Key Responsibilities
- Act as the cyber security lead across complex rail infrastructure and OT projects.
- Engage with client security teams to understand security strategies, risk appetite, assurance requirements, and compliance obligations.
- Develop and maintain cyber security requirements throughout the project lifecycle.
- Produce and manage Cyber Security Management Plans, ensuring delivery against agreed timescales, budget, and quality objectives.
- Lead security risk assessments, threat modelling exercises, and mitigation planning.
- Develop secure architectures using zoning and conduit principles to protect critical systems and networks.
- Assess third-party products and components against security requirements.
- Review and approve cyber security evidence and assurance documentation.
- Define security verification and validation strategies, including factory testing, site acceptance testing, and penetration testing activities.
- Support investigation and response activities relating to cyber vulnerabilities and incidents.
- Contribute to continuous improvement initiatives and lessons learned programmes.
- Provide technical leadership, mentoring, and security guidance to project teams and junior engineers.
What We're Looking For
- Strong cyber security engineering experience within Operational Technology (OT) or industrial control environments.
- Proven experience delivering security assurance on complex engineering or infrastructure projects.
- Practical experience applying the IEC 62443 standards framework.
- Experience performing threat and risk assessments.
- Knowledge of security architecture principles, including network segmentation, zoning, and conduits.
- Experience developing security requirements and assurance artefacts.
- Ability to engage effectively with customers, engineering teams, and senior stakeholders.
- Degree-qualified (or equivalent experience) in Engineering, Computer Science, Cyber Security, or a related discipline.
Desirable Experience
- Knowledge of UK rail systems and infrastructure projects.
- Experience applying CENELEC standards.
- Understanding of:
- NIS / NIS2
- EU Cyber Resilience Act (CRA)
- TS 50701
- Previous experience working within regulated or safety-critical industries such as:
- Rail
- Energy
- Utilities
- Defence
- Industrial Automation
Professional Certifications
- The following certifications would be advantageous:
- CISSP (Certified Information Systems Security Professional)
- CSSLP (Certified Secure Software Lifecycle Professional)
- CCP (CESG Certified Professional)
Location:
Ashby-De-La-Zouch
IR35 Status:
Not specified