Principal Engineer - Product Security

Job Title\: Principal Engineer – Cyber Security

Location\: Frimley, Bristol, Weymouth, Portsmouth, Coventry. Hybrid - 3 days/week onsite

We offer a range of hybrid and flexible working arrangements - please speak to your recruiter about the options for this particular role

Referral Scheme\: £5,000

Grade\: S5

You’re expected to have completed 12 months in role prior to applying for an advertised vacancy and you should also discuss the internal opportunity with your line manager to ensure sustained business continuity and to further support your career development.

We know there may be exceptional individual circumstances that impact this, in the first instance please discuss this with your line manager.

If you don’t feel you can talk to your line manager, you can contact your HRBP.

PLEASE NOTE\: Should you be invited for interview; you acknowledge that the Recruitment team will contact you and your line manager regarding your application for this opportunity.

What you’ll be doing\:

You’ll define and implement risk-based cybersecurity requirements for systems and subsystems, providing technical expertise and guidance across all aspects of cyber security and resilience. You’ll conduct in-depth cybersecurity analysis, including development of threat taxonomies, security architectures, security baselines, and risk mitigation strategies. You’ll develop and execute cybersecurity test plans and schedules, carrying out both informal and formal security testing activities

You’ll support engineering lifecycle reviews and design assurance processes to ensure security is embedded throughout system development. You’ll produce and maintain key security artefacts, including risk registers, security assurance cases, plans, and schedules, while contributing security input to broader engineering documentation

Core duties\:

  • You'll hold a degree in a relevant STEM subject or maintaining recognised Industry Security Qualifications e.g., CCP, CISSP
  • You'll have proven experience of assessing and managing risk in line with industry good practice (NIST, ISO 27001)Y
  • You'll bring significant experience with using security baselines, mitigations and controls
  • You'll be considerably familiar with a life cycle phased approach

The Engineering Delivery Team\:

The team designs, builds, integrates and provides through life support to all the Submarine Platforms in the Royal Naval fleet. You will ensure the submarine systems and products are developed to support the delivery of an appropriately secure and resilient product. Through application of your knowledge and experience, you shall identify, analyse, evaluate and manage information security risks associated with the products used on-board the submarine. Speaking knowledgably and credibly with customers, users and internal stakeholders you shall provide advice on the causes of the risks identified, their likelihood and potential operational impacts. We offer relocation support packages across all Submarines roles, subject to meeting eligibility criteria.

Why BAE Systems?

Here you’ll build a career with purpose and limitless possibilities. With lifelong learning and meaningful work, this is a place where you can grow your career with confidence and be empowered to be your best. You’ll be recognised for your contribution and enjoy rewards tailored to what’s most important to you and your family, support for your financial and personal wellbeing, as well as a balanced lifestyle. In an environment embracing sustainable ways of working and with a strong sense of shared purpose, our supportive culture is a place you can feel you belong and proud of the difference you make.

A place where everyone can thrive\:

We’re committed to building an inclusive workplace where everyone feels valued and supported. We know that a diversity of backgrounds, perspectives and experiences strengthens our teams and is vital to the work we do.

We welcome applications from all suitably qualified people, who are BAE Systems employees and have been in their current role for 12 months or longer.

Please be aware that many roles at BAE Systems are subject to both security and export control restrictions. These restrictions mean that factors such as your nationality, any nationalities you may have previously held, and your place of birth can restrict the roles you are eligible to perform within the organisation. All applicants must as a minimum achieve Baseline Personnel Security Standard. Many roles also require higher levels of National Security Vetting where applicants must typically have 5 to 10 years of continuous residency in the UK depending on the vetting level required for the role, to allow for meaningful security vetting checks.

Closing Date\: 14th July 2026