×
Register Here to Apply for Jobs or Post Jobs. X

Security Architect (OT, IT, Network and Physical

Job in Gloucester, Gloucestershire, GL1, England, UK
Listing for: Expleo UK LTD
Full Time position
Listed on 2026-08-08
Job specializations:
  • Engineering
    Systems Engineer, Cybersecurity
  • IT/Tech
    Systems Engineer, Cybersecurity
Salary/Wage Range or Industry Benchmark: 80000 - 120000 GBP Yearly GBP 80000.00 120000.00 YEAR
Job Description & How to Apply Below
Position: Security Architect (OT, IT, Network and Physical)

Expleo is a trusted partner for end-to-end, integrated engineering, quality services, and management consulting for digital transformation. We help businesses harness technological change to successfully deliver innovation, improve resilience and support secure, regulated and operationally critical environments.

As part of the Expleo UK Cybersecurity Practice, you will define and ensure the security architecture for a major UK defence maritime programme, supporting an autonomous surface vessel capability that is being matured towards a whole-ship system design review.

This is a hands-on architecture role for an engineer who is comfortable designing across operational technology, IT, networks, and physical security, and who can serve as a design lead to naval architects, systems engineers, a digital system integrator, and subsystem owners. Because the platform is designed to operate crewless, the architecture must be fail-safe under compromise and maintain a defined minimum-risk state upon loss of the remote command-and-control link.

You will own the security architecture and the asset baseline that underpins it, working to the Security Management Plan set by the Secure by Design lead and providing architectural evidence to support formal design review.

The role requires strong secure-by-design architectural skills, deep IT and OT understanding, and the ability to translate risk and consequences into segmentation, controls, and defensible design decisions.

  • Develop the security architecture for OT and IT in coordination with the digital system integrator and sub-system owners, and produce the preliminary security architecture design.
  • Partition the platform into zones and conduits in accordance with IEC 62443, setting target security levels based on safety and mission consequences.
  • Review the network architecture and communications security, and provide advice, including on the resilience of remote command-and-control links and of position, navigation, and timing.
  • Produce the network security architecture in coordination with the digital teams.
  • Review the physical security provision in the design and develop appropriate protection measures, producing the physical security design in coordination with the arrangement team.
  • Define trust boundaries, segregation, secure configuration baselines, identity and access management, and secure remote access requirements for shipboard and supporting systems.
  • Build and structure the initial asset register for configuration control, capturing criticality, zone, ownership and dependency attributes.
  • Support threat modelling and security risk assessment from an architecture perspective, and translate assessed risk into architectural controls.
  • Define architecture-level security requirements and maintain their traceability into the wider requirements specification.
  • Assure that architectural controls are fail-safe and do not defeat safety functions, working alongside safety and engineering colleagues.
  • Provide architectural evidence and materials for internal and external design reviews, including system design reviews, and close out resulting actions.
  • Contribute to supplier and interface security requirements where these bear on the architecture, including third-party payload and control-system interfaces.
  • Produce clear high-and low-level design material, architecture views, decision records and design rationale suitable for technical scrutiny.
  • Relevant education or industry-recognised certifications in security architecture, cybersecurity, secure engineering, operational technology security or a related discipline.
  • Suitable qualifications may include BSc, MSc, CISSP, CISM, CRISC, CCP, ISA/IEC 62443 (Fundamentals Specialist, Risk Assessment Specialist, Design Specialist or Expert), SABSA, TOGAF, CCNP, OSCP, ISO 27001 Lead Implementer/Lead Auditor or equivalent professional experience.
  • Experience working within UK MOD, defence, maritime, shipbuilding, naval, critical national infrastructure or operationally critical environments would be highly beneficial.
#J-18808-Ljbffr
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary