- Company Name
- CENSUS
- Job Title
- Senior Product Security Consultant - Defense Systems (UK Nationals)
- Job Description
-
**Job title**
Senior Product Security Consultant – Defense Systems
**Role Summary**
Lead security engineering engagements for defense‐grade products, combining architecture review, threat modeling, compliance mapping, and stakeholder communication. Drive secure‑by‑design solutions from pre‑sales through execution, ensuring alignment with international standards and operational mission constraints.
**Expactations**
- 5+ years of hands‑on cybersecurity in embedded, secure communications, or mission‑critical domains.
- MSc/BSc in Computer Science, Cybersecurity, or related field.
- Fluency in English with strong technical writing skills.
**Key Responsibilities**
- Conduct architecture & implementation reviews, verify secure boot, cryptography, and firmware integrity.
- Perform threat modeling against NIST, Common Criteria, NATO NIAG, ISO 15408 frameworks.
- Evaluate post‑quantum/hybrid crypto in key management and secure comms.
- Test control systems, SCADA, IoT, and air‑to‑ground payloads.
- Map findings to FIPS 140‑3, Common Criteria EAL, DoD STIGs, DoDIN APL certification pathways.
- Support compliance evidence, ATO processes, and hardening for RTOS, containers, ruggedized hardware.
- Aid pre‑sales: architecture proposals, whitepapers, demos, and cost‑value justification.
- Lead technical execution, define milestones, manage resources, and maintain client‑team communication.
**Required Skills**
- Security architecture, API gateways, microservices, service meshes.
- Design‑level security reviews, threat model validation.
- Defense standards: DFARS / NIST 800‑171, CMMC, MIL‑STD‑882, STANAGs.
- Tactical constraints: C4ISR, unmanned, EW integrations.
- Zero Trust for disconnected/intermittent networks (D‑DIL).
- Identity & secrets: OAuth2, MFA, PKI, SSO, Cloud IAM, Vault.
- Applied cryptography: mTLS, E2EE, AEAD, key derivation, remote attestation.
- Vulnerability detection: OWASP Top 10, misconfigurations, transport gaps.
- Documentation & communication for technical and non‑technical audiences.
- Proposal development and liaison with government acquisition stakeholders.
**Required Education & Certifications**
- MSc or BSc in Computer Science, Electrical/Software Engineering, Cybersecurity, or related discipline.
- No specific certifications required; knowledge of DoD and ISO standards is essential.