Company

Cubic CorporationSee more

addressAddressSalfords, Surrey
CategoryConstruction & Property

Job description

Business Unit:
Cubic Transportation Systems
Company Details:
When you join Cubic, you become part of a company that creates and delivers technology solutions in transportation to make people’s lives easier by simplifying their daily journeys, and defense capabilities to help promote mission success and safety for those who serve their nation. Led by our talented teams around the world, Cubic is committed to solving global issues through innovation and service to our customers and partners.
We have a top-tier portfolio of businesses, including Cubic Transportation Systems (CTS) and Cubic Defense (CD). Explore more on Cubic.com.
Job Details:
Job Summary: Leads assurance of cyber resilience controls and provides information Security Architecture consultancy to multiple Cubic customer projects for new and revised Cloud services, back-office systems and hardware devices within bids and projects. The role will work closely with systems and project engineers, developers, bid teams, internal/ external business stakeholders and project managers across functions both regionally and globally. Reports to Security Architecture Manager.
Essential Job Duties and Responsibilities:
  • Develop responses to customer security requirements with engineering and business development teams for customer bids
  • Develop Cubic security response to customer variation requests and ensure customer understanding of the impact of their request against new and existing security risks.
  • Create the delivery of design and build / operations and maintenance budget requirements for customer bids and variation requests. Provides financial requirements for cyber resilience controls and security labour estimates in cost models for presentation to senior Cubic leadership.
  • Develop assurance for security requirements to be developed by DevOps, system engineers and other project team staff according to Cubic cyber resilience engineering policies and customer needs and ensure that these requirements are supportable and clearly documented.
  • Develops all security risk assessment / business impact analysis/ audit for new and existing business applications or IT infrastructure and leads advice and guidance on the application and operation of physical, procedural and technical security controls within all engineering and IT solutions.
  • Lead information security assurance within design gateways and service transition/ change boards.
  • Champion best practices for application and infrastructure/ architecture design principles for the use of existing and new information security technologies across customer systems.
  • Assure appropriate security support processes are delivered by projects to support service transition.
  • Some manual handling may occasionally be required
  • May be required to work on other Cubic sites and datacentres
  • Comply with Cubic’s values and adherence to all company policy and procedures. In particular, comply with the code of conduct, quality, security and occupational health, safety and environmental policies and procedures.
  • In addition to the duties and responsibilities listed, the job holder is required to perform other duties assigned by their manager from time-to-time, as may be reasonably required of them.
Minimum Job Requirements:

Qualifications
Essential:
  • Degree or equivalent qualifications/experience
  • Certification as an Information Security professional (e.g. IISP/CISA/CISM/CISSP/CCSP/ ISA)
  • Current driving licence
Desirable:
  • A university degree in a numerate subject (e.g. computer science, maths, engineering, natural science)
  • Information privacy/ data protection – CIPPE/ + CIPM
  • HMG IA qualifications/ CLAS; CREST-registered penetration tester and/or Security Architect
  • ITIL v3/ Prince2 foundation level/ TOGAF
  • Security and IT infrastructure/ networking vendors’ certifications
Skills/Experience/Knowledge
Essential:
  • Solid exposure of taking a leading role in the establishment and implementation of Security Architecture, policies and procedures.
  • Experience of secure development lifecycles (SDLC)
  • Good understanding of enterprise-scale security management process and infrastructure
  • Exposure to current IT Security standards and regulations such as PCI-DSS, ISO 27001, SOX, DPA
  • Exposure to enterprise IT infrastructure and tools (e.g. MS Windows Server, Cisco, Linux)
  • Superior network infrastructure and protocol knowledge
Desirable:
  • Experience of transactional revenue, embedded, smartcards and mobile payment systems
  • Knowledge / experience of Security Architecture of major public cloud services e.g. Microsoft Azure, Amazon Web Services, Google Cloud, Cloud Access Service Brokers
  • Knowledge of cryptographic services
  • Knowledge of wider security, audit, risk and compliance standards e.g. PCI-P2PE, PCI-POI-PTS, ISO 27701, ISO27005, ISO31000, NIST, GDPR and governance/ risk/ compliance tools
  • Requirements analysis and tracing tools such as DOORS and SD Elements; OneTrust privacy tool
  • Understanding of security within DevOps and waterfall project methods, product development
  • Experience of application security testing tools and devops frameworks, e.g. SonarQube, JIRA, static & dynamic code analysis/ “fuzzing”
  • Development tools/ environments; Java, Visual Studio, C#
  • In depth understanding of information security control tools, e.g. Splunk, Crowdstrike, Trend Micro DeepSecurity, Imperva WAF, Tenable.IO/ Nessus, TripWire, Cisco IPS, F5, Centrify
  • Experience of quality management systems and external audit standards e.g. ISO 9001, ISAE3402
Personal Qualities
  • Must be able to work effectively and uphold professional standards and confidentiality with Cubic internal and external customers as well as staff at all levels of the organisation. The role will also be required to work with security vendors, Cubic suppliers and customers.
  • Self-motivated, able to work on own initiative and as part of a matrix team, unsupervised, and be recognized by their peers as inspirational and the “go-to” person for solving problems.
  • Able to juggle multiple tasks with deftness and attention to deadlines.
  • Strong analytical and influencing skills to assess demand for change and ensure that the necessary controls are in place to deliver successfully.
  • An enthusiasm for new technologies and their application for both business and consumers.
  • A natural curiosity and a passion for learning new skills “on the job”. A continuous improvement mindset.
  • The tenacity to keep going when things get difficult, an optimistic and upbeat personal manner
  • Strong verbal and written communications skills in English.
  • A degree of flexibility required in working time due to supporting a 24/7 operation and to liaise with colleagues in multiple time zones.
  • Candidate will be required to complete basic security checks.
The description provided above is not intended to be an exhaustive list of all job duties, responsibilities and requirements. Duties, responsibilities and requirements may change over time and according to business need.
Worker Type:
Employee
Refer code: 2964806. Cubic Corporation - The previous day - 2024-03-11 01:14

Cubic Corporation

Salfords, Surrey
Popular Security Architect jobs in top cities

Share jobs with friends

Related jobs

Security Architect

Cloud Security Architect

Eames Consulting

£700.00 - £800.00 per day

Surrey, England

4 months ago - seen

Cloud Security Architect

esure Group

Reigate, Surrey

5 months ago - seen

Cloud Security Architect - Contract

esure Group

Reigate, Surrey

5 months ago - seen

Cloud Security Architect

esure

Salary not specified

Surrey, England

5 months ago - seen

Cloud Security Architect - Contract

esure

Salary not specified

Surrey, England

5 months ago - seen

Cloud Security Architect

esure

Reigate, Surrey

5 months ago - seen

Senior Application Security Architect

Johnson Controls International

Competitive

Surrey, England

6 months ago - seen