Point your AI agent at freehire and let it find you a job.

Get the CLI →

BAE Systems

NewBe an early applicant

Cyber Security Engineer

Discussion

Summary

Cyber Security Engineer safeguarding BAE Systems' UK enterprise IT by administering Palo Alto firewall governance and IDPS policies, running vulnerability scanning, managing DLP controls, and supporting the Atlassian stack on Linux/PostgreSQL. Hybrid role (1 day onsite per week) based in Preston or Frimley; internal applicants only.

Job Title\: Cyber Security Engineer

Job Location\: Preston or Frimley. Hybrid - 1 day per week onsite. We offer a range of hybrid and flexible working arrangements - please speak to your recruiter about the options for this particular role.

Grade\: GG10

You’re expected to have completed 12 months in role prior to applying for an advertised vacancy and you should also discuss the internal opportunity with your line manager to ensure sustained business continuity and to further support your career development.

We know there may be exceptional individual circumstances that impact this, in the first instance please discuss this with your line manager.

If you don’t feel you can talk to your Line Manager, you can contact your HRBP.

PLEASE NOTE Should you be invited for interview; you acknowledge that the Recruitment team will contact you and your line manager regarding your application for this opportunity.

Role Description\:

The role of the Cyber Security Engineer is to work as part of a team safeguarding BAE Systems UK enterprise IT infrastructure against cyber threats through the configuration, installation and maintenance of Cyber Security Technical Control Software solutions and compensating controls. As part of the role, you will provide technical assurance and governance for Palo Alto firewalls, reviewing and approving firewall rule requests to ensure compliance with security policies, risk management standards, and business requirements. Other duties include the configuration and maintenance of vulnerability scanning platforms, including scanner administration, scan configuration, and the scheduling of authenticated and unauthenticated vulnerability assessments across enterprise environments.

Core Duties\:

  • Act as the technical authority for Palo Alto Security Profiles, including Intrusion Detection and Prevention System (IDPS) policy changes, validating configuration updates to maintain an effective security posture and minimise operational risk
  • Conduct ongoing firewall policy reviews, rule recertification, and security profile assessments, ensuring configurations align with security best practices, regulatory requirements, and organisational standards while supporting audit and compliance activities
  • Support firewall governance activities, including firewall rule reviews, change assessments, approval processes, and policy compliance checks
  • Conduct vulnerability scanning activities across servers, workstations, network devices, cloud assets, and applications, validating scan results, investigating false positives, and ensuring comprehensive asset coverage
  • Administer and maintain DLP controls, supporting data protection, regulatory compliance, and the prevention of unauthorised data disclosure
  • Provide technical support across the Atlassian Stack, including Linux server administration, PostgreSQL database management, platform upgrades, configuration management, performance optimisation, troubleshooting, and maintaining a secure, highly available environment

Essential Skills\:

  • Strong knowledge of firewalls including firewall rule reviews, policy optimisation, NAT, security profiles, and troubleshooting
  • Understanding of network security principles, including TCP/IP, routing, VPNs, segmentation, and IDPS technologies
  • Experience managing Windows and Linux servers, including system administration, automation capabilities and performance monitoring
  • Strong analytical skills to assess data, identify risks and provide actionable recommendations
  • Awareness of common security vulnerabilities and threats affecting end user devices, servers, applications, and network infrastructure, including appropriate mitigation and remediation practices
  • Knowledge of Microsoft 365 security and data protection controls

The Cyber Engineering team\:

You will be joining an expansion to an existing cyber engineering team, supporting additional requirements that sits within Enterprise IT, providing enterprise IT services across the UK businesses and internationally. You will participate in the creation of security solutions to provide enterprise security services, and maintain, develop, and communicate their associated roadmaps and standards through the full lifecycle of the service. This could also offer a natural progression route and the opportunity to develop further.

Why BAE Systems?

Here you’ll build a career with purpose and limitless possibilities. With lifelong learning and meaningful work - this is a place where you can grow your career with confidence and be empowered to be your best. You’ll be recognised for your contribution and enjoy rewards tailored to what’s most important to you and your family - support for your financial and personal wellbeing, as well as a balanced lifestyle. In an environment embracing sustainable ways of working and with a strong sense of shared purpose, our supportive culture is a place you can feel you belong and proud of the difference you make.

We welcome applications from all suitably qualified people, who are BAE Systems employees and have been in their current role for 12 months or longer.

A place where everyone can thrive\:

We’re committed to building an inclusive workplace where everyone feels valued and supported. We know that a diversity of backgrounds, perspectives and experiences strengthens our teams and is vital to the work we do.

Please be aware that many roles at BAE Systems are subject to both security and export control restrictions. These restrictions mean that factors such as your nationality, any nationalities you may have previously held, and your place of birth can restrict the roles you are eligible to perform within the organisation. All applicants must as a minimum achieve Baseline Personnel Security Standard. Many roles also require higher levels of National Security Vetting where applicants must typically have 5 to 10 years of continuous residency in the UK depending on the vetting level required for the role, to allow for meaningful security vetting checks.

Skills

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available