Hiring.Camp

Security Architect (OT, IT, Network and Physical)

Expleo Gb En

·

Today

Location
Bristol, ENG, GB
Department
IT
Closing date
Today
Source
iCIMS

Description

Overview

Expleo is a trusted partner for end-to-end, integrated engineering, quality services, and management consulting for digital transformation. We help businesses harness technological change to successfully deliver innovation, improve resilience and support secure, regulated and operationally critical environments.

As part of the Expleo UK Cybersecurity Practice, you will define and ensure the security architecture for a major UK defence maritime programme, supporting an autonomous surface vessel capability that is being matured towards a whole-ship system design review.

This is a hands-on architecture role for an engineer who is comfortable designing across operational technology, IT, networks, and physical security, and who can serve as a design lead to naval architects, systems engineers, a digital system integrator, and subsystem owners. Because the platform is designed to operate crewless, the architecture must be fail-safe under compromise and maintain a defined minimum-risk state upon loss of the remote command-and-control link.

You will own the security architecture and the asset baseline that underpins it, working to the Security Management Plan set by the Secure by Design lead and providing architectural evidence to support formal design review.

The role requires strong secure-by-design architectural skills, deep IT and OT understanding, and the ability to translate risk and consequences into segmentation, controls, and defensible design decisions.

Responsibilities

  • Develop the security architecture for OT and IT in coordination with the digital system integrator and sub-system owners, and produce the preliminary security architecture design.
  • Partition the platform into zones and conduits in accordance with IEC 62443, setting target security levels based on safety and mission consequences.
  • Review the network architecture and communications security, and provide advice, including on the resilience of remote command-and-control links and of position, navigation, and timing.
  • Produce the network security architecture in coordination with the digital teams.
  • Review the physical security provision in the design and develop appropriate protection measures, producing the physical security design in coordination with the arrangement team.
  • Define trust boundaries, segregation, secure configuration baselines, identity and access management, and secure remote access requirements for shipboard and supporting systems.
  • Build and structure the initial asset register for configuration control, capturing criticality, zone, ownership and dependency attributes.
  • Support threat modelling and security risk assessment from an architecture perspective, and translate assessed risk into architectural controls.
  • Define architecture-level security requirements and maintain their traceability into the wider requirements specification.
  • Assure that architectural controls are fail-safe and do not defeat safety functions, working alongside safety and engineering colleagues.
  • Provide architectural evidence and materials for internal and external design reviews, including system design reviews, and close out resulting actions.
  • Contribute to supplier and interface security requirements where these bear on the architecture, including third-party payload and control-system interfaces.
  • Produce clear high- and low-level design material, architecture views, decision records and design rationale suitable for technical scrutiny.

Qualifications

  • Relevant education or industry-recognised certifications in security architecture, cybersecurity, secure engineering, operational technology security or a related discipline.
  • Suitable qualifications may include BSc, MSc, CISSP, CISM, CRISC, CCP, ISA/IEC 62443 (Fundamentals Specialist, Risk Assessment Specialist, Design Specialist or Expert), SABSA, TOGAF, CCNP, OSCP, ISO 27001 Lead Implementer/Lead Auditor or equivalent professional experience.
  • Experience working within UK MOD, defence, maritime, shipbuilding, naval, critical national infrastructure or operationally critical environments would be highly beneficial.

Essential skills

  • Demonstrable application of IEC 62443, including zones and conduits, target security levels, and 62443-3-2 style risk assessment.
  • Strong understanding of secure configuration baselines, hardening, identity and access management and privileged access for OT environments.
  • Understanding of secure industrial and platform communications, including relevant protocols, cryptographic protection and public key infrastructure.
  • Ability to translate risk and consequence into proportionate architectural controls, and to defend those decisions in technical forums.
  • Ability to work across engineering, architecture, platform, IT, OT, assurance and supply chain teams.
  • Strong written and verbal communication skills, with the ability to produce precise technical design material.
  • TEMPEST awareness, particularly as it relates to defence standards and secure design.

Experience

  • Proven experience as a security architect, OT security architect, or secure engineering specialist on complex technical programmes.
  • Experience supporting defence, maritime, naval, energy, rail, manufacturing or other critical national infrastructure environments.
  • Experience developing enterprise or platform OT security reference architectures.
  • Experience of multi-site or multi-system IT and OT segmentation programmes.
  • Experience with asset discovery and inventory tooling, and with passive-first approaches in sensitive operational environments.
  • Experience supporting factory acceptance testing, site acceptance testing, integration testing or equivalent technical validation from a security perspective.
  • Experience working alongside system integrators and sub-system suppliers to land architectural requirements.
  • Experience developing security architecture in environments where safety and availability constraints shape the design.
  • Experience handling sensitive defence or client information in line with UK MOD, NCSC, client security and data protection requirements.
  • Strong experience in a security architecture role covering both operational technology and IT environments.
  • Experience designing network segmentation, industrial demilitarised zones, trust boundaries and secure remote access for operational environments.
  • Experience securing industrial control systems, embedded or platform control systems, and safety-related control environments.
  • Experience producing security architecture documentation, including high- and low-level designs, architecture views and design rationale.
  • Experience building or structuring asset inventories and registers to support configuration control and risk assessment.
  • Experience contributing security architecture into formal engineering design reviews and assurance gates.
  • Experience with shipboard systems, platform systems, mission systems, navigation, propulsion, power management or similar complex operational environments.
  • Awareness of maritime cyber engineering benchmarks such as IACS Unified Requirements E26 and E27.
  • Experience with autonomous, uncrewed or remotely operated platforms, including command-and-control link protection and position, navigation and timing resilience.
  • Experience with data diodes, unidirectional gateways or equivalent high-assurance boundary protection.
  • Experience with MOD Secure by Design, NCSC CAF, NIST SP 800-82, ISO 27001 or Def Stan 05-138.
  • Experience of physical and electronic security convergence, including protection of equipment spaces and cable routes.

What do I need before I apply

  • Have the right to work in the UK.
  • Hold, or be eligible to obtain, UK Security Check (SC) clearance. Clearance is a mandatory requirement for this programme, and applicants must meet the UK residency criteria for security clearance.
  • Be willing and able to work in a hybrid model, including client site attendance as required.
  • Be comfortable working within secure collaboration environments and handling information marked up to OFFICIAL-SENSITIVE.
  • Be able to work under the terms of applicable confidentiality and non-disclosure arrangements.

Benefits

  • Collaborative working environment – we stand shoulder to shoulder with our clients and our peers through good times and challenges
  • We empower all passionate technology loving professionals by allowing them to expand their skills and take part in inspiring projects 
  • Expleo Academy - enables you to acquire and develop the right skills by delivering a suite of accredited training courses 
  • Competitive company benefits
  • Always working as one team, our people are not afraid to think big and challenge the status quo

 

  • As a Disability Confident Committed Employer we have committed to:
    • Ensure our recruitment process is inclusive and accessible
    • Communicating and promoting vacancies
    • Offering an interview to disabled people who meet the minimum criteria for the job
    • Anticipating and providing reasonable adjustments as required
    • Supporting any existing employee who acquires a disability or long term health condition, enabling them to stay in work at least one activity that will make a difference for disabled people

 

“We are an equal opportunities employer and welcome applications from all suitably qualified persons regardless of their race, sex, disability, religion/belief, sexual orientation or age”. 

 

We treat everyone fairly and equitably across the organisation, including providing any additional support and adjustments needed for everyone to thrive

 

Skills

CybersecurityISO 27001CISSP

Similar Jobs

4

OT Security Architect

Deloitte Netherlands · Amsterdam, NH, Netherlands · Hybrid

1 month ago

OT Security Architect

Firstquality · Home Office (GA), United States of America +3 · Remote

5 months ago

OT Security Architect (all genders)

Meteocontrol

3 months ago

Global OT Security Architect – Identity & Networks

Trafigura · Madrid - Impala Office, Spain

6 months ago