Architect
Posted 4 days ago
Job Viewed
Job Description
Security Architect
+6 months +
+Fully remote working
+Inside IR35
+650- 725 a day
+DV cleared role
Requirement
Contribute to the delivery of compelling technical cyber security consultancy including designing and delivering secure technical solutions for complex systems for varied clients including Government, CNI and commercial sectors.
Partnering with our clients at senior levels to conduct analysis of and deliver consultancy on the security posture of complex systems. This includes development of conceptual security solutions, logical architectures, security plans, policies & processes and providing advice on technology selection. To include security-related project delivery elements, from the detailed technical level to high-level enterprise views.
Work with other security experts (including IA consultants, accreditors, penetration testers, and threat intelligence/hunting & SOC analysts) to inform secure design that meets both relevant governance requirements and customer business & security outcomes.
Apply detailed knowledge of the current cyber threat landscape, technical vulnerabilities and attack methodologies to the design of complex systems and inform risk.
Key competencies
- Strong technical background in varied environments and platforms.
- Understanding of the advantages and disadvantages of different system designs, including operating systems and network topologies.
- Excellent understanding of the current cyber threat landscape, technical vulnerabilities and attack methodologies and how these affect the design of complex systems.
- Motivated by working in a collaborative environment, both within the delivery team and within clients technical, security and project teams.
Desirable
- Experience of working Information Assurance Frameworks, both Government and commercial (e.g. NCSC CAF, IS 1&2, 27001, NIST, CIS).
- Understanding of how cyber security affects business and operational outcomes.
- A current understanding of security architecture principles and good practice for cyber defence in government, defence, CNI and commercial markets.
++ DV clearance is essential for this role ++
If you'd like to discuss this role in more detail, please send your updated CV to (url removed) and I will get in touch.
Security Architect
Posted 8 days ago
Job Viewed
Job Description
Security Architect
+6 months +
+Fully remote working
+Inside IR35
+650- 725 a day
+SC cleared role
Requirement
Contribute to the delivery of compelling technical cyber security consultancy including designing and delivering secure technical solutions for complex systems for varied clients including Government, CNI and commercial sectors.
Partnering with our clients at senior levels to conduct analysis of and deliver consultancy on the security posture of complex systems. This includes development of conceptual security solutions, logical architectures, security plans, policies & processes and providing advice on technology selection. To include security-related project delivery elements, from the detailed technical level to high-level enterprise views.
Work with other security experts (including IA consultants, accreditors, penetration testers, and threat intelligence/hunting & SOC analysts) to inform secure design that meets both relevant governance requirements and customer business & security outcomes.
Apply detailed knowledge of the current cyber threat landscape, technical vulnerabilities and attack methodologies to the design of complex systems and inform risk.
Key competencies
- Strong technical background in varied environments and platforms.
- Understanding of the advantages and disadvantages of different system designs, including operating systems and network topologies.
- Excellent understanding of the current cyber threat landscape, technical vulnerabilities and attack methodologies and how these affect the design of complex systems.
- Motivated by working in a collaborative environment, both within the delivery team and within clients technical, security and project teams.
Desirable
- Experience of working Information Assurance Frameworks, both Government and commercial (e.g. NCSC CAF, IS 1&2, 27001, NIST, CIS).
- Understanding of how cyber security affects business and operational outcomes.
- A current understanding of security architecture principles and good practice for cyber defence in government, defence, CNI and commercial markets.
++ SC clearance is essential for this role ++
If you'd like to discuss this role in more detail, please send your updated CV to (url removed) and I will get in touch.
Security Architect
Posted 8 days ago
Job Viewed
Job Description
Security Architect
+6 months +
+Hybrid working in Corsham
+Inside IR35
+SC cleared role
Skills:
+MOD
+HLD / LLD
+ VMware Horizon, ESXi, vCentre, vSAN
+PKI
We are seeking an experienced Security Architect to support the design and assurance of secure, enterprise-grade solutions for a major MOD NSOIT programme. Working at the heart of the OpNET Solution Design Authority, you'll play a vital role in developing secure, interoperable, and compliant architectures for a complex, high-security environment.
Key Responsibilities:
Provide expert security input into OpNET's technical roadmap and High-Level Designs (HLDs) for the NSOIT solution.
Design Intermediate Level Designs (ILDs) that align to MOD policies and industry best practices.
Review and assure Low-Level Designs (LLDs) and Detailed-Level Designs (DLDs).
Identify system vulnerabilities and advise on mitigation strategies.
Assess and review third-party services for security compliance.
Define and document security elements within the architectural runway, guiding platform and cyber teams (e.g., logging, antivirus, cyber defence, firewall configuration).
Essential Skills & Experience:
Proven experience delivering secure architecture within complex, large-scale government or defence programmes.
Deep knowledge of:
Secure infrastructure and software solution design
MOD security standards and NCSC design patterns
Public and private cloud solutions using Software Defined Datacentre (SDDC)
Secure cryptographic provisioning, PKI, ADFS, proxy services
Defence Lines of Development and MOD Capability Integration
Technical expertise across:
VMware Horizon, ESXi, vCentre, vSAN
Microsoft Server (Apply online only)), Windows 10, Exchange, SQL, Skype, Group Policy
Linux-based VDI solutions
Experience with MOD service management tooling and ITIL
Strong communication and analytical skills, with the ability to engage diverse technical and non-technical audiences.
Security certifications and experience with accredited secure solutions in the UK Public Sector.
Current SC clearance
If you'd like to discuss this Security Architect role in more detail, please send your updated CV to (url removed) and I will get in touch.
Be The First To Know
About the latest Email security solutions architect Jobs in Bath !
Security Architect
Posted 8 days ago
Job Viewed
Job Description
Security Architect
+6 months +
+Hybrid working in Corsham
+Inside IR35
+SC cleared role
Skills:
+MOD
+HLD / LLD
+ VMware Horizon, ESXi, vCentre, vSAN
+PKI
We are seeking an experienced Security Architect to support the design and assurance of secure, enterprise-grade solutions for a major MOD NSOIT programme. Working at the heart of the OpNET Solution Design Authority, you'll play a vital role in developing secure, interoperable, and compliant architectures for a complex, high-security environment.
Key Responsibilities:
Provide expert security input into OpNET's technical roadmap and High-Level Designs (HLDs) for the NSOIT solution.
Design Intermediate Level Designs (ILDs) that align to MOD policies and industry best practices.
Review and assure Low-Level Designs (LLDs) and Detailed-Level Designs (DLDs).
Identify system vulnerabilities and advise on mitigation strategies.
Assess and review third-party services for security compliance.
Define and document security elements within the architectural runway, guiding platform and cyber teams (e.g., logging, antivirus, cyber defence, firewall configuration).
Essential Skills & Experience:
Proven experience delivering secure architecture within complex, large-scale government or defence programmes.
Deep knowledge of:
Secure infrastructure and software solution design
MOD security standards and NCSC design patterns
Public and private cloud solutions using Software Defined Datacentre (SDDC)
Secure cryptographic provisioning, PKI, ADFS, proxy services
Defence Lines of Development and MOD Capability Integration
Technical expertise across:
VMware Horizon, ESXi, vCentre, vSAN
Microsoft Server (Apply online only)), Windows 10, Exchange, SQL, Skype, Group Policy
Linux-based VDI solutions
Experience with MOD service management tooling and ITIL
Strong communication and analytical skills, with the ability to engage diverse technical and non-technical audiences.
Security certifications and experience with accredited secure solutions in the UK Public Sector.
Current SC clearance
If you'd like to discuss this Security Architect role in more detail, please send your updated CV to (url removed) and I will get in touch.
Security Architect
Posted 8 days ago
Job Viewed
Job Description
An expanding Defence client of ours is currently in the market for a Secutrity Architect to specialise within their Product Security division. As the Product Security Architect, you will be working alongside a team who are constantly growing and developing. You will be responsible for Identify security requirements and ensure the integration of security controls during the product development lifecycle
Some of what you will be involved in:
- Develop and implement risk management strategies
- Perform security threat modelling and risk assessments applying security controls to mitigate any threats identified
- Collaborate with the development teams to ensure the adoption of Secure by Design principles
- Identify security risks that arise from potential solution architectures, advising and assuring alternate solutions or counter-measures to mitigate identified information risks.
- Collaborate with the product development teams to integrate security best practices ensuring Secure by Design
- Identify and mitigate security vulnerabilities and risks in products
- Develop and maintain security guidelines, documentation, and training materials
- Participate in incident response and remediation efforts for security breaches affecting products
Your skillset may include:
- Knowledge of HMG standards (including MOD-specific JSP, Def Stan 05-138, Def Stan 05-139)
- An understanding of MOD ISN 23/09 Secure by Design
- Knowledge of security frameworks, such as ISO/IEC 27001, NIST 800-30, NIST 800-53 or OWASP
- Working with risk management frameworks and methodologies (e.g., ISO 27001/2, ISO27005/31000, NIST 800-30, NIST 800-53)
Please reach out to Lewis Dunn @ ARM if you are interested or simply have some questions - E: or DD: (phone number removed)
Disclaimer:
This vacancy is being advertised by either Advanced Resource Managers Limited, Advanced Resource Managers IT Limited or Advanced Resource Managers Engineering Limited ("ARM"). ARM is a specialist talent acquisition and management consultancy. We provide technical contingency recruitment and a portfolio of more complex resource solutions. Our specialist recruitment divisions cover the entire technical arena, including some of the most economically and strategically important industries in the UK and the world today. We will never send your CV without your permission.
Security Architect
Posted 8 days ago
Job Viewed
Job Description
Security Arcitect
Location: Bristol, UK
Clearance Required: Must be eligible for SC Clearance
Are you passionate about safeguarding advanced products and systems from ever-evolving security threats? We are seeking a highly skilled Security Architect to join our cutting-edge team in Bristol. In this role, you'll be instrumental in securing the software development lifecycle for complex systems within the defence and national security domain.
This position is critical to ensuring our products meet the highest standards of security by design. The successful candidate will be expected to bring deep, hands-on experience with NIST cybersecurity standards -this is essential -as well as a strong working knowledge of Defence Standards DefStan 05-138 Issue 3 and DefStan 05-139 Issue 1 . If you're an experienced professional with strong capabilities in threat modelling , risk assessment , and secure systems architecture , we want to hear from you.
Role Responsibilities:
Integrate security controls throughout the product development lifecycle
Conduct detailed threat modelling and risk assessments using recognised tools
Lead the implementation of risk management strategies based on industry best practices (NIST, ISO)
Work closely with development teams to ensure secure-by-design principles are followed
Identify and propose mitigations for security vulnerabilities in solution architectures
Maintain and evolve internal security policies, documentation, and awareness training
Support incident response efforts and coordinate remediation actions where needed
Serve as a subject matter expert on product and application security to internal stakeholders
Key Requirements:
Extensive experience applying NIST frameworks (including NIST 800-30, NIST 800-53) - non-negotiable
Working knowledge of DefStan 05-138 (Issue 3) and DefStan 05-139 (Issue 1) is essential
Proficiency in threat modelling methodologies and tools (e.g., STRIDE, DREAD, Attack Trees)
Familiarity with other standards such as ISO/IEC 27001, ISO 27005, OWASP, and MOD ISN 23/09
Ability to identify, assess and mitigate risks across software and hardware product ecosystems
Strong written and verbal communication skills, including the ability to convey risk to non-technical audiences
Ideal Candidate Traits:
Analytical thinker with strong problem-solving skills
Detail-oriented with excellent planning and organisational abilities
Resilient, proactive, and capable of driving initiatives forward independently
A team player with the ability to influence at all levels of the organisation
Eligible for SC clearance and able to work in the UK without restrictions