We are seeking an experienced Cyber Security Architect to design, document and govern the security architecture underpinning our technology estate. You will define target-state security designs and reference architectures across cloud, network, identity, endpoint and data domains; translate business risk, regulatory obligations and threat intelligence into practical, proportionate controls; and act as the design authority for change - reviewing solution designs, challenging assumptions and signing off architectural decisions.
Working closely with engineering, infrastructure, application and operations teams, you will embed security-by-design and zero-trust principles into projects from inception, produce threat models and control matrices, define security standards and patterns for reuse, and support assurance activities including risk assessments, penetration testing and audit. You will also advise senior stakeholders on the security implications of strategic initiatives, maintain a forward-looking roadmap of capability improvements, and mentor engineers and analysts in secure design practice.
The successful candidate will have significant experience in security architecture or senior security engineering, strong knowledge of identity and access management, network and cloud security, encryption and secure development practices, familiarity with recognised frameworks and standards (eg NIST CSF, ISO 27001, CIS, MITRE ATT&CK, SABSA/TOGAF), and the communication skills to explain complex risk clearly to both technical and non-technical audiences. Relevant certifications (CISSP, CCSP, SABSA, cloud security certifications) are desirable.
3 days per week on site, 2 days remote. £650/day inside IR35