- Company Name
- General Dynamics UK Limited
- Job Title
- Security Engineer (Contractor)
- Job Description
-
**Job title**
Security Engineer (Contractor)
**Role Summary**
Support technical project teams in designing, documenting, and ensuring security compliance for defence‑grade systems. Provide security authority, produce security design artifacts, conduct risk mitigation, and facilitate accreditation and testing activities across the project lifecycle.
**Expectations**
- Acquire and maintain the appropriate level of UK Security clearance.
- Deliver security deliverables on schedule within contractual obligations.
- Act as the security authority for projects, integrating security throughout engineering decisions.
- Maintain audit‑ready documentation and evidence for accreditation bodies.
**Key Responsibilities**
1. Collaborate with Technical Project Managers and Solution Design Team to create required security deliverables.
2. Offer security guidance to ensure security is embedded in all engineering decisions.
3. Generate, maintain, and trace project‑level security documentation and design artifacts.
4. Provide assurance for all security outputs and ensure alignment with accreditation risk appetite.
5. Develop and implement Model‑Based System Engineering security architectures and open‑architecture solutions.
6. Produce a coherent, layered security architecture integrating with system design.
7. Identify risks, propose mitigations, and keep issues within the accreditors’ risk appetite.
8. Coordinate with customer security representatives, creating artefacts for SyTLMs.
9. Trace security design to requirements and support secure configuration and integration.
10. Work with design and test teams to confirm compatibility and provide evidence from security functional tests.
**Required Skills**
- Hands‑on experience with Model‑Based System Engineering.
- Ability to develop and implement open‑architecture, layered security designs.
- Strong knowledge of defence security architectural frameworks (Infosec Standard 1&2, ISO27001, NIST SP 800‑53, NIST Cybersecurity Framework, NATO CI Agency standards, BS ISO/IEC 27001:2013, etc.).
- Experience in large, complex systems across all project lifecycle phases, including security design, accreditation, and support.
- Proven track record in risk identification, mitigation, and documentation for accreditation.
- Excellent written and verbal communication for producing security deliverables and liaising with stakeholders.
- Familiarity with secure configuration and integration activities, and security functional testing.
**Required Education & Certifications**
- Relevant university degree in Computer Science, Cybersecurity, Defence Engineering, or related field.
- Certifications: ISO/IEC 27001 Lead Implementer/Lead Assessor or equivalent (e.g., SABSA, COBIT, NIST frameworks).
- Demonstrated compliance experience with at least one listed security architectural framework (e.g., NIST SP 800‑53, NIS Directive, Infosec Standard 1&2).
- UK Security clearance (level appropriate for defence contracting).