Product Security Engineer

Endeavour Recruitment

Product Security Engineer

Location: Chertsey, Surrey

Salary: Up to £70,000 per annum

This is a hybrid role requiring a minimum of 2 days per week onsite in Chertsey, with the expectation of up to 5 days per week onsite – project dependant.

Due to the nature of the work and security clearance requirements, applications will only be considered from UK nationals who have been British citizens from birth. Candidates must also be eligible to obtain UK Security Clearance (SC).

We are seeking an experienced Product Security Engineer to join our engineering team, supporting the delivery of secure, high-assurance products within the defence sector. This is an excellent opportunity to work on technically challenging projects where security is embedded throughout the product lifecycle using Secure by Design (SbD) principles.

The Role

Reporting to the Supportability Engineering Functional Lead, you will play a critical role in supporting multiple projects throughout the product lifecycle, ensuring Product Security Assurance activities and associated artefacts meet customer and regulatory requirements.

Working closely with engineering, product development and quality teams, you will integrate Secure by Design principles to minimise cyber vulnerabilities and reduce the risk of system abuse or exploitation.

Key Responsibilities

  • Conduct Product Security risk analysis and assessments.
  • Develop and maintain Product Security documentation and assurance artefacts.
  • Ensure security deliverables comply with customer and contractual requirements.
  • Develop and implement Product Security policies and processes.
  • Contribute security effort estimates during the bid process.
  • Chair internal and external Product Security reviews and working groups.
  • Support engineering teams in embedding Secure by Design principles throughout product development.
  • Provide additional support across the wider Supportability function as required.

Essential Skills & Experience

  • Experience planning and implementing Product Security activities (e.g. NIST SP 800 series).
  • Experience producing project security documentation using Secure by Design principles.
  • Knowledge of Security/Information Assurance standards and guidance (e.g. CESG Good Practice Guides).
  • Experience conducting security risk assessments using recognised methodologies (e.g. NCSC).
  • Strong understanding of security assurance within complex engineering or defence environments.
  • Excellent written and verbal communication skills.
  • Strong Microsoft Office skills.
  • Ability to work independently while collaborating effectively within multidisciplinary teams.
  • Flexible and adaptable, with the ability to respond to changing project demands.
  • Eligible to obtain UK Security Clearance (SC).

Desirable Skills

  • Risk Management.
  • DevSecOps.
  • Electromagnetic Compatibility (EMC).
  • TEMPEST.
  • Familiarity with Defence Security Standards including Def Stan 05-138, Def Stan 05-139, JSP440 and the Security Policy Framework.

Previous experience within Defence, the Ministry of Defence, Armed Forces or defence contracting.

Apply Now →

Application opens at the source listing. Free for jobseekers.