Cybersecurity Consultant (Discovery, Threat and Requirements)
Expleo · Bristol, England, United Kingdom
IT Services and IT Consulting · 10,001+ employees
About the role
You will lead discovery activities to establish an authoritative asset baseline and maintain the platform threat landscape for a major UK defence maritime programme. Additionally, you will capture security requirements and support risk assessments while ensuring traceability across all project artefacts.
What they look for
Requirements
Candidates should possess relevant cybersecurity certifications and experience in threat modelling, risk management, or information assurance. A background in defence, maritime, or critical national infrastructure environments is highly beneficial, along with the ability to obtain UK Security Check (SC) clearance.
Benefits
Full description
Overview
Expleo is a trusted partner for end-to-end, integrated engineering, quality services, and management consulting for digital transformation. We help businesses harness technological change to successfully deliver innovation, improve resilience and support secure, regulated and operationally critical environments.
As part of the Expleo UK Cybersecurity Practice, you will deliver the discovery, threat, risk and requirements activity that underpins the security case for a major UK defence maritime programme, supporting an autonomous surface vessel capability being matured towards a whole-ship system design review.
This is a delivery-focused consultancy role for someone methodical and evidence-driven. You will establish the asset baseline that everything else traces back to, contribute to the threat and risk picture, and capture the security requirements that the design team will build to.
You will work within a small, security-cleared team alongside a Secure by Design lead and a security architect, and directly with the client's design team, in an environment where accuracy, traceability and clear documentation carry real weight.
The role suits a cybersecurity consultant with a solid grounding in threat and risk methods and requirements work, who is looking to apply this in a technically demanding defence maritime programme.
Responsibilities
- Lead discovery activity across documentary, logical, interview and physical sources to establish an authoritative asset baseline.
- Populate and maintain the initial asset register, capturing asset class, criticality, ownership, configuration state, dependencies and interfaces.
- Establish and maintain the platform threat landscape by drawing on credible, up-to-date threat information.
- Contribute to threat modelling using recognised methods such as STRIDE and MITRE ATT&CK for Industrial Control Systems, expressed as attack paths.
- Support the preliminary security risk assessment using NIST SP 800-30 and ISO/IEC 27005, and maintain entries in the design risk register.
- Capture security requirements and maintain the traceability thread from threat to risk to control to requirement.
- Support security classification and criticality assessment across platform systems and information.
- Prepare clear, well-structured documentation and evidence packs suitable for design review and client acceptance.
- Support the compliance crosswalk of programme artefacts against applicable standards and assurance frameworks.
- Support security stakeholder meetings, capture actions and drive them to closure.
- Produce knowledge-transfer material to enable the client design team to maintain the artefacts across subsequent phases.
- Work collaboratively with colleagues in engineering, architecture, IT, OT, and assurance, and promptly escalate issues and risks.
Qualifications
- Relevant education or industry-recognised certifications in cybersecurity, information assurance, risk management or a related discipline.
- Suitable qualifications may include BSc, MSc, CompTIA Security+, CySA+, CISM, CISSP (or associate), ISO 27001 Lead Implementer/Lead Auditor, ISO 27005 risk, ISA/IEC 62443 Cybersecurity Fundamentals Specialist, or equivalent professional experience.
- Candidates working towards relevant certifications alongside strong practical experience are welcome to apply.
- Experience working within UK MOD, defence, maritime, shipbuilding, naval, critical national infrastructure or operationally critical environments would be highly beneficial.
Essential skills
- Working knowledge of threat modelling methods and the ability to express threats as credible attack paths.
- Understanding of both IT and operational technology environments and the different security considerations each carries.
- Awareness of MOD, NCSC or defence security frameworks and how they shape assurance evidence.
- Strong documentation skills, with the ability to produce accurate, well-structured and reviewable technical material.
- Methodical, detail-focused approach with a strong sense of ownership for the quality and traceability of evidence.
- Good stakeholder skills, with the ability to gather information effectively from engineers and system owners.
- Ability to work as part of a small, security-cleared delivery team to fixed milestones.
- A military or defence background, particularly in communications, information systems or security.
Experience
- Experience delivering cyber risk, assurance or security requirements work on technical programmes.
- Experience contributing to threat assessments, threat models or risk assessments for complex systems.
- Experience producing security documentation and evidence for review by clients, assessors or regulators.
- Experience working alongside engineering or design teams in a multi-disciplinary environment.
- Experience of regulated, safety-critical or operationally critical delivery environments.
- Experience handling sensitive defence or client information in line with UK MOD, NCSC, client security and data protection requirements.
- Practical cybersecurity consultancy experience in defence, maritime, critical national infrastructure or another regulated or operationally critical environment.
- Experience conducting discovery and building or maintaining asset registers or configuration baselines.
- Experience supporting security risk assessment using recognised methods such as NIST SP 800-30 or ISO/IEC 27005.
- Experience capturing security requirements and maintaining traceability to threat, risk and control.
- Experience with marine or vessel systems, or with defence communications and information systems.
- TEMPEST awareness, or experience of emanation security assurance to NATO standards.
- Experience with IEC 62443, NCSC CAF, MOD Secure by Design, ISO 27001 or Def Stan 05-138.
- Experience of autonomous, uncrewed or remotely operated systems.
- Experience supporting design reviews or formal assurance gates.
- Experience with requirements management or traceability tooling.
What do I need before I apply
- Have the right to work in the UK.
- Hold, or be eligible to obtain, UK Security Check (SC) clearance. Clearance is a mandatory requirement for this programme, and applicants must meet the UK residency criteria for security clearance.
- Be willing and able to work in a hybrid model, including client site attendance as required.
- Be comfortable working within secure collaboration environments and handling information marked up to OFFICIAL-SENSITIVE.
- Be able to work under the terms of applicable confidentiality and non-disclosure arrangements.
Benefits
- Collaborative working environment – we stand shoulder to shoulder with our clients and our peers through good times and challenges
- We empower all passionate technology loving professionals by allowing them to expand their skills and take part in inspiring projects
- Expleo Academy - enables you to acquire and develop the right skills by delivering a suite of accredited training courses
- Competitive company benefits
- Always working as one team, our people are not afraid to think big and challenge the status quo
- As a Disability Confident Committed Employer we have committed to:
- Ensure our recruitment process is inclusive and accessible
- Communicating and promoting vacancies
- Offering an interview to disabled people who meet the minimum criteria for the job
- Anticipating and providing reasonable adjustments as required
- Supporting any existing employee who acquires a disability or long term health condition, enabling them to stay in work at least one activity that will make a difference for disabled people
“We are an equal opportunities employer and welcome applications from all suitably qualified persons regardless of their race, sex, disability, religion/belief, sexual orientation or age”.
We treat everyone fairly and equitably across the organisation, including providing any additional support and adjustments needed for everyone to thrive