Job description
Job Title\: Information Security Consultant
Location\: Portsmouth Naval Base - Remote Working Available with some occasional travel to site working
Grade\: GG10
You’re expected to have completed 12 months in role prior to applying for an advertised vacancy and you should also discuss the internal opportunity with your line manager to ensure sustained business continuity and to further support your career development.
We know there may be exceptional individual circumstances that impact this, in the first instance please discuss this with your line manager.
If you don’t feel you can talk to your line manager, you can contact your HRBP.
PLEASE NOTE\: Should you be invited for interview; you acknowledge that the Recruitment team will contact you and your line manager regarding your application for this opportunity.
Who we are\:
Join BAE Systems and you’ll be part of something bigger. As a valued member of our global colleague network, you’ll bring your unique skills and perspectives to help pioneer progress and protect what matters most. You’ll be trusted to play your part in delivering the advanced, technology-led defence, aerospace and security solutions of tomorrow, shaping a safer future, for all of us.
From the depths of the ocean, to the far reaches of space, there’s no limit to where a career at BAE Systems could take you.
Job Description\:
This role is responsible for developing and maintaining Security Operating Procedures to ensure employees handle systems and classified information in line with MOD and BAE Systems security standards. The position also leads security improvement projects, conducts assurance activities to identify risks and gaps in information security processes, and implements remediation plans to strengthen compliance. Additionally, the role provides travel security guidance, reviewing requests and ensuring employees receive the appropriate advice, materials, and support in collaboration with Export Control and wide
Core duties\:
- Develop and maintain Security Operating Procedures (SyOps), ensuring systems are used, managed and governed in line with information security policies, standards and best practices.
- Support the organisation's travel security processes by reviewing travel requests, providing security guidance, and coordinating the supply of protective equipment and resources.
- Lead and deliver information security improvement initiatives, driving enhancements to processes, controls and ways of working across the business.
- Provide information security representation within working groups and projects, offering specialist advice and ensuring compliance with internal and external security requirements.
- Assess security risks, identify vulnerabilities and process gaps, and recommend practical solutions that strengthen security while supporting business operations.
- Drive continuous improvement through the development of improved security processes, controls and governance frameworks that reduce risk and increase effectiveness.
- Act as a trusted security advisor, working independently to resolve information security issues and provide guidance to stakeholders across the business.
- Ensure adherence to company, defence and industry security standards, applying best practice to support secure and compliant business operations.
Essential Skills\:
- Strong understanding of cyber and information security principles, including industry standards and frameworks such as ISO 27001, NIST 800-53, DEFSTANs and UK Government security classifications.
- Experience applying Secure by Design principles, managing security risks, and implementing appropriate controls throughout the system lifecycle.
- Proven ability to create clear, concise policies, procedures and security guidance that translate complex technical concepts into practical instructions for end users.
- Skilled in identifying security gaps, assessing compliance, investigating issues, and recommending effective solutions to improve security posture and operational effectiveness.
- Confident working with cross-functional teams, presenting to both technical and non-technical audiences, and building strong relationships to drive collaboration and positive security outcomes.
The Information Security Team\:
The Information Security team is responsible for leading information security incident investigations, managing security risk across the business, ensuring Information Security protocols and policies are complied with, and providing day-to-day security support and guidance to stakeholders. Working closely with Cyber Security teams, Engineering functions, Maritime programmes, and other Information Security Managers across other business units, you will collaborate across a diverse and complex environment to ensure risks and processes are effectively managed, and security obligations are met in line with government and BAE Systems standards.
Why BAE Systems?
Here you’ll build a career with purpose and limitless possibilities. With lifelong learning and meaningful work, this is a place where you can grow your career with confidence and be empowered to be your best. You’ll be recognised for your contribution and enjoy rewards tailored to what’s most important to you and your family, support for your financial and personal wellbeing, as well as a balanced lifestyle. In an environment embracing sustainable ways of working and with a strong sense of shared purpose, our supportive culture is a place you can feel you belong and proud of the difference you make.
A place where everyone can thrive\:
We’re committed to building an inclusive workplace where everyone feels valued and supported. We know that a diversity of backgrounds, perspectives and experiences strengthens our teams and is vital to the work we do.
We welcome applications from all suitably qualified people, who are BAE Systems employees and have been in their current role for 12 months or longer.
Please be aware that many roles at BAE Systems are subject to both security and export control restrictions. These restrictions mean that factors such as your nationality, any nationalities you may have previously held, and your place of birth can restrict the roles you are eligible to perform within the organisation. All applicants must as a minimum achieve Baseline Personnel Security Standard. Many roles also require higher levels of National Security Vetting where applicants must typically have 5 to 10 years of continuous residency in the UK depending on the vetting level required for the role, to allow for meaningful security vetting checks.
Closing Date\: 23rd October 2026
We reserve the right to close this vacancy early if we receive sufficient applications for the role. Therefore, if you are interested, please submit your application as early as possible.
#LI-RG1
#LI-Hybrid