Expert
Job Description:
Leonardo is an international industrial group, one of the world's leading players in Aerospace, Defense, and Security, creating multi-domain technological capabilities in Helicopters, Aircraft, Aerostructures, Electronics, Cyber Security, and Space. With over 60,000 employees worldwide, the company has a strong industrial presence in Italy, the United Kingdom, Poland, and the United States, and operates in 150 countries, including through subsidiaries, joint ventures, and investments. A key player in major global strategic programs, it is a technological and industrial partner for Governments, Defense Administrations, Institutions, and businesses.
Leonardo is one of the strategic industrial partners in the GCAP (Global Combat Air Programme), alongside the UK's BAE Systems and Japan's Mitsubishi Heavy Industries. This program aims to develop and deliver a new generation air system, defined as a “system of systems.” Used for multi-domain defense operations, the system will feature a “core platform” connected to other peripheral systems, or “adjuncts,” both manned and unmanned.
The program, one of the most challenging and futuristic for the aerospace and defense industries, will drive the technological revolution that will characterize the sector for the next fifty years. It is a challenge aimed at strengthening the technological and industrial sovereignty of the participating countries, as it focuses on identifying and making available those innovative, enabling technologies that will ensure a generational leap, generating positive returns and economic and social progress for the entire country, benefiting new generations.
Those working on this program will have the opportunity to access a career growth path in an internationally competitive and technologically advanced environment.
Within the Joint Venture established for the implementation of the GCAP Program, we are looking for a Secure by Design Lead Specialist for the GCAP Headquarters located in Reading (UK).
JOB PURPOSE:
The Secure by Design Lead Specialist is responsible for integrating security principles into the design and delivery of Edgewing systems, applications, and services from the outset. This role guides specific architecture, threat modeling, and assurance activities, defining standards and reference criteria. Furthermore, it ensures that security is considered early in the project lifecycle, reducing risk, preventing vulnerabilities, and supporting the delivery of secure, resilient, and compliant solutions, aligned with organizational standards and acceptable risk levels.
RESPONSIBILITIES:
The resource will be part of the Governance function for the JV and will report directly to the Secure by Design Manager.
DUTIES:
Lead the implementation of Secure by Design principles across projects, programs, and throughout the product lifecycle
Provide expert security design advice to technology, digital, and business teams
Review and evaluate solution architectures, technical designs, and project proposals
Early identification of security risks in the design phases and proposal of proportionate controls
Develop and maintain Secure by Design standards, patterns, and guidelines
Support threat modeling activities and secure architecture reviews
Collaborate with development, engineering, cloud, and infrastructure teams
Ensure alignment with security policies, standards, and regulatory requirements
Support assurance, testing, and approval activities for new or modified services
Promote a culture of security and good design practices within the organization
Contribute to the continuous improvement of security architecture and design processes
REQUIREMENTS:
Qualification: Degree or equivalent qualification in cybersecurity, computer science, engineering, or a related discipline
Technical Knowledge and skills:
Relevant professional certifications (or working towards), including:
CISSP, CSSLP, or CISM
SABSA, TOGAF, or similar architecture certifications
Cloud security or application security certifications
Essential requirements:
Strong experience in secure system, application, or solution design
In-depth understanding of Secure by Design and security architecture principles
Experience in conducting security design reviews and threat modeling activities
Strong knowledge of common security risks and associated mitigation techniques
Ability to evaluate complex technical designs and identify potential security gaps
Excellent communication skills, including the ability to explain security concepts to non-technical stakeholders
Desirable requirements:
Experience in cloud-native, DevSecOps, or agile delivery environments
Knowledge of application security testing techniques and secure coding practices
Experience in regulated or high-risk environments
Familiarity with security frameworks and standards (e.g., ISO 27001, NIST)
Experience supporting large-scale transformation or digital initiatives
Understanding of data protection and privacy-by-design principles
Language skills: English C1
Leonardo is an international industrial group and one of the world’s leading players in Aerospace, Defense, and Security, specialized in multi-domain technological capabilities in the fields of Helicopters, Aircraft, Aerostructures, Electronics, Cyber Security, and Space. With over 60,000 employees worldwide, the company has a strong industrial presence in Italy, the United Kingdom, Poland, and the United States, and operates in 150 countries, including through subsidiaries, joint ventures, and investments. A key player in major global strategic programs, Leonardo is a technological and industrial partner for governments, defense administrations, institutions, and businesses.
Leonardo is one of the strategic industrial partners in the GCAP (Global Combat Air Program), alongside the UK’s BAE Systems and Japan’s Mitsubishi Heavy Industries. This program aims to develop and deliver a next-generation air system, defined as a “system of systems.” Used for multi-domain defense operations, the system will feature a “core platform” connected to other peripheral systems, or “adjuncts,” both manned and unmanned.
This program, one of the most ambitious and forward-thinking in the aerospace and defense industries, will drive the technological revolution that will define the sector for the next fifty years. It is a challenge aimed at strengthening the technological and industrial sovereignty of the participating countries, as it focuses on identifying and making available enabling technologies that will ensure a generational leap. These technologies will generate positive returns, contributing to the economic and social progress of the entire nation, benefiting future generations.
Those working on this program will have the opportunity to access a career growth path in an internationally competitive and technologically advanced environment.
JOB TITLE:
Within the GCAP Joint Venture Security, we are looking for a Secure by Design Lead Specialist for GCAP HQ in Reading (UK).
JOB PURPOSE:
The Secure by Design Lead Specialist is responsible for embedding security principles into the design and delivery of Edgewing systems, applications, and services from the outset. The role leads specific architecture, threat modelling, and assurance activities and sets standards. The role also ensures security is considered early in the lifecycle of change and transformation initiatives, reducing risk, preventing vulnerabilities, and enabling the delivery of secure, resilient, and compliant solutions aligned to organizational standards and risk appetite.
RESPONSIBILITIES:
The role will be part of the Governance function for the JV and will report directly to the Secure by Design Manager.
OBJECTIVES:
Lead the implementation of Secure by Design principles across projects, programmes, and product lifecycles
Provide expert security design guidance to technology, digital, and business teams
Review and assess solution architectures, designs, and technical proposals
Identify security risks early in the design phase and recommend proportionate controls
Develop and maintain Secure by Design standards, patterns, and guidance
Support threat modelling and secure architecture reviews
Collaborate with development, engineering, cloud, and infrastructure teams
Ensure alignment with security policies, standards, and regulatory requirements
Support assurance, testing, and sign-off activities for new and changed services
Promote security awareness and good design practices across the organization
Contribute to continuous improvement of security architecture and design processes
REQUIREMENTS:
Qualification: Degree or equivalent qualification in cybersecurity, computer science, engineering, or a related discipline
Technical Knowledge and skills:
Relevant professional certification (or working towards), such as:
CISSP, CSSLP, or CISM
SABSA, TOGAF, or similar architecture certifications
Cloud security or application security certifications
Essential requirements:
Strong experience in secure system, application, or solution design
In-depth understanding of Secure by Design and security architecture principles
Experience conducting security design reviews and threat modelling
Strong knowledge of common security risks and mitigation techniques
Ability to assess complex technical designs and identify security gaps
Strong communication skills, including explaining security concepts to non-specialists
Desirable requirements:
Experience with cloud-native, DevSecOps, or agile delivery environments
Knowledge of application security testing and secure coding practices
Experience working in regulated or high-risk environments
Familiarity with security frameworks and standards (e.g. ISO 27001, NIST)
Experience supporting large-scale transformation or digital programmes
Understanding of data protection and privacy-by-design principles
Language skills: English C1
Seniority: Expert
Primary Location: IT - Roma - Via Montello
Contract Type: Permanent
Hybrid Working: Hybrid
Sign up to apply and find out right away if you're a fit.
Your agent will tell you — in seconds.
Sign up and I'll tell you right away how well Leonardo matches you — what you already have, and what's missing. Then I stay on it: I search for you and only write when I find something worth your time.