Skip to main content
C

Senior Cyber Security Engineer

Chippenham
1 hour ago
Full-time
On-site
Chippenham, Wiltshire
£600 - £600 GBP daily
Security
We are looking for a Senior Cyber Security Engineer (Assurance) to join a Rail Infrastructure Communication and Information Systems (CIS) business. The role is flexible in location, with weekly face-to-face working required in Chippenham or Ashby de la Zouch, UK.

The Role

As a Senior Cyber Security Engineer (Assurance), you will provide technical leadership across product and whole-solution security within Operational Technology (OT) environments. You will lead and advise on cyber security activities throughout the engineering lifecycle, from bid and design through to commissioning and support.
You will play a key role in securing rail signalling and control systems, electrification, SCADA, and station information and security systems.

Key Responsibilities

Engage with customer security teams to understand security strategies, assurance requirements and risk appetite.

Define and maintain security requirements and support compliance with NIS/NIS2, EU CRA, IEC 62443 and TS 50701.

Develop Cyber Security Management Plans and monitor delivery against time, cost and quality.

Develop secure architectures using zones and conduits, identifying appropriate security controls.

Lead threat and risk assessments, defining appropriate countermeasures in line with risk acceptance criteria.

Assess third-party components against product and solution security requirements.

Review security engineering artefacts and verify implementation through system, factory and site acceptance testing.

Plan and support security validation, including penetration testing, vulnerability identification and remediation assessment.

Support project teams in developing product and solution security capabilities and represent security engineering at milestone and stage-gate reviews.

Contribute to vulnerability and incident response, lessons learned and continuous improvement.

Maintain awareness of emerging technologies, cyber risks, threats and relevant standards.

Qualifications, Skills & Experience

Degree or equivalent qualification in engineering, science or a numerate discipline.

Proven experience providing security engineering leadership within demanding Operational Technology environments.

Practical experience applying the IEC 62443 standard series and an understanding of CENELEC standards.

Experience with security assurance, risk assessment, architecture and security testing.

Experience mentoring and developing engineers.

Excellent communication and stakeholder management skills, with the ability to influence internal and external stakeholders.

Preferably hold one or more of: CISSP, CSSLP or CESG Certified Professional (CCP)