IT Security Officer (highly classified systems
Listed on 2026-08-08
-
Security
Cybersecurity, Information Security & Data Protection, Security Management & Operations -
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Job Description:
Your impact
Leonardo UK operates systems and handles information in highly classified environments. As IT Security Officer for highly classified systems, you will act as the main security point of contact for systems and data at SECRET and above, helping ensure security controls are understood,appliedandmaintainedthrough life. This role is likely to require regular on-site working across secure Leonardo UK locations, with hybrid working supported where appropriate forduties that do not require access to classified environments.
Whatyou will do as IT Security Officer for highly classified systems:
Act as the security point of contact for highly classified systems and associated data.
Support the application of agreed security controls, managementplansand assurance arrangements.
Provide security architecture support and advice for highly classified systems, working with architects, systemownersand operational teams.
Review security governance for project delivery, helping ensure security requirements, risks and assurance evidence are considered at the right stages.
Work with system owners, delivery teams, operationalteamsand Information Security colleagues to manage security risk through the system lifecycle.
Review security-relevant changes andprovideinformed advice on whether theyremainwithin agreed security guardrails.
Support risk assessments, non-compliancereviewsand remediation planning where controls are not fully implemented.
Help ensure security evidence, control status and assurance activity aremaintainedand available for review.
Escalate material changes in cyber or information risk to the appropriate stakeholders.
Support audits, assurancereviewsand continual improvement activity for highly classified environments.
This aligns to the operating model, which describes the role as taking IT Security Officer responsibilities for highly classified systems and acting as the main security point of contact for systems and data at SECRET and above. The model also describes the need for security architecture support, project delivery governance, security managementplansand through-life assurance.
Whatyou’llbringYou will bring practical information security experience in secure, regulated or highly controlled environments. You should understand how to apply security requirements in an operational setting and how to support proportionate risk decisions without creating unnecessary friction for delivery teams.
Essential experience and skills:Experience in information security, cyber security, secure operations, security assuranceor a related technical security role.
Experience working with classified, regulated, defence,govern mentor similarly sensitive environments.
Understanding of MoD and other UK government security policy and frameworks.
Knowledge of security control frameworks and risk management practices.
Practical understanding of security risk assessment, residual risk, riskacceptanceand non-compliance management.
Experience supporting security architecture, designreviewsor technical security decision-making.
Experience reviewing security governance for project delivery, including security requirements, risk records, assurance evidenceor readiness criteria.
Experience reviewing ormaintainingsecurity management plans, assurance evidence, controlrecordsor equivalent security artefacts.
Understanding of secure system operation, change control, access control, protectivemonitoringand incident response principles.
Ability to work with technical teams, systemownersand security specialists to assess whether controls are being applied effectively.
Willingness and ability to hold the required security clearance for highly classified environments.
Professional security qualification such as CISSP, CISM, Security+, ISO 27001, Certified Cyber Professional or equivalent experience.
Knowledge of cyber and information risk frameworks or methodologies.
This is not an exhaustive list, and we are keen to hear from you even if you might not have experience in all the above. The most important skill is a good attitude and willingness to learn.
Security ClearanceThis role is subject to pre-employment screening in line…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: