
Job Description
The CSEA Contractor is expected to provide hands-on support to the Cyber Security
Engineering and Architecture section by contributing to security architecture
activities, technical security reviews, control implementation, risk
assessments and advisory services across enterprise systems, infrastructure,
cloud environments and applications.
The
contractor is expected to have:
- Hands-on experience with
Enterprise Security Architecture methodologies and modern security
technologies, including IAM, SIEM, EDR/XDR, WAF, SASE, Zero Trust, cloud
security, and security automation tools. - Strong knowledge of IT
infrastructure security, including network security, cloud security,
endpoint security, identity security, and secure architecture design
principles. - Strong knowledge of application
security, including secure SDLC, DevSecOps, API security, secure coding
practices, and application threat modeling. - Experience implementing,
validating, and reviewing security controls across IT infrastructure,
cloud platforms such as AWS, Azure, and GCP, and enterprise applications. - Experience developing,
maintaining, and enhancing security control libraries, security patterns,
baselines, and architecture standards, while ensuring their integration
into security architecture and engineering activities. - Strong understanding of
cybersecurity standards, laws, and frameworks, including NIST, ISO/IEC
27001, CIS Controls, GDPR, PCI-DSS, and other relevant regulatory or
compliance requirements. - Strong understanding of
cybersecurity best practices, including secure network architecture,
endpoint protection, identity and access management, cloud security,
DevSecOps, and defense-in-depth design. - Experience conducting security
design reviews, architecture assessments, threat modeling, technical risk
assessments, and security gap assessments.
Key
Deliverables:
The
contractor may be expected to support or deliver:
- Security architecture reviews
- Security design review reports
- Threat models and risk
assessments - Security control mapping and
recommendations - Architecture patterns,
baselines, and standards - Technical security advisory
reports - Secure design recommendations
for infrastructure, cloud, and applications - Security improvement roadmaps
- Support for incident response,
investigations, and technical analysis - Knowledge transfer sessions for
CSEA members
Requirements
Education:
- Bachelor’s
degree in a technology-related field, such as Cybersecurity, Computer Science,
Computer Engineering, Information Security, Information Technology, or a
related discipline. A higher degree or relevant professional certifications are
preferred.
Experience:
- Minimum of 10 years relevant experience in
cybersecurity, information security, security engineering, or IT infrastructure
security, with at least 3 years of hands-on experience in cybersecurity
architecture, security engineering, or enterprise security architecture.
Preferred Certifications:
- CISSP, CISM, SABSA, or TOGAF certifications preferred.
- Cloud security certifications such as CCSP, Azure Security Engineer, or AWS Security Specialty preferred.
- Cybersecurity certifications such as GCIH, GCIA, GSEC, or Security+ preferred.
- Other relevant cybersecurity, cloud security, or architecture certifications considered.
Proficiency in English & Arabic is
required.
Other jobs you might like
Working at BAE Systems

3 office days / week – Hybrid options are dependant on role and can range from fully remote to on-site full time

A little flex time – We offer a range of hybrid and flexible working arrangements depending on the role you apply for – explore your options with our recruiter during the application process.
