Cybersecurity Consultant (Discovery, Threat and Requirements)

Expleo is a trusted partner for end-to-end, integrated engineering, quality services, and management consulting for digital transformation. We help businesses harness technological change to successfully deliver innovation, improve resilience and support secure, regulated and operationally critical environments.

As part of the Expleo UK Cybersecurity Practice, you will deliver the discovery, threat, risk and requirements activity that underpins the security case for a major UK defence maritime programme, supporting an autonomous surface vessel capability being matured towards a whole-ship system design review.

This is a delivery-focused consultancy role for someone methodical and evidence-driven. You will establish the asset baseline that everything else traces back to, contribute to the threat and risk picture, and capture the security requirements that the design team will build to.

You will work within a small, security-cleared team alongside a Secure by Design lead and a security architect, and directly with the client's design team, in an environment where accuracy, traceability and clear documentation carry real weight.

The role suits a cybersecurity consultant with a solid grounding in threat and risk methods and requirements work, who is looking to apply this in a technically demanding defence maritime programme.

  • Lead discovery activity across documentary, logical, interview and physical sources to establish an authoritative asset baseline.
  • Populate and maintain the initial asset register, capturing asset class, criticality, ownership, configuration state, dependencies and interfaces.
  • Establish and maintain the platform threat landscape by drawing on credible, up-to-date threat information.
  • Contribute to threat modelling using recognised methods such as STRIDE and MITRE ATT&CK for Industrial Control Systems, expressed as attack paths.
  • Support the preliminary security risk assessment using NIST SP 800-30 and ISO/IEC 27005, and maintain entries in the design risk register.
  • Capture security requirements and maintain the traceability thread from threat to risk to control to requirement.
  • Support security classification and criticality assessment across platform systems and information.
  • Prepare clear, well-structured documentation and evidence packs suitable for design review and client acceptance.
  • Support the compliance crosswalk of programme artefacts against applicable standards and assurance frameworks.
  • Support security stakeholder meetings, capture actions and drive them to closure.
  • Produce knowledge-transfer material to enable the client design team to maintain the artefacts across subsequent phases.
  • Work collaboratively with colleagues in engineering, architecture, IT, OT, and assurance, and promptly escalate issues and risks.
  • Relevant education or industry-recognised certifications in cybersecurity, information assurance, risk management or a related discipline.
  • Suitable qualifications may include BSc, MSc, CompTIA Security+, CySA+, CISM, CISSP (or associate), ISO 27001 Lead Implementer/Lead Auditor, ISO 27005 risk, ISA/IEC 62443 Cybersecurity Fundamentals Specialist, or equivalent professional experience.
  • Candidates working towards relevant certifications alongside strong practical experience are welcome to apply.
  • Experience working within UK MOD, defence, maritime, shipbuilding, naval, critical national infrastructure or operationally critical environments would be highly beneficial.

Job Details

Company
Expleo UK LTD
Location
Bristol, United Kingdom
Employment Type
Permanent
Posted