Cambridge, UK
UK travel and occasional international travel
Introduction
We're looking for graduates who are excited by the opportunity to make emerging technologies secure, trustworthy and resilient. You'll work on real-world engineering challenges across cyber security, artificial intelligence, embedded systems and connected technologies, supporting projects in areas including defence and security, industrial systems and critical national infrastructure.
You'll need to be curious, willing to learn and comfortable exploring unfamiliar technical problems. In return, we'll provide the support, mentoring and hands-on experience you need to develop into a confident, well-rounded security engineer working on innovative deep technology.
We're much more interested in the engineer you can become than the one you are now. We'll give you the time, support and opportunities to build your security engineering skills and develop the confidence to contribute to challenging client projects. Curiosity, a careful and structured approach to problem solving, and enthusiasm for technology are more important than having experience in every area of cyber security.
Overview
Cambridge Consultants develops deep technology across sensing, communications, embedded systems, artificial intelligence and complex systems. Our Trusted AI and Secure Technologies team helps clients understand, design and demonstrate security and trustworthiness in emerging and connected technologies.
You'll work as part of multidisciplinary teams alongside engineers and specialists in electronics, firmware, software, RF, AI and data science, and systems engineering. Projects can span the full engineering lifecycle, from early-stage concepts and requirements through to implementation, verification, deployment and in-service support.
Our work includes cyber security, secure-by-design engineering, embedded and connected systems, industrial and critical infrastructure, defence and national security, edge AI, secure connectivity and post-quantum cryptography.
Your responsibilities
You'll work on real client assignments with support and guidance from experienced engineers. You'll have opportunities to contribute across different stages of the engineering lifecycle and work alongside specialists from across Cambridge Consultants.
You may contribute to projects at different stages of the engineering lifecycle, from early-stage concept development and requirements through to architecture, implementation, verification, deployment and in-service support.
You'll also have opportunities to interact directly with clients, including requirements discussions, technical workshops, progress updates and delivery, with support from experienced engineers where appropriate.
What you'll be doing
- Contributing to threat modelling, attack-surface analysis and security risk assessments.
- Helping to identify security requirements and develop secure-by-design system architectures.
- Supporting vulnerability assessments and security testing, including helping to scope testing activities and track remediation.
- Investigating vulnerabilities and helping teams understand and address security risks.
- Contributing to security cases, assurance activities and technical documentation.
- Analysing systems, software and technical designs to identify potential security weaknesses.
- Developing prototypes, analysis tools or other technical solutions to investigate security problems.
- Working with multidisciplinary teams to understand the interaction between security, functionality, safety and system performance.
- Communicating technical findings clearly to engineers, project teams and customers.
Domains and project types
You could work across a range of applications and technologies, including:
- Critical national infrastructure: energy, transport, communications and utilities.
- Industrial systems: ICS, SCADA, OT and industrial IoT.
- Defence and national security: secure systems and technologies supporting demanding operational environments.
- Emerging technologies: AI assurance, sensing, secure connectivity and post-quantum cryptography.
What you can bring
The below is essential
- An excellent degree or PhD in Computer Science, Cyber Security, Electronic/Electrical Engineering, Systems Engineering, Physics or a related technical discipline.
- 12 months industrial experience, for example through a placement year or relevant postgraduate experience.
- A good understanding of fundamental engineering, computing or security principles.
- Practical experience through university, industrial placement, work experience, research or personal projects in at least one or more relevant areas, such as:
-
- cyber/security engineering
- software or application development
- embedded systems
- computer or network systems
- electronics or hardware security
- AI or data science
- systems engineering
- The ability to understand and analyse technical systems and identify risks or weaknesses.
- Some familiarity with security concepts such as authentication, authorisation, cryptography, key management, secure boot, network security and secure development.
- The ability to read and understand code in languages such as C, C++, Python or Java.
- Enthusiasm for learning and developing new technical skills.
- A careful and structured approach to problem solving.
- Clear communication skills and the ability to work collaboratively with others.
The below is advantageous, but isn't essential
- Familiarity with threat-modelling approaches such as STRIDE or MITRE ATT&CK.
- Knowledge of secure development practices and frameworks such as OWASP or CWE.
- Experience with embedded platforms, MCUs, RTOS, TPMs or TrustZone.
- Familiarity with industrial protocols and standards such as Modbus, DNP3, OPC UA or IEC 62443.
- Experience using tools such as Burp Suite, Wireshark or firmware-analysis tools.
- An understanding of cloud security.
- Experience considering security alongside safety or other system-level requirements.
- Security research, university projects, technical projects or open-source contributions.
- Industry certifications or formal security training.
Some projects at Cambridge Consultants are subject to security restrictions. This role requires you to obtain a Security Check level security clearance ( https://www.gov.uk/guidance/united-kingdom-security-vetting-applicant ). You must be able to work in the UK without restrictions in accordance with UK National Law and be prepared to successfully undertake an appropriate level of UK National Security Vetting according to UK Government National Security Vetting criteria.
Along with your CV, please describe why you are attracted to this position, what you feel you offer Cambridge Consultants, and any achievements that you are particularly proud of. We are especially interested to hear about any projects you have done, for a hobby, for work or for university.
By submitting an application to Cambridge Consultants, you confirm that the information provided in this application, together with any supporting documentation, is true, complete, and accurate to the best of your knowledge and belief. You understand that any false statement, misleading information, or material omission may render you liable to disqualification from the recruitment process, withdrawal of any offer of employment, or dismissal without notice if discovered following appointment. You acknowledge that the organisation reserves the right to verify the information supplied.