Principal Cyber Security Architect ( R-00085620 )
DescriptionJob Description:Principal Cyber Security Architect
Level: T5Are you ready to make an impact?..
We are in search of a Principal Cyber Security Architect to join our team based at our Skypark office in Glasgow.
Are you ready for your next career challenge?
At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers’ success. We empower our teams in the UK to address some of the most complex problems in defence, government, safety and security, and transportation. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community. Our Mission, Vision, and Values guide the way we do business.
If this sounds like the kind of environment where you can thrive, keep reading!
- As a Principal Security Architect you will be able to work with minimal direction on a range of large and small programmes that deliver IT transformation and new services capabilities. You will ensure that the solution security design meets the customer functional and non-functional security requirements and provides the necessary assurance to our client, highly likely to be backed up by rigorous accreditation and certification processes, normally HMG standards (including MOD-specific JSP) alongside ISO27001
- You will have responsibility for interfacing to security design partners across programmes, both customer and supplier representatives, and colleagues within our engineering, service, and business development teams. You will ensure that Leidos can establish and maintain an effective and efficient security architecture for a programme, and that the designs will be able to adapt as customer requirements, legislation and accreditation standards change over a programme lifespan
- Within a programme, the role will primarily be responsible to a solution architect for developing and delivering the relevant elements of a solution, whilst understanding the whole. You will be required to work in both delivery and proposal environments. You may be required to work on multiple programmes at the same time and these may include bids, implementation of new systems and transformation of existing systems
- You will have a complete understanding of cyber risk and treatment approaches. Based on a strong ability to communicate risk and its proportionate management, you will know how this issue is addressed both in traditional ‘off-cloud’ highly sensitive platforms, and naturally in cloud technologies. You will be experienced and accomplished in meeting the challenges associated with accrediting systems in public and private cloud environments
- You will be required to develop high and low level security architecture designs for systems intended for secure/sensitive environments, with appropriate security based on detailed risk analysis. SABSA qualifications and experience would be desirable
- The Leidos client base includes a number of national government departments and arms-length bodies, local authorities and providers of critical national infrastructure. We take our security obligations very seriously and will ensure there is a strong security component to all our proposals, and will be able to demonstrate a sound security operation is enabled by the solution we design for our clients. You will be required to hold security clearance under National Security Vetting and Police processes
- You may need to work on customer locations or one of our secure development locations, or a mix of both, as well as an element of working from home
- Experience of a taking a defence in depth and multi layered approach to security architecture
- Experience of applying commensurate detective and protective security controls to reduce risk to an acceptable level
- Understanding of the controlling processes for, and experience of a significant portion of, the systems engineering lifecycle (e.g. requirements management, configuration management)
- Understanding of different lifecycles/methodologies (waterfall, incremental, agile, DevOps)
- Experience of the key engineering lifecycle reviews – e.g. System Requirements Review (SRR), Critical Design Review (CDR)
- Experience in performing design trade off working with other architects and engineers to deliver an integrated and coherent solution
- Understanding of service operations and security operational management planning
- Experience working in both delivery and proposal environments
- Experience of Defence Digital and relevant solutions and approaches across MOD
- Excellent understanding of Confidentiality, Integrity and Availability (CIA) and practical experience in applying that
- Experience in defining derived security requirements for a system, and managing traceability
- Experience of gaining and maintaining accreditation for secure/sensitive systems
- Experience in producing security documentation sets (such as SyOPS, RMADs, Security Management Plan, ISMS and DART submissions)
- Understanding of the implementation, operation and maintenance of SIEM products
- Understanding of network and boundary protection technologies (firewalls, mail gateways, load balancers, anti-virus)
- Understanding of authentication and authorisation technologies (SAML, LDAP, PKI, etc)
- Understanding of security infrastructure in Public and Private cloud, e.g. virtual network infrastructure, hybrid IaaS/PaaS/SaaS solutions
- The ideal candidate will hold CISSP certification in addition to SABSA qualification
Communication and Soft Skills:
- Excellent verbal and written communication skills and works well in a team environment
- Capable of developing and communicating a vision to meet the System Requirements
- Ability to communicate complex technical ideas across a wide range of different audiences
- A good level of commercial awareness that will support the bid and delivery environments
- Clearance to Start SC
- Clearance for Role SC
- British - Non-dual national – many of our projects have nationality restrictions.
- SC cleared – Candidates should have or be willing to undergo SC, and if required, DV clearance.
- Eligible for Non-personnel Police Vetting level 3 standard (NPPV3)
What do we do for you?:
At Leidos we are PASSIONATE about customer success, UNITED as a team and INSPIRED to make a difference. We offer meaningful and engaging careers, a collaborative culture, and support for your career goals, all while nurturing a healthy work-life balance.
We provide an employment package that attracts, develops and retains only the best in talent. Our reward scheme includes:
• Contributory Pension Scheme
• Private Medical Insurance
• 33 days Annual Leave (including public and privilege holidays)
• Access to Flexible benefits (including life assurance, health schemes, gym memberships, annual buy and sell holidays and a cycle to work scheme)
Commitment to Diversity:
We welcome applications from every part of the community and are committed to a truly diverse and inclusive culture. We foster a sense of belonging, welcoming all perspectives and contributions, and providing equal access to opportunities and resources for everyone. If you have a disability or need any reasonable adjustments during the application and selection stages please let us know, and we will respond in a way that best fits your needs.Pay Range:
The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.