Point your AI agent at freehire and let it find you a job.

Get the CLI →

BAE Systems

NewBe an early applicant

Principal Product Security Engineer

Posted
Discussion

Summary

A senior security engineering role at BAE Systems in Portsmouth (hybrid), leading Secure by Design across defence product lifecycles: defining security requirements, threat modelling, risk assessments, and producing security assurance evidence alongside design teams and assessors. Requires CISSP/CISM and deep knowledge of NIST, ISO 27000 and MoD security standards.

Job Title\: Principal Product Security Engineer

Location\: Portsmouth Broad Oak and occasional travel to other BAE Systems sites. We offer a range of hybrid and flexible working arrangements - please speak to your recruiter about the options for this particular role

Referral Bonus\: £1,000

Grade\: GG11

You’re expected to have completed 12 months in role prior to applying for an advertised vacancy and you should also discuss the internal opportunity with your line manager to ensure sustained business continuity and to further support your career development.

We know there may be exceptional individual circumstances that impact this, in the first instance please discuss this with your line manager.

If you don’t feel you can talk to your line manager, you can contact your HRBP.

PLEASE NOTE\: Should you be invited for interview; you acknowledge that the Recruitment team will contact you and your line manager regarding your application for this opportunity.

Job Description\:

As a Principal Product Security Engineer, you will lead the application of information assurance, cyber security, and physical security principles throughout the Secure by Design engineering lifecycle. This includes influencing security requirements from concept and design through development, verification, acceptance, and in-service support.

Working closely with the System Design Authority (SDA), product development teams, and external assessors, you will provide expert security guidance to ensure that security requirements are effectively integrated into product designs and aligned with regulatory, customer, and organisational security standards. You will be responsible for defining, developing, and maintaining security requirements, ensuring that security considerations are embedded in technical solutions from the outset.

A key aspect of the role will be conducting threat modelling, security risk assessments, and vulnerability analysis to identify potential attack vectors early in the design lifecycle. You will advise engineering teams on the selection and implementation of appropriate security controls and mitigation strategies to reduce risk and support security assurance objectives.

You will also lead the development of the security evidence and assurance documentation required to demonstrate that products meet Secure by Design principles and are suitable for acceptance into service, and ongoing operational use.

Core Duties\:

  • Work closely with the design engineering team to ensure that security considerations and controls are included in the design ahead of production, test and acceptance
  • Represent projects at Security Working Groups, providing progress reports and status of the product with regard to Secure by Design and Security Risk profiles
  • Undertake functional design and/or provide qualification and evidence for acceptance, fitness for purpose, legislative requirements, and security
  • Support the design engineering team by collating and demonstrating technical maturity of the security aspects of the design at formal design reviews

Essential Skills\:

  • You will be certified to CISSP, CISM or equivalent
  • You will have in-depth knowledge of Security standards and frameworks, such as NIST series, ISO 27000 series and understanding of Defence Standards and process’s
  • You will have knowledge of security analysis techniques, such as Threat modelling, Risk Assessment, Encryption, Penetration Testing
  • You will have expert knowledge in security gained through substantial work experience to apply principles and concepts in a product development environment
  • You will have a depth of knowledge of the tools and technologies that can be applied to support Product Security Assurance, such as MoD Process’s, procedures and SbD Principles and Security Cases including Security Management Plans, Security Impact Assessments, Risk Assessments

The team\:

The Product Security team are a centrally managed group of practitioners that are part of a business wide capability centre. The capability centre is the prime vehicle for the professional development of our security engineers, whilst increasing the capability of the business regards Secure by Design. The security engineers are deployed to projects to support the engineering teams but maintain the back office support of the wider team and centre.

Why BAE Systems?

Here you’ll build a career with purpose and limitless possibilities. With lifelong learning and meaningful work, this is a place where you can grow your career with confidence and be empowered to be your best. You’ll be recognised for your contribution and enjoy rewards tailored to what’s most important to you and your family, support for your financial and personal wellbeing, as well as a balanced lifestyle. In an environment embracing sustainable ways of working and with a strong sense of shared purpose, our supportive culture is a place you can feel you belong and proud of the difference you make.

A place where everyone can thrive\:

We’re committed to building an inclusive workplace where everyone feels valued and supported. We know that a diversity of backgrounds, perspectives and experiences strengthens our teams and is vital to the work we do.

We welcome applications from all suitably qualified people, who are BAE Systems employees and have been in their current role for 12 months or longer.

Please be aware that many roles at BAE Systems are subject to both security and export control restrictions. These restrictions mean that factors such as your nationality, any nationalities you may have previously held, and your place of birth can restrict the roles you are eligible to perform within the organisation. All applicants must as a minimum achieve Baseline Personnel Security Standard. Many roles also require higher levels of National Security Vetting where applicants must typically have 5 to 10 years of continuous residency in the UK depending on the vetting level required for the role, to allow for meaningful security vetting checks.

Closing Date\: 29th September 2026

Skills

What Principal Security jobs ask for — and how much of it you have →

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available