Rodeo
Get started

CyberFortis Consulting

Security Systems Engineer - Security Clearence

London
Posted about 16 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

About CyberFortis

CyberFortis Consulting Limited is a UK cybersecurity and technology company developing AI-enabled governance, risk and compliance solutions and expanding its capabilities in secure government and defence technology.

We are seeking an experienced Security & Secure Systems Engineer to support the design, implementation and assurance of secure technical environments for defence-oriented software and AI capabilities.

The successful candidate will work closely with company leadership and engineering teams to translate security requirements into practical technical controls, support secure system delivery, and produce the evidence required for technical assurance and security review.

This role is suited to an engineer who combines hands-on security implementation with a strong understanding of secure system architecture, operational risk and security assurance.

Role Purpose

The Security & Secure Systems Engineer will be responsible for developing, implementing and validating security controls across application, infrastructure, identity, data and deployment layers.

The role will support secure-by-design engineering, security risk management, vulnerability remediation, operational security and the preparation of technical assurance documentation.

The successful candidate must understand that security is an engineering discipline: controls must be implemented, tested, evidenced and maintained throughout the system lifecycle.

Key Responsibilities

Secure Architecture and Engineering

  • Design and review secure system architectures, identifying security risks and appropriate mitigations.
  • Translate security requirements into implementable technical controls and engineering standards.
  • Conduct threat modelling and attack-surface analysis for applications, APIs, data flows and infrastructure.
  • Apply secure-by-design principles across development, integration, deployment and maintenance.
  • Review system boundaries, trust relationships, dependencies and external service integrations.
  • Support security architecture decisions for AI-enabled applications and associated data-processing components.

Infrastructure and Environment Security

  • Implement and validate secure configurations across approved cloud, infrastructure and application environments.
  • Configure identity and access management, role-based access controls and least-privilege permissions.
  • Support privileged-access management, secrets management, key handling and secure configuration practices.
  • Establish and review security logging, monitoring, alerting and audit-trail requirements.
  • Support network segmentation, environment separation, secure connectivity and controlled administrative access.
  • Assist with backup protection, recovery arrangements, configuration management and operational resilience.

Vulnerability Management and Security Testing

  • Conduct vulnerability assessments and coordinate remediation activities.
  • Review dependency, container, operating-system, application and infrastructure security findings.
  • Support secure code reviews, configuration reviews and penetration-testing activities.
  • Assess findings according to technical severity, exploitability, exposure and operational impact.
  • Maintain remediation records and verify that security fixes are effective.
  • Develop repeatable security checks that can be incorporated into development and deployment pipelines.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Secure Software Development and DevSecOps

  • Integrate security checks into CI/CD pipelines and release processes.
  • Support software composition analysis, secrets detection, static analysis and container-image scanning.
  • Establish security acceptance criteria for releases and document residual risks.
  • Work with software engineers to remediate vulnerabilities without unnecessarily disrupting delivery.
  • Maintain secure configuration baselines and support infrastructure-as-code security reviews.
  • Help establish auditable release, change-management and deployment practices.

AI and Data Security

  • Review the security implications of LLM integrations, AI orchestration, retrieval-augmented generation and external model services.
  • Assess data flows involving prompts, outputs, embeddings, document stores, caches, telemetry and logs.
  • Help implement appropriate controls for data classification, retention, access, encryption and deletion.
  • Assess prompt injection, insecure tool use, data leakage, excessive agent permissions and other AI-specific attack paths.
  • Support controls that prevent unauthorised use of project data for model training or unrelated processing.
  • Ensure that AI-generated outputs, where relevant, are subject to appropriate validation, traceability and human oversight.

Security Assurance and Compliance Evidence

  • Translate applicable contractual security requirements into a control implementation and evidence matrix.
  • Prepare and maintain security architecture documents, threat models, risk registers, configuration records and remediation plans.
  • Support security reviews, technical assurance activities and responses to customer security findings.
  • Maintain traceability between requirements, implemented controls, test results and supporting evidence.
  • Support relevant organisational security assessments and improvement plans.
  • Work with the project team to identify security gaps early and track them through to closure or formally accepted remediation.

Defence and Government Security

  • Work within the security instructions, information-handling rules and access restrictions applicable to each assigned project.
  • Support the implementation of customer-approved security requirements and operational procedures.
  • Identify when a proposed design, hosting arrangement, service or integration requires additional approval.
  • Escalate security incidents, suspected data exposure and material control failures through the designated process.
  • Cooperate with authorised customer security personnel and assurance representatives.
  • Maintain appropriate separation between development, testing and environments handling protected information.

Essential Requirements

Candidates must demonstrate:

  • Active, valid UK SC clearance, subject to verification through the appropriate authorised process.
  • Substantial practical experience in cybersecurity engineering, secure systems engineering, infrastructure security or a closely related discipline.
  • Strong understanding of security architecture, threat modelling and risk-based control implementation.
  • Hands-on experience with identity and access management, least privilege, authentication and privileged access.
  • Practical experience with vulnerability management, secure configuration and security remediation.
  • Understanding of secure software development and DevSecOps practices.
  • Experience with security logging, monitoring, auditability and incident-response processes.
  • Familiarity with cloud security, containers, APIs and modern application architectures.
  • Ability to produce clear technical documentation and evidence that supports independent security review.
  • Strong problem-solving skills and the ability to work collaboratively with developers, architects and project stakeholders.
  • A disciplined approach to handling sensitive information and complying with security procedures.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Desirable Experience

The following would be advantageous:

  • Experience supporting UK government or Ministry of Defence technology programmes.
  • Experience with systems subject to formal security assurance or accreditation.
  • Familiarity with UK government security policies and relevant NCSC guidance.
  • Experience with AWS, Microsoft Azure, IBM Cloud or other enterprise cloud environments.
  • Familiarity with IBM watsonx, LLM application architectures or enterprise AI platforms.
  • Experience with Kubernetes, Docker, infrastructure as code and automated security tooling.
  • Knowledge of data classification, cryptographic controls, key management and secure data handling.
  • Experience with ISO 27001, Cyber Essentials Plus or other relevant security frameworks.
  • Experience with security requirements traceability, technical risk registers and remediation tracking.
  • Relevant security, cloud or infrastructure certifications.

Initial Deliverables

During the initial engagement, the engineer will be expected to contribute to:

  • A security architecture and threat model for the assigned system and deployment environment.
  • A security requirements and controls matrix mapped to the applicable contractual requirements.
  • An assessment of the existing security posture, including prioritised findings and remediation recommendations.
  • A secure configuration baseline covering identity, access, logging, secrets and deployment controls.
  • A vulnerability-management and remediation workflow with clear ownership and verification.
  • Security checks integrated into the engineering and release lifecycle, where appropriate.
  • An evidence pack containing relevant architecture documents, test results, control records and outstanding risks.
  • A documented security handover and recommendations for ongoing operational assurance.

Deliverables and acceptance criteria will be agreed with the successful candidate in line with the actual project scope and customer requirements.

Working Expectations

  • Work closely with the company leadership and technical delivery team.
  • Communicate security risks clearly, with practical remediation options and prioritisation.
  • Maintain accurate records of security decisions, control implementation and outstanding issues.
  • Avoid unsupported claims about compliance, accreditation or security effectiveness.
  • Distinguish implemented and tested controls from planned controls and documented policies.
  • Do not access, transfer or process classified or otherwise restricted information except where the individual, organisation, systems and environment are appropriately authorised.
  • Follow applicable contractual, legal and organisational security requirements.

CyberFortis Consulting Limited is committed to secure-by-design engineering, responsible AI development and rigorous technical assurance.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

London, England, United Kingdom

Sign up to applySee more jobs like this