Job
SBD Specialist - Secure By Design
Secure by Design (SbD) Specialist - MOD Project (Inside IR35)
Role: Secure by Design (SbD) Specialist
Location: UK (Hybrid / On-site as required)
Contract: Inside IR35
Duration: 6 months initial (likely extension)
Clearance: Active SC required - DV highly desirable
Client: UK MOD Programme
Rate: £500 to £550 per day
Role Overview
We are seeking an experienced Secure by Design (SbD) Specialist to support delivery within a UK MOD environment. The role will focus on embedding security principles into system and solution design, ensuring compliance with MOD and UK Government security standards.
You will work closely with architects, engineers, and security teams to ensure security is integrated across the full development lifecycle and aligned to programme risk and assurance requirements.
Key Responsibilities
- Embed Secure by Design principles across system and solution delivery
- Conduct security design reviews and provide risk-based recommendations
- Support development of:
- Security architectures
- Threat models and risk assessments
- Security design documentation
- Ensure alignment with MOD and UK Government security standards
- Work with architects and delivery teams to integrate security into Agile and DevSecOps environments
- Support security assurance and accreditation activities
- Identify and manage design-level security risks
Essential Experience
- Proven experience implementing Secure by Design within MOD, Defence, or Government environments
- Strong background in security architecture and secure system design
- Experience conducting threat modelling and security risk assessments
- Knowledge of:
- NCSC Secure by Design guidance
- ISO 27001 or equivalent frameworks
- Secure SDLC methodologies
- Experience working within regulated, high-assurance environments
- Strong stakeholder engagement and documentation skills
- Active SC Clearance (minimum requirement)
Desirable
- DV Clearance
- Experience working on MOD programmes
- Knowledge of:
- JSP 440
- HMG Security Policy Framework
- Cloud security (Azure or AWS)
- Relevant certifications (e.g., CISSP, CISM, SABSA)

