Rowden Logo

Rowden

Senior Cyber Security Engineer

Posted 6 Days Ago
Be an Early Applicant
Hybrid
Bristol, England
Senior level
Hybrid
Bristol, England
Senior level
Designs, implements, and maintains cybersecurity controls for cloud, software, network, and far-edge systems. Responsibilities include threat modeling, risk assessments, vulnerability management, security assurance, accreditation evidence, audit support, incident response, compliance monitoring, and supply-chain security. The engineer advises delivery teams, collaborates with external partners, supports secure system architecture, and represents the company in security forums. The role is hybrid with at least three days weekly onsite in Bristol and occasional customer-site travel.
The summary above was generated by AI
We’re building the UK's next generation engineering powerhouse, providing critical technology that strengthens national security and resilience.
 
We specialise in turning advances in sensing, AI, and communications into operational capability for the edge, where connectivity may be degraded or denied. Our work focuses on accelerating the deployment of technology, improving decision-making for frontline teams, and protecting people and critical assets in demanding environments.
Headquartered in Bristol, Rowden employs around 200 people and operates over 20,000 square feet of engineering and manufacturing facilities. We have a growing international footprint and are one of Europe’s fastest-growing engineering businesses.
About the role
 
As a Senior Cyber Security Engineer at Rowden, you’ll collaborate closely with the wider engineering team to design, implement, and maintain secure systems and infrastructure. You will be embedded within a delivery team(s) and work closely with the Technical Security Lead and external partners to assess risks, define security requirements, and ensure technical solutions are pragmatic, proportionate, and aligned with both business and customer needs.
 
Your focus will span both strategic and tactical aspects of security engineering. At a strategic level, you’ll contribute to high-level design and planning across areas such as secure network architecture, identity management, and cloud security. At a tactical level, you’ll be hands-on with implementation, working directly with systems, tools, and configurations to apply and validate security controls, troubleshoot issues, and support secure delivery. You’ll collaborate with the wider engineering community to ensure agreed controls are effectively embedded, and that all systems are resilient, compliant, and aligned with current security standards.
 
The ideal candidate will bring knowledge of threat modelling, secure system design, and compliance frameworks including NIST, ISO 27001, and DefStan 05-139. We understand that even experienced professionals may not have expertise across every aspect of the role. If you bring relevant experience, sound technical judgement, and a passion for delivering secure solutions, we encourage you to apply. 
This role requires a minimum of 3 days per week on-site at our Bristol HQ with occasional travel to customer sites.
 
Candidates must be eligible for SC clearance. Due to the nature of this role and the sensitivity of the work involved, applications are restricted to sole UK nationals.
 
More information about security clearance is available here: https://www.gov.uk/government/publications/united-kingdom-security-vetting-clearance-levels

Key areas of responsibility
As a Senior Cyber Security Engineer you will be responsible for: 
  • Implementing and maintaining system security controls and operating procedures, ensuring alignment with MOD and Rowden standards.
  • Supporting the delivery of cyber security assurance activities, including documentation, testing, and reporting.
  • Collaborating with project teams and external partners to deliver on agreed security deliverables and schedules.
  • Participating in security risk assessments, threat modelling, and vulnerability management for cloud, software, and far-edge deployments.
  • Contributing to the security accreditation process, preparing evidence, managing asset registers and supporting audits as required.
  • Assisting in the continuous improvement of security processes, incident response, and compliance monitoring.
  • Engaging with supply chain partners to verify and assure security requirements throughout the capability lifecycle.
  • Providing technical advice and hands-on support to engineering teams, acting as a security champion within agile delivery teams.
  • Representing Rowden in internal and external security forums.

Key skills, experience and behaviours
Essential
  • Proven experience in cyber security engineering, ideally within defence, government, or critical infrastructure environments.
  • Strong understanding of Secure by Design, risk management, and MOD security standards.
  • Hands-on experience with cloud security, software assurance, and network security controls.
  • Familiarity with security accreditation processes (e.g., RMADS, JSP 440/604, NCSC guidance).
  • Ability to interpret and deliver against SOWs and SORs, working collaboratively with external assurance providers.
  • Excellent communication skills, with the ability to explain complex security concepts to technical and non-technical stakeholders.
  • Strong analytical, documentation, and problem-solving skills.
Desirable
  • Experience of tactical networked C4I systems, including Opnet.
  • Knowledge of multi-domain systems and cross-domain solutions.
  • Understanding of LOS & BLOS communication systems.
  • Awareness of UK Government LETacCIS programmes and systems such as DSA, Morpheus, Trinity and Bowman.
About you
The ideal candidate will have a strong balance of technical skills and experience, and the behavioural competencies that we believe are key to success in the role are as follows:
  • Extensive experience in software development environments and infrastructure delivery, with a solid engineering foundation, ideally in software engineering.
  • In-depth knowledge of Secure by Design principles and their application in secure systems architecture.
  • Proficiency in securing cloud infrastructure, software, far edge networking, and integrated systems.
  • Strong analytical and risk management skills, with a focus on continuous security improvement.
  • Ability to work within cross-functional teams to achieve secure, compliant solutions.

Working at Rowden
We are committed to building a flexible, inclusive, and enabling company. Our aim is to create a diverse team of talented people with unique skills, experience, and backgrounds, so please apply and come as you are!
 
We also recognise the importance of flexible working and support this wherever we can. We typically operate a flexible, hybrid-working model, with an average 3 days in the office each week (dependent on the role). We welcome the opportunity to discuss flexibility, part-time working requirements and/or workplace adjustments with all our applicants.
 
Rowden is a Disability Confident Committed company, and we actively encourage people with disabilities and health conditions to apply for our roles. Please let us know your requirements early on so that we can make sure you have everything you need up front to help make the recruitment process and experience as easy as possible.
 
Finally, if you feel that you don’t meet all the criteria included above but have transferable skills and relevant experience, we’d still love to hear from you!

About
What matters to us?  Our focus is on the end user. We exist to deliver the best possible outcomes for the users of our systems. Pace matters. The problems we solve are urgent.  Our diverse skills and backgrounds make us better. Our team prides itself on being inclusive and multidisciplinary. We are radically honest. Saying what we mean, even when it isn’t easy. We are pragmatists. We provide realistic, focused solutions that get to the point. We improve continuously. We are relentless in our drive to make things better.

Similar Jobs

15 Days Ago
In-Office
Senior level
Senior level
Energy
Design, implement, and maintain cybersecurity solutions for subsea production systems, SCADA environments, and OT infrastructure. Conduct risk assessments, threat modeling, vulnerability analysis, security reviews, and audits. Develop secure architectures, network segmentation, remote access, monitoring, authentication, encryption, and certificate-management controls. Support incident response, root-cause analysis, compliance, customer engagements, and technical documentation. Mentor junior engineers and collaborate with engineering, software, and product teams to secure industrial protocols and safety-critical systems.
Top Skills: AuthenticationCertificate ManagementEncryptionEthernet/IpFirewallsHmiIds/IpsIec 62443Industrial Control SystemsIso 27001Key InfrastructureModbus Tcp/IpNetwork SegmentationNistOpc UaOt SecurityPenetration TestingPlcScadaTcp/IpVpnsVulnerability Management
20 Days Ago
In-Office or Remote
London, Greater London, England, GBR
Senior level
Senior level
Utilities
Design and implement security for a cloud-native B2B SaaS platform. Responsibilities include cloud and Kubernetes security, threat modeling, application and infrastructure hardening, vulnerability management, detection and incident response, security automation, and compliance assurance. The role partners with Engineering, SRE, Risk, Product, Legal, and InfoSec teams to embed secure-by-design practices, automate controls through infrastructure as code and CI/CD, and improve security metrics, detection capabilities, and regulatory readiness.
Top Skills: AWSBashCi/CdCloudFormationDastEdrGoIamIdentity ProvidersIdsInfrastructure As CodeKmsKubernetesPythonSastSecure Web GatewaysTerraformWaf
22 Days Ago
In-Office
London, Greater London, England, GBR
Senior level
Senior level
eCommerce
Lead and mature enterprise threat intelligence and vulnerability management programs. Monitor global threats, manage TIP/SIEM/SOAR integrations, run risk-based vulnerability assessments, drive remediation with infrastructure teams, automate workflows, and produce executive-level reports on risk and remediation status.
Top Skills: AIApi IntegrationsAutomationCveMitre Att&CkNist CsfOrchestrationOsintOwasp Top 10PowershellPythonSIEMSoarThreat FeedsThreat Intelligence Platform (Tip)Vulnerability Scanning Tools

What you need to know about the London Tech Scene

London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account