Make Your Resume Now

Principal Product Security Engineer

Posted April 10, 2026
Full-time Mid-Senior Level

Job Overview

Navantia UK is a leading provider of innovative naval solutions, specialising in the design, construction, and lifecycle support of naval ships. As part of the global Navantia Group, we are committed to delivering cutting-edge technologies and world-class services across the maritime sector. Based in Bristol, we are seeking a passionate Principal Product Security Engineer to join our team and play a pivotal role in the security of our designs and related current and emerging technology solutions on advanced next generation naval and government ships.

This role is offered on a full‑time basis, but we also welcome applications from candidates with the right skills who are interested in part‑time working.

The Opportunity

Based in Bristol the Principal Product Security Engineer is responsible for defining, implementing, and assuring the security strategy for defence shipping and Fleet Solid Support Programme. This role ensures that cyber security, information assurance, and secure-by-design principles are embedded across both the platform (ship) design and the IT/OT architecture throughout the full engineering lifecycle.

The role operates at the intersection of naval architecture, marine systems engineering, combat/logistics support systems, and enterprise IT/operational technology (OT), ensuring compliance with MOD security policies and relevant maritime cyber regulations.

Duties

 

Security Leadership & Strategy

  • Develop and maintain the Product Security Management Plan (PSMP) for the vessel programme, covering all aspects of security.
  • Define the security architecture strategy for both ship systems (OT) and IT networks.
  • Act as the security authority within the Integrated Project Team (IPT).
  • Provide leadership on secure-by-design principles across naval platform development.

Secure Ship Design Integration

  • Ensure security requirements are embedded into programmable elements and systems included but not limited too:
    • Platform management systems
    • Navigation systems
    • Propulsion and machinery control systems
    • Communications systems (internal & external)
    • Mission/logistics systems (if applicable)
  • Conduct threat modelling and risk assessments for marine and hybrid IT/OT environments.
  • Define physical security requirements and access controls.
  • Support management of TEMPEST where required.
  • Support design reviews (SRR, PDR, CDR) with formal security assurance inputs.
  • Ensure compliance with relevant standards (e.g., Def Stan, NCSC guidance, IEC 62443, NIST, IMO cyber guidance).

IT & OT Architecture Security

  • Define secure network zoning and segregation between:
    • Operational Technology (OT)
    • Information Technology (IT)
    • Communications systems
  • Approve system boundary definitions and trust zones.
  • Ensure secure configuration baselines for onboard systems.
  • Oversee secure integration of third-party vendors and subcontractors.
  • Define Identity and Access Management (IAM) and privileged access strategies for afloat systems.

Risk, Assurance & Compliance

  • Lead security risk management in alignment with MOD/NCSC frameworks.
  • Manage security risk registers and treatment plans.
  • Coordinate accreditation and authority-to-operate activities.
  • Support JSP 440 / JSP 604 compliance activities.
  • Provide evidence for security case development and formal assurance reviews.

Supply Chain & Third-Party Security

  • Define security requirements within supplier contracts.
  • Conduct supplier security assessments.
  • Ensure secure development practices across the supply chain.
  • Validate SBOMs (Software Bill of Materials) where required.

Testing & Validation

  • Define security test strategies including:
    • Vulnerability assessments
    • Penetration testing
    • Factory Acceptance Testing (FAT) security scope
    • Harbour and Sea Trial cyber validation
  • Oversee remediation of identified vulnerabilities.
  • Ensure secure configuration prior to vessel acceptance.

Incident Preparedness & Operational Security

  • Define onboard cyber incident response requirements.
  • Ensure monitoring and logging architecture supports detection and forensic investigation.
  • Contribute to lifecycle security planning, including in-service support.

Ready to Apply?

Take the next step in your career journey

Stand out with a professional resume tailored for this role

Build Your Resume – It’s Free!