- Referenceable, in-depth experience and knowledge in Cyber Security and IT; including business process design across multiple organisations and projects.
- Proven track record in secure delivery of scale national infrastructure and subsequent managed service. Ability to design and build practical security infrastructure within this environment based on a contextualised understanding of the risk.
- Proven ability to work with Enterprise Security Architecture frameworks (SABSA / TOGAF)
- Demonstrable experience of leading and mentoring colleagues, encouraging the application of architectural expertise in all areas of Cyber Security
- Thorough understanding of designing and constructing business processes, functions and organizational structures using appropriate tools/modelling languages
- Significant knowledge of cloud architecture and integration technologies
- Demonstrated understanding and experience of IT, networking and virtualisation technologies
- Proven ability to define architecture roadmaps and associated strategies.
- Excellent communicator, verbal and written, with the ability to explain complex issues to a variety of stakeholders; technical and non-technical.
- Excellent quality focus, ensuring appropriate documentation and knowledge sharing.
- Proven experience of architecture design analysis
- Experience of NCSC’s Cyber Assurance Framework (CAF), NIST Cyber Security Framework (CSF), NIST SP 800-53, ISO 27001 and HMG regulations and other departmental IT in defence and security
- Ability to work in small teams, highly specialised technology areas across diverse projects
- Experience of cross-security domain approaches and solutions
- Experience of operating in Critical National Infrastructure (CNI) and the requirements around cyber security and operational resilience
- Understanding of threats in a government, mission and critical national infrastructure environments.
- A working knowledge of IT Security risk assessment processes and ability to identify a proportionate set of IT Security controls aligned with business objectives.
- In-depth assessment of IT systems, cloud offerings (IaaS, PaaS and SaaS), services and IT Security controls to provide an independent view of their compliance and effectiveness with Security Policy, IT Security standards and external regulatory requirements.
- Assessing architectural designs to determine whether the relevant IT Security controls have been identified in line with business objectives and risk mitigation.
- Analysis, creation and compilation of relevant documentation determining the compliance level of systems and services, technical security controls with applicable certification, accreditation, and internal policy requirements
- Stakeholder engagement; promoting a mind-set of developing secure systems, transferring knowledge of security standards / processes and acting as a subject matter expert (SME)
- Essential Cyber Security Certifications:
One of the following certifications:
- Certified Information Security Systems Professional (CISSP)
- SABSA Chartered Security Architect (SCF)
- Certified Information Security Manager (CISM)
And two or more of the following certifications:
- CompTIA Security+
- Certified Cloud Security Professional (CCSP)
- Systems Security Certified Practitioner (SSCP)
- GIAC Security Essentials Certification (GSEC)
- Certified Ethical Hacker (CEH)
- Certified in Risk and Information Systems Control (CRISC)
- ISO 27001 Lead Auditor
- ISO 27001 Lead Implementer
- Certified Information Systems Auditor (CISA)
We actively recruit citizens of all backgrounds, but the nature of our work in specific departments means that nationality, residency and security requirements can be more tightly defined than others. You will be asked about this throughout the recruitment process. To work at NPL, you will need to obtain BPSS security clearance. However, to work in this role in the Time & Frequency department, you will need to have an SC clearance with no restrictions, or you must have the ability to obtain an SC clearance.
Please note: Applications will be reviewed, and interviews conducted throughout the duration of this advert therefore we may at any time bring the closing date forward. We encourage all interested applicants to apply as soon as practical.