Expleo
Senior Cybersecurity Consultant (Secure by Design Lead)

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Overview
Expleo is a trusted partner for end-to-end, integrated engineering, quality services, and management consulting for digital transformation. We help businesses harness technological change to successfully deliver innovation, improve resilience and support secure, regulated and operationally critical environments.
As part of the Expleo UK Cybersecurity Practice, you will lead the delivery of product security, cyber assurance and secure-by-design activity for a major UK defence maritime programme, supporting an autonomous surface vessel capability being matured towards a whole-ship system design review.
This is a senior, client-facing role requiring strong cybersecurity leadership, defence assurance experience, maritime or shipbuilding awareness, and the ability to embed security into complex engineering, platform, IT and OT environments. The platform is designed to operate crewless, which shifts the security centre of gravity from information confidentiality towards the safety and availability of operational technology, and makes the remote command-and-control link and position, navigation, and timing resilience the assets that matter most.
You will act as the cyber authority within the client's integrated design team, owning the Security Management Plan and the coherence of the wider security artefact set, and directing the work of a security architect and a cybersecurity consultant. The role sits at the intersection of naval architecture, systems engineering, product security, information assurance and MOD/maritime cyber compliance.
The role requires a strong blend of cybersecurity leadership, secure engineering, technical assurance, stakeholder management, governance, supplier oversight and defence regulatory experience. You will need to operate with autonomy, technical credibility and the ability to provide clear decision support to senior leaders.
Responsibilities
- Own and maintain the Security Management Plan covering OT, IT and physical security, including the assurance and acceptance strategy, management of the supply chain and the route to demonstrating secure by design in accordance with UK MOD requirements.
- Act as the senior security authority within the client's integrated design team, providing direction, challenge and assurance across engineering and delivery activity.
- Develop the threat assessment and a proposed security risk appetite for agreement, in lieu of customer-supplied statements.
- Lead the preliminary security risk assessment and manage design risk exposure, proportionate to the design’s maturity, through a live design risk register owned by and reported to the client delivery team.
- Produce the preliminary specification of security requirements and appropriate standards for OT, IT and physical security, including security classification and criticality assessment.
- Maintain traceability from threat to risk to control to requirement, so that every security requirement is justified and evidenced.
- Define supplier and supply chain security requirements and ensure they are embedded in specifications, delivery expectations and technical acceptance criteria.
- Review and assess supplier security deliverables, including security claims, compliance evidence, technical designs, assurance artefacts and software bills of materials.
- Direct and quality-assure the work of the security architect and cybersecurity consultant, ensuring the artefact set is coherent, traceable and defensible.
- Provide security input to formal engineering design reviews, including system design reviews and equivalent programme governance gates, prepare and present material, and close out resulting actions.
- Manage meetings with security stakeholders and represent the security position to senior client stakeholders and independent technical governance.
- Apply relevant MOD, NCSC, defence and maritime security frameworks to support assurance, accreditation and compliance activities, and reconcile the security position with the platform safety case.
- Generate a detailed scope of work for subsequent programme phases, and an outline scope for later phases.
- Produce clear technical assurance outputs, security design material, decision papers, risk statements, briefing notes and governance updates.
- Work independently as a senior subject matter expert, determining the day-to-day technical approach, stakeholder engagement and assurance rhythm required to achieve agreed outcomes.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Qualifications
- Relevant education or industry-recognised certifications in cybersecurity, information assurance, secure engineering, security architecture, risk management or a related discipline.
- Suitable qualifications may include BSc, MSc, CISSP, CISM, CRISC, CISA, CCP, ISO 27001 Lead Implementer/Lead Auditor, Security+, CySA+, SABSA, TOGAF, IEC 62443, NCSC CAF-related experience or equivalent professional experience.
- Experience working within UK MOD, defence, maritime, shipbuilding, naval, critical national infrastructure or operationally critical environments would be highly beneficial.
Essential skills
- Demonstrable ownership of a Security Management Plan, product security management plan, security case or equivalent controlling assurance artefact.
- Strong understanding of secure-by-design principles and their application across complex engineering lifecycles.
- Ability to lead security input into formal engineering design reviews and technical governance forums.
- Ability to translate security risks and regulatory expectations into practical engineering, architecture and delivery actions.
- Strong stakeholder management skills, including the ability to influence senior technical and programme stakeholders.
- Strong written and verbal communication skills, with the ability to produce concise technical assurance material, risk statements, executive briefings and decision papers.
- Ability to work independently and provide senior technical direction without day-to-day supervision, and to direct the work of other consultants.
- Awareness of maritime cyber assurance benchmarks such as IACS Unified Requirements E26 and E27, and of the Defence Maritime Regulator's assurance framework.
Experience
- Proven experience in a senior cybersecurity, product security, information assurance, or secure engineering role.
- Experience supporting major defence, maritime, naval, shipbuilding, CNI or complex engineering programmes.
- Experience defining or maintaining a Security Management Plan, Product Security Management Plan, Security Case, accreditation pack or equivalent assurance artefact.
- Experience embedding cybersecurity across the full engineering lifecycle, from requirements and design through to build, integration, validation and acceptance.
- Experience leading security input into design reviews, technical governance forums and assurance gates.
- Experience developing and maintaining security risk registers, treatment plans, control evidence and assurance records.
- Experience supporting MOD, NCSC, defence or maritime compliance activity.
- Experience defining supplier security requirements and assessing third-party security evidence.
- Experience operating within Integrated Project Teams or multi-disciplinary engineering delivery environments.
- Experience handling sensitive defence information in line with UK MOD, NCSC, client security and data protection requirements.
- Practical experience applying MOD Secure by Design, NCSC, defence security, information assurance or risk management frameworks.
- Experience conducting threat modelling, security risk assessment and security requirements definition, using recognised methods such as STRIDE, MITRE ATT&CK for Industrial Control Systems, NIST SP 800-30 or ISO/IEC 27005.
- Experience securing complex IT and OT systems, including platform systems, industrial control systems, networks, communications and support environments.
- Experience supporting security accreditation, assurance, compliance or certification activities in a UK defence or similarly regulated environment.
- Cybersecurity experience within defence, maritime, shipbuilding, critical national infrastructure, or operationally critical environments.
- Strong supplier and third-party oversight experience, including security requirements definition, deliverable review, dependency management and acceptance criteria.
- Experience with MOD security policy, defence standards, JSPs, Secure by Design, NCSC guidance or equivalent assurance frameworks.
- Experience with autonomous, uncrewed or remotely operated platforms, and the safety and availability considerations these create.
- Experience with IEC 62443, NIST CSF, ISO 27001, NCSC CAF, Def Stan 05-138 or DEFCON security conditions.
- TEMPEST awareness or experience, particularly as it relates to defence standards, secure design and NCSC guidance.
- Experience contributing to executive-level security reporting, assurance dashboards, risk briefings or programme decision packs.
- Experience scoping IT health checks, penetration testing or technical assurance activity as follow-on work.
- Strong experience operating in a senior product security, cyber assurance, information assurance, secure engineering or security architecture role.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
What do I need before I apply
- Have the right to work in the UK.
- Hold, or be eligible to obtain, UK Security Check (SC) clearance. Clearance is a mandatory requirement for this programme, and applicants must meet the UK residency criteria for security clearance.
- Be willing and able to work in a hybrid model, including client site attendance as required.
- Be comfortable working within secure collaboration environments and handling information marked up to OFFICIAL-SENSITIVE.
- Be able to work under the terms of applicable confidentiality and non-disclosure arrangements.
Benefits
- Collaborative working environment – we stand shoulder to shoulder with our clients and our peers through good times and challenges
- We empower all passionate technology loving professionals by allowing them to expand their skills and take part in inspiring projects
- Expleo Academy - enables you to acquire and develop the right skills by delivering a suite of accredited training courses
- Competitive company benefits
- Always working as one team, our people are not afraid to think big and challenge the status quo
- As a Disability Confident Committed Employer we have committed to:
- Ensure our recruitment process is inclusive and accessible
- Communicating and promoting vacancies
- Offering an interview to disabled people who meet the minimum criteria for the job
- Anticipating and providing reasonable adjustments as required
- Supporting any existing employee who acquires a disability or long term health condition, enabling them to stay in work at least one activity that will make a difference for disabled people
- “We are an equal opportunities employer and welcome applications from all suitably qualified persons regardless of their race, sex, disability, religion/belief, sexual orientation or age”.
- We treat everyone fairly and equitably across the organisation, including providing any additional support and adjustments needed for everyone to thrive
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location