CSEA Contractor
The CSEA Contractor is expected to provide hands-on support to the Cyber Security
Engineering and Architecture section by contributing to security architecture
activities, technical security reviews, control implementation, risk
assessments and advisory services across enterprise systems, infrastructure,
cloud environments and applications.
The
contractor is expected to have:
- Hands-on experience with
Enterprise Security Architecture methodologies and modern security
technologies, including IAM, SIEM, EDR/XDR, WAF, SASE, Zero Trust, cloud
security, and security automation tools. - Strong knowledge of IT
infrastructure security, including network security, cloud security,
endpoint security, identity security, and secure architecture design
principles. - Strong knowledge of application
security, including secure SDLC, DevSecOps, API security, secure coding
practices, and application threat modeling. - Experience implementing,
validating, and reviewing security controls across IT infrastructure,
cloud platforms such as AWS, Azure, and GCP, and enterprise applications. - Experience developing,
maintaining, and enhancing security control libraries, security patterns,
baselines, and architecture standards, while ensuring their integration
into security architecture and engineering activities. - Strong understanding of
cybersecurity standards, laws, and frameworks, including NIST, ISO/IEC
27001, CIS Controls, GDPR, PCI-DSS, and other relevant regulatory or
compliance requirements. - Strong understanding of
cybersecurity best practices, including secure network architecture,
endpoint protection, identity and access management, cloud security,
DevSecOps, and defense-in-depth design. - Experience conducting security
design reviews, architecture assessments, threat modeling, technical risk
assessments, and security gap assessments. - Ability to support business
units, project teams, IT teams, and security stakeholders in selecting,
designing, and implementing secure information systems and technology
solutions. - Experience with security
automation and scripting using tools and languages such as Python,
PowerShell, Bash, Terraform, Ansible, or similar technologies. - Ability to support security
investigations, incident response activities, forensic analysis, root
cause analysis, and post-incident improvement recommendations when
required. - Experience providing technical
consultation and advisory support on CSEA-related projects, initiatives,
and engagements as requested by the CSEA Section Head. - Excellent ability to translate
technical cybersecurity concepts, risks, and recommendations into clear
business language for both technical and non-technical stakeholders. - Experience participating in
cybersecurity committees, technical working groups, architecture review
boards, project meetings, and cross-functional security discussions. - Strong problem-solving,
analytical, and decision-support skills, with the ability to assess
complex technical environments and recommend practical security solutions. - Ability to work independently
while also collaborating effectively with security architects, SOC
analysts, IT teams, application teams, project managers, and business
stakeholders. - Excellent verbal and written
communication skills, with the ability to document security findings,
architecture recommendations, risks, and remediation actions clearly and
professionally. - Ability to mentor and support
CSEA team members as needed by transferring knowledge, sharing technical
expertise, and contributing to the development of internal cybersecurity
engineering and architecture capabilities.
Key
Deliverables:
The
contractor may be expected to support or deliver:
- Security architecture reviews
- Security design review reports
- Threat models and risk
assessments - Security control mapping and
recommendations - Architecture patterns,
baselines, and standards - Technical security advisory
reports - Secure design recommendations
for infrastructure, cloud, and applications - Security improvement roadmaps
- Support for incident response,
investigations, and technical analysis - Knowledge transfer sessions for
CSEA members
Requirements
Education:
- Bachelor’s
degree in a technology-related field, such as Cybersecurity, Computer Science,
Computer Engineering, Information Security, Information Technology, or a
related discipline. A higher degree or relevant professional certifications are
preferred.
Experience:
- Minimum of 10 years relevant experience in
cybersecurity, information security, security engineering, or IT infrastructure
security, with at least 3 years of hands-on experience in cybersecurity
architecture, security engineering, or enterprise security architecture.
Preferred Certifications:
- CISSP, CISM, SABSA, or TOGAF certifications preferred.
- Cloud security certifications such as CCSP, Azure Security Engineer, or AWS Security Specialty preferred.
- Cybersecurity certifications such as GCIH, GCIA, GSEC, or Security+ preferred.
- Other relevant cybersecurity, cloud security, or architecture certifications considered.
required.
Life at BAE Systems
Within a growing network of around 100,000 colleagues in more than 40 countries, our teams bring together people with diverse skills, ways of thinking and backgrounds - while our work spans the depths of the ocean to the far reaches of space.
Tackling complex problems. Building innovative solutions. This is a place where you can make real change happen, for your career and the world.
Discover more
Inclusion
We want everyone here to feel valued and empowered to thrive. Who you are should never define what you can do. We believe when you bring together different people and perspectives it inspires creativity and drives innovation, helping us fulfil our purpose and is integral to our culture. Everyone is heard and respected here.
Learn more
Learning and development
If you’re curious, hungry for more responsibility, and prepared to step out of your comfort zone, there are endless opportunities to grow with us. At every stage of your career our first-class training, coaching and development programmes, role models and mentors will help you embrace your potential and take the next step.
Learn more
Rewards and benefits
Great work deserves benefits that go beyond your salary. Whether it’s health, wellbeing, or financial security for you and your family – our flexible benefits help you focus on what’s important to you.
Learn more
Making an impact
Together we embrace every opportunity to have a positive impact. On the world around us, our communities, and each other.
Learn more