CRP – Secure at Reach – Cyber Security Engineer (CSC)

Closing date for applications: 25/01/2023
OVERVIEW OF ROLE
Specialist role
Cyber security consultant
Summary of the work
Support the project to define and mature the cyber security assessment framework/methodologies based on approach on the various assessments conducted by the project.
Latest start date
06/03/2023
Expected contract length
12 months, with an option to extend by a further 6 months, subject to financial approvals.
Location
No specific location, for example they can work remotely
Organisation the work is for
Strategic Command (UKStratCom) part of the Ministry of Defence (MoD)
Maximum day rate
£700
ABOUT THE WORK
Early market engagement
Who the specialist will work with
Working with Project Manager and Project Technical Lead. Specialist will be part of the core team and will work within the core team to establish work streams that will involve different suppliers where applicable.
What the specialist will work on
To develop a proven & robust process, backed up with policy and technology that will provide cyber risk identification and reduction in the deployed environment. This also include the provision of high priority risk reduction where required.
WORK SETUP
Address where the work will take place
London / Corsham (DD CRP) / Occasional Work at UK Military Sites
Working arrangements
Hybrid working, where the core team will meet at least once every week (London) and work with assessment locations, e.g. base station of an operation. This will be determined based on the work being undertaken.
Security clearance
Minimum of SC level clearance, DV-held preferred. Clearance must be in place prior to the contract start date and remain valid for the contract duration.
ADDITIONAL INFORMATION
Additional terms and conditions
T&S will be reimbursable when travelling to alternate locations (to be confirmed). All expenses must be pre-agreed between the parties and must comply with the MOD Travel and Subsistence (T&S) Policy.Off-payroll working rules apply (IR35 in-scope). Any Personal Services Company (PSC) candidates will require to come through an umbrella company.Risk Assessment Ref: RAR-458663198Cyber risk profile: HighPotential bidders are required to complete a Supplier Assurance Questionnaire (SAQ) against the security controls appropriate to the risk level. Tenderers should complete their SAQ using the form in the following link: https://forms.office.com/Pages/ResponsePage.aspx?id=7WB3vlNZS0iuldChbfoJ5Tv4OR9pb0BHial1Ag-WKXVUOFk3Sk9SS0JDQ0FRWjhYNDhTVldHUDJaNy4u
EVALUATION CRITERIA
How many specialists to evaluate
3
Cultural fit criteria
-> Work as a team with our organisation and other suppliers [collaboration across defence and its service providers] [5%] -> Be transparent and collaborative when making decisions [Recording all artefacts that support the decision making / rational] [5%] -> Take responsibility for their Work [Accountability - ability to identify potential blockers, working with multiple stakeholders / contributors to transparently achieve resolution] [5%] -> Share knowledge and experience with other team members [Building the project knowledge based through sharing of information / artefacts / documentation to support onboarding and growth within organisation. [5%]
Assessment methods
Evaluation weighting
Technical competence 60% Cultural fit 20% Price 20%
EXPERIENCE
Essential skills and experience
  • Experience of conducting Cyber Security engagements on industrial plants or critical network infrastructures including risk assessment/management and deployment of appropriate security measures
  • Experience in solution analysis from vulnerability management, prioritisation of cyber risks and establishing mechanisms or change management procedures to ensure secure operations of the infrastructure / systems
  • Experience in development, planning, and deployment of security measures including monitoring of remediation activities to completion
  • Experience in system patching, deployment of specialised controls, standards, procedures or infrastructure changes to deliver a strong vulnerability remediation plan
  • Ability to identify risk criticality and urgency to inform remediation strategies/plans
  • Experience in Windows or Linux systems (preferably embedded systems, SCADA, CANBus, Profibus, PLCs, sensors, etc.
  • MoD Background or Military with joint effects background preferred
Nice-to-have skills and experience
  • Have critical national infrastructure projects experience
  • Proven experience / expertise in Assessment of Operational Technology / Internet of Things systems using IEC 62443 or relevant frameworks e.g. NIST CSF, CAF or others
  • Relevant Certified Cyber Professional (CCP) qualifications

Closing date for applications: 25/01/2023

CRP – Secure at Reach – Cyber Security Engineer (CSC)

Closing date for applications: 25/01/2023


Specialist role:

Cyber security consultant

Location:

No specific location, for example they can work remotely

Organisation:

Strategic Command (UKStratCom) part of the Ministry of Defence (MoD)

Maximum day rate:

£700

FULL DETAILS / EXPRESS INTEREST HERE
IT Recruitment Marketplace
The Hive Enterprise Centre, Victoria Avenue
Southend-on-Sea, Essex SS2 6EX
© IT Recruitment Marketplace
To change your subscription email us here