The CSEA Contractor is expected to provide hands-on support to the Cyber Security
Engineering and Architecture section by contributing to security architecture
activities, technical security reviews, control implementation, risk
assessments and advisory services across enterprise systems, infrastructure,
cloud environments and applications.

The
contractor is expected to have:

  • Hands-on experience with
    Enterprise Security Architecture methodologies and modern security
    technologies, including IAM, SIEM, EDR/XDR, WAF, SASE, Zero Trust, cloud
    security, and security automation tools.
  • Strong knowledge of IT
    infrastructure security, including network security, cloud security,
    endpoint security, identity security, and secure architecture design
    principles.
  • Strong knowledge of application
    security, including secure SDLC, DevSecOps, API security, secure coding
    practices, and application threat modeling.
  • Experience implementing,
    validating, and reviewing security controls across IT infrastructure,
    cloud platforms such as AWS, Azure, and GCP, and enterprise applications.
  • Experience developing,
    maintaining, and enhancing security control libraries, security patterns,
    baselines, and architecture standards, while ensuring their integration
    into security architecture and engineering activities.
  • Strong understanding of
    cybersecurity standards, laws, and frameworks, including NIST, ISO/IEC
    27001, CIS Controls, GDPR, PCI-DSS, and other relevant regulatory or
    compliance requirements.
  • Strong understanding of
    cybersecurity best practices, including secure network architecture,
    endpoint protection, identity and access management, cloud security,
    DevSecOps, and defense-in-depth design.
  • Experience conducting security
    design reviews, architecture assessments, threat modeling, technical risk
    assessments, and security gap assessments.
  • Ability to support business
    units, project teams, IT teams, and security stakeholders in selecting,
    designing, and implementing secure information systems and technology
    solutions.
  • Experience with security
    automation and scripting using tools and languages such as Python,
    PowerShell, Bash, Terraform, Ansible, or similar technologies.
  • Ability to support security
    investigations, incident response activities, forensic analysis, root
    cause analysis, and post-incident improvement recommendations when
    required.
  • Experience providing technical
    consultation and advisory support on CSEA-related projects, initiatives,
    and engagements as requested by the CSEA Section Head.
  • Excellent ability to translate
    technical cybersecurity concepts, risks, and recommendations into clear
    business language for both technical and non-technical stakeholders.
  • Experience participating in
    cybersecurity committees, technical working groups, architecture review
    boards, project meetings, and cross-functional security discussions.
  • Strong problem-solving,
    analytical, and decision-support skills, with the ability to assess
    complex technical environments and recommend practical security solutions.
  • Ability to work independently
    while also collaborating effectively with security architects, SOC
    analysts, IT teams, application teams, project managers, and business
    stakeholders.
  • Excellent verbal and written
    communication skills, with the ability to document security findings,
    architecture recommendations, risks, and remediation actions clearly and
    professionally.
  • Ability to mentor and support
    CSEA team members as needed by transferring knowledge, sharing technical
    expertise, and contributing to the development of internal cybersecurity
    engineering and architecture capabilities.

Key
Deliverables:

The
contractor may be expected to support or deliver:

  • Security architecture reviews
  • Security design review reports
  • Threat models and risk
    assessments
  • Security control mapping and
    recommendations
  • Architecture patterns,
    baselines, and standards
  • Technical security advisory
    reports
  • Secure design recommendations
    for infrastructure, cloud, and applications
  • Security improvement roadmaps
  • Support for incident response,
    investigations, and technical analysis
  • Knowledge transfer sessions for
    CSEA members


Requirements

Education:

  • Bachelor’s
    degree in a technology-related field, such as Cybersecurity, Computer Science,
    Computer Engineering, Information Security, Information Technology, or a
    related discipline. A higher degree or relevant professional certifications are
    preferred.

Experience:

  • Minimum of 10 years relevant experience in
    cybersecurity, information security, security engineering, or IT infrastructure
    security, with at least 3 years of hands-on experience in cybersecurity
    architecture, security engineering, or enterprise security architecture.

Preferred Certifications:

  • CISSP, CISM, SABSA, or TOGAF certifications preferred.
  • Cloud security certifications such as CCSP, Azure Security Engineer, or AWS Security Specialty preferred.
  • Cybersecurity certifications such as GCIH, GCIA, GSEC, or Security+ preferred.
  • Other relevant cybersecurity, cloud security, or architecture certifications considered.
Proficiency in English & Arabic is
required.

BAE Systems employee working on a machine
Company Culture

Life at BAE Systems

Within a growing network of around 100,000 colleagues in more than 40 countries, our teams bring together people with diverse skills, ways of thinking and backgrounds - while our work spans the depths of the ocean to the far reaches of space.

Tackling complex problems. Building innovative solutions. This is a place where you can make real change happen, for your career and the world.

Discover more
Want to know more?
Part of the BAE Systems team

Inclusion

We want everyone here to feel valued and empowered to thrive. Who you are should never define what you can do. We believe when you bring together different people and perspectives it inspires creativity and drives innovation, helping us fulfil our purpose and is integral to our culture. Everyone is heard and respected here.

Learn more
BAE Systems employee

Learning and development

If you’re curious, hungry for more responsibility, and prepared to step out of your comfort zone, there are endless opportunities to grow with us. At every stage of your career our first-class training, coaching and development programmes, role models and mentors will help you embrace your potential and take the next step.

Learn more
Two BAE Systems employees smiling

Rewards and benefits

Great work deserves benefits that go beyond your salary. Whether it’s health, wellbeing, or financial security for you and your family – our flexible benefits help you focus on what’s important to you.

Learn more
BAE Systems apprentice, Lache', with school pupils.

Making an impact

Together we embrace every opportunity to have a positive impact. On the world around us, our communities, and each other.

Learn more