National AI Awards 2025Discover AI's trailblazers! Join us to celebrate innovation and nominate industry leaders.

Nominate & Attend

Chief Product Security Engineer

Leonardo SpA
Bristol
5 months ago
Applications closed

Related Jobs

View all jobs

Chief Product Security Engineer

Chief Product Security Engineer

IT Security Engineering Manager

Chief Information Security Officer

Principal Security Architect

Network Security Engineer - London

Job Description:

The opportunity:

At Leonardo, we have a fantastic opportunity for a Chief Product Security Engineer to join our team within the Customer Support and Service Solutions (CS3) line of business. CS3 operates across the UK, providing innovative and invaluable support solutions to our customers. We help to ensure the availability of front-line capability wherever and whenever required.

We are looking for an experienced product security practitioner with expertise in developing and maintaining robust product security management systems for defence and government customers.

Within CS3, the term product can be used to include both in-service equipment, and the support solutions/services provided to customers, which in themselves are developed. The Chief Product Security Engineer will take responsibility for ensuring that all security aspects of the design, development, verification and maintenance of this range of products, through all phases of their lifecycle, have been completed in accordance with policy and process. They will work closely with the development teams to provide guidance in the design, implementation and maintenance of appropriate security controls.

What you'll do as a Chief Product Security Engineer:

  • Provide security advice and support to product development teams, including in terms of:
    • Deriving security requirements
    • Undertaking security risk assessments for products
    • Preparing security risk mitigation plans
    • Review and approval of Security Management plans
  • Security policy maintenance and monitoring
  • Production of LoB security metrics
  • Management of attendance at external security forums
  • Attendance and support to the Security Special Interest Group
  • Lead security incident management teams during incident/crisis situations in conjunction with the Lead Product Security Engineer(s)


The Chief Product Security Engineer has delegated authority within the independent Design Integrity function, responsible for the following elements:

  • Security process maintenance and monitoring
  • Security competence framework maintenance and monitoring
  • Assessment of security competence in line with the competency framework
  • Chair and maintenance of a LoB security Community of Interest (CoI)
  • Promoting and sharing knowledge and best practice across the division to improve product security awareness and help embed it within ways of working
  • Training the engineering teams with respect to the security framework, policies and processes


We would like to hear from you if you have a combination of the following:

  • Demonstrated experience of developing robust security risk management systems for a range of pan domain products and services in accordance with customer, regulatory and legislative expectations.
  • Familiarity with Legislation - e.g. IPA, DPA, Official Secrets Act
  • Registered NCSC Certified Professional at lead level, or equivalent NCSC recognised qualification.
  • Knowledge of UK/NATO Information Assurance standards, procedures & systems, including HMG Security Policy Framework, ISO security standards, RTCA DO326A.
  • Familiarity with the principles of incident investigation and knows how to implement an investigation process;
  • Practical experience of NCSC and Common Criteria security evaluation techniques and requirements up to High Grade.
  • Knowledge of current Crypto technologies, Key Management Systems & practical COMSEC implementations.
  • Experience of identifying the future Product Security needs of the company, regularly delivering training courses within a corporate environment and delivering awareness presentations to other groups.
  • Awareness of product security implications relating to safety
  • Excellent communication and interpersonal skills, with the ability to interact with a number of stakeholders from subject matter experts to senior leaders, regarding a wide range of technical and operational topics.
  • Good understanding and experience in delivery and maintenance of products to meet regulatory requirements, for example MAA DAOS, ARP4754
  • Understanding of the concept of operations for products, in order to understand the functional security risks and define/agree the appropriate mitigations
  • Ability to identify and deliver alternative/innovative ways to manage security, including ensuring buy-in from key regulatory bodies
  • Understanding of the role of advisory boards within the UK Government or NATO for security.
  • Active membership of an external security specialist group or forum


Security Clearance

You must be eligible for full security clearance. For more information and guidance please visit :https://www.gov.uk/government/publications/united-kingdom-security-vetting-clearance-levels

Life at Leonardo

With a company funded benefits package, a commitment to learning and development, and a flexible approach to working hours focused on the needs of both our employees and customers, a career with Leonardo has never offered as many opportunities or been more accessible to as many people.

Flexible Working:Flexible hours with hybrid working options. For part time opportunities, please talk to us

Company funded flexible benefits:Access to private healthcare, dental schemes, Workplace ISA, Go Green Car Scheme, technology and lifestyle options (£500 annual allowance)

Holidays:25 days plus bank holidays, option to buy/sell leave and to accrue up to 12 additional flexi leave days per year

Pension:Award winning pension scheme (up to 15% employer contribution)

Wellbeing:Employee Assistance Programme with access to free mental health support, financial wellbeing support and network groups to demonstrate our ongoing commitment to diversity & inclusion (Enable, Pride, Equalise, Reservists, Carers)

Lifestyle:Discounted Gym membership, Cycle to work scheme

Training:Free access to more than 4000 online courses via Coursera

Referral Incentive:You can earn a reward for successfully referring a friend or family member

Bonus:Scheme in place for all employees at management level and below

For a full list of our Company benefits please visit our website.

Leonardo is a global high-tech company and one of the key players in Aerospace, Defence and Security. Headquartered in Italy, Leonardo has over 45,000 employees, of which 8,000 are based at 8 sites throughout the UK.

At Leonardo UK, we believe that a diverse and inclusive work environment unlocks our people's full potential and drives innovation and creativity. We work hard to offer a welcoming, accessible and inclusive place to work for all of our people, creating a culture where everyone can thrive, feel safe and have a sense of belonging and connection.

This is a great opportunity to bring your talents and form an integral part of Leonardo's future. We can help you develop your skills and offer great opportunities to develop and grow, so why not join us.

Primary Location:
GB - Bristol - Coldharbour Lane

Additional Locations:
GB - Basildon, GB - Edinburgh, GB - Luton - Cap. Green 300, GB - Newcastle, GB - Southampton

Contract Type:

Hybrid Working:
Hybrid#J-18808-Ljbffr

National AI Awards 2025

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

How to Find Hidden Cyber Security Jobs in the UK Using Professional Bodies like BCS, CIISec & More

The demand for skilled cyber security professionals in the UK has never been higher. With threats increasing in sophistication and frequency, organisations are urgently hiring ethical hackers, threat analysts, GRC specialists, and security architects. But many of the most valuable roles—particularly in government, defence, and critical infrastructure—are never publicly advertised. Instead, these jobs are shared behind the scenes through trusted networks, private communities, and professional bodies. In this article, we explore how to uncover hidden cyber security jobs in the UK using organisations like the BCS (The Chartered Institute for IT), CIISec (The Chartered Institute of Information Security), ISACA, and ISC² UK Chapter. We’ll show you how to use membership directories, special interest groups, CPD events and informal networks to gain early access to roles most people never see.

How to Get a Better Cyber Security Job After a Lay-Off or Redundancy

Redundancy is never easy—especially in a fast-moving field like cyber security, where your skills and experience are constantly evolving. But if you’ve recently been made redundant from a cyber security role, know this: the UK cyber workforce remains in high demand, and your expertise is more valuable than ever. Whether you’re a SOC analyst, penetration tester, incident responder, security architect or GRC specialist, there are still thousands of opportunities across sectors including finance, defence, government, retail, and critical infrastructure. This guide will help you turn redundancy into a career relaunch, with a clear action plan tailored to the UK cyber security job market.

Cyber Security Jobs Salary Calculator 2025: Check Your Market Value in Seconds

Why yesterday’s pay survey no longer protects you. “Could I earn more at a managed SOC?” “Is that fintech’s offer really competitive?” Every UK cyber‑security professional asks some version of those questions—usually after another colleague lands a pay rise, a recruiter sends a tempting JD, or a fresh breach makes headline news. Yet salary guides published even last year feel as out‑of‑date as a forgotten antivirus signature. Since 2024, ransomware gangs switched to double‑extortion, deepfake phishing exploded, & the EU’s NIS2/DORA regulations bled into UK contracts despite Brexit. With each shift, salary bands move. To cut through stale averages, CybersecurityJobs.tech distilled a three‑factor formula that lets you estimate a realistic 2025 salary in under a minute. Feed in your role, your UK region, & your seniority level. The output arms you with data‑driven leverage for your next appraisal, job application, or freelance rate card. This article explains the formula, reveals the forces pushing cyber pay ever higher, & outlines five practical moves to boost your market value within ninety days.