Navy Command - Project Cybersecurity Officer
Ministry of Defence
Job at a glance
Job summary At Navy Command, we lead, support, and sustain the Royal Navy across every theatre of operations. We coordinate the people, platforms, and missions that keep the Fleet ready for today’s challenges and tomorrow’s opportunities. Together, we uphold centuries of naval tradition while driving innovation that ensures the Royal Navy’s readiness to protect our nation and secure our future. As the authority for the Royal Navy’s nuclear submarine capability, the Submarine Directorate oversees one of the most complex and critical elements of UK defence.
Covering everything from in‑service management to long‑term fleet modernisation, the directorate ensures the Submarine Flotilla remains safe, reliable, and ready to meet national security requirements. You'll be based at HMNB Devonport, the largest naval base in Western Europe and a powerhouse of Royal Navy capability. It is home to amphibious ships, survey squadrons, submarines, and two-thirds of the frigate force.
With its unique nuclear refitting facility, Devonport ensures the Fleet remains ready to support operations worldwide. This position is advertised at 37 hours per week. Job description Are you ready to put your cyber skills to work where they really matter? We’re looking for a curious, confident and forward-thinking Project Cyber Security Officer to help protect critical systems, support exciting projects, and embed secure-by-design thinking across HM Naval Base Devonport.
This is a fantastic opportunity to be at the heart of a busy and unique Defence environment, working with a wide range of stakeholders to spot risks, solve problems, and make sure security is built in from the very start.What you will do: Identify, assess, and manage cyber security risks associated with project systems, networks, data, and suppliers. Develop, maintain, and apply project cyber security risk management and incident response arrangements.
Ensure compliance with relevant cyber security policies, standards, and regulatory requirements. Embed cyber security controls into system design, development, implementation, testing, and acceptance activities. Coordinate security testing and assurance activity, including vulnerability assessment, penetration testing, and remediation tracking. Protect project services and information from cyber threats, including unauthorised access, malicious activity, data loss, and system compromise.
Provide timely cyber security advice to project teams, stakeholders, and leadership during planning, delivery, and transition phases. Support the development and maintenance of proportionate security plans, procedures, and assurance artefacts. Conduct audits, reviews, and inspections, and ensure that findings are addressed through agreed actions. Monitor the effectiveness of implemented controls and report risks, issues, and assurance outcomes to project and security leadership.
Maintain accurate records of cyber security activities, incidents, decisions, and evidence to support governance and audit requirements. Promote alignment between cyber, physical, and business continuity arrangements across the project environment. Person specification To be successful with your application, you'll need to show that you meet the following essential criteria: Experience of working in a cyber security, information assurance, IT security, protective security, or technical risk management environment.
A good understanding of cyber security principles, including secure-by-design, risk management, vulnerability management, and the protection of systems, networks and information. Ability to identify, assess and communicate cyber security risks clearly to stakeholders. Experience of working collaboratively with multiple stakeholders to support delivery of secure outcomes. Strong written and verbal communication skills, with the ability to produce clear advice, reports, records and assurance evidence.
Ability to prioritise work, manage competing demands and deliver at pace in a bu