Senior Cybersecurity Consultant (Secure by Design Lead)
Expleo is a trusted partner for end-to-end, integrated engineering, quality services, and management consulting for digital transformation. We help businesses harness technological change to successfully deliver innovation, improve resilience and support secure, regulated and operationally critical environments.
As part of the Expleo UK Cybersecurity Practice, you will lead the delivery of product security, cyber assurance and secure-by-design activity for a major UK defence maritime programme, supporting an autonomous surface vessel capability being matured towards a whole-ship system design review.
This is a senior, client-facing role requiring strong cybersecurity leadership, defence assurance experience, maritime or shipbuilding awareness, and the ability to embed security into complex engineering, platform, IT and OT environments. The platform is designed to operate crewless, which shifts the security centre of gravity from information confidentiality towards the safety and availability of operational technology, and makes the remote command-and-control link and position, navigation, and timing resilience the assets that matter most.
You will act as the cyber authority within the client's integrated design team, owning the Security Management Plan and the coherence of the wider security artefact set, and directing the work of a security architect and a cybersecurity consultant. The role sits at the intersection of naval architecture, systems engineering, product security, information assurance and MOD/maritime cyber compliance.
The role requires a strong blend of cybersecurity leadership, secure engineering, technical assurance, stakeholder management, governance, supplier oversight and defence regulatory experience. You will need to operate with autonomy, technical credibility and the ability to provide clear decision support to senior leaders.
- Own and maintain the Security Management Plan covering OT, IT and physical security, including the assurance and acceptance strategy, management of the supply chain and the route to demonstrating secure by design in accordance with UK MOD requirements.
- Act as the senior security authority within the client's integrated design team, providing direction, challenge and assurance across engineering and delivery activity.
- Develop the threat assessment and a proposed security risk appetite for agreement, in lieu of customer-supplied statements.
- Lead the preliminary security risk assessment and manage design risk exposure, proportionate to the design's maturity, through a live design risk register owned by and reported to the client delivery team.
- Produce the preliminary specification of security requirements and appropriate standards for OT, IT and physical security, including security classification and criticality assessment.
- Maintain traceability from threat to risk to control to requirement, so that every security requirement is justified and evidenced.
- Define supplier and supply chain security requirements and ensure they are embedded in specifications, delivery expectations and technical acceptance criteria.
- Review and assess supplier security deliverables, including security claims, compliance evidence, technical designs, assurance artefacts and software bills of materials.
- Direct and quality-assure the work of the security architect and cybersecurity consultant, ensuring the artefact set is coherent, traceable and defensible.
- Provide security input to formal engineering design reviews, including system design reviews and equivalent programme governance gates, prepare and present material, and close out resulting actions.
- Manage meetings with security stakeholders and represent the security position to senior client stakeholders and independent technical governance.
- Apply relevant MOD, NCSC, defence and maritime security frameworks to support assurance, accreditation and compliance activities, and reconcile the security position with the platform safety case.
- Generate a detailed scope of work for subsequent programme phases, and an outline scope for later phases.
- Produce clear technical assurance outputs, security design material, decision papers, risk statements, briefing notes and governance updates.
- Work independently as a senior subject matter expert, determining the day-to-day technical approach, stakeholder engagement and assurance rhythm required to achieve agreed outcomes.
- Relevant education or industry-recognised certifications in cybersecurity, information assurance, secure engineering, security architecture, risk management or a related discipline.
- Suitable qualifications may include BSc, MSc, CISSP, CISM, CRISC, CISA, CCP, ISO 27001 Lead Implementer/Lead Auditor, Security+, CySA+, SABSA, TOGAF, IEC 62443, NCSC CAF-related experience or equivalent professional experience.
- Experience working within UK MOD, defence, maritime, shipbuilding, naval, critical national infrastructure or operationally critical environments would be highly beneficial.