Key Responsibilities
- Lead the design and delivery of end-to-end security architecture across enterprise applications, platforms and cloud environments.
- Develop high-level security designs and translate business, technology and risk requirements into practical security architecture.
- Define and maintain security architecture principles, standards, patterns and reusable design guidance.
- Provide architecture governance and design assurance, challenging proposed solutions and ensuring security requirements are addressed throughout the delivery lifecycle.
- Act as a Subject Matter Expert for Data Protection and Cloud Security, providing technical guidance to architecture, engineering and business teams.
- Design and govern enterprise data protection and data security controls, including:
- Data discovery and inventory
- Data classification and sensitivity labelling
- Data Loss Prevention (DLP)
- Data governance
- Data retention and disposal
- Data lifecycle controls
- Protection of structured and unstructured information
- Encryption and access controls
- Support the secure design and adoption of Microsoft Azure, alongside AWS, SaaS and hybrid-cloud environments.
- Ensure appropriate security controls across applications, infrastructure, identities, networks and data.
- Translate cyber risks and regulatory requirements into appropriate security controls and non-functional requirements (NFRs).
- Conduct and support security architecture reviews, threat/risk assessments and design validation.
- Work closely with Enterprise Architecture, Engineering, Cloud, DevSecOps, Risk, Compliance and CISO teams.
- Identify gaps within the existing security landscape and recommend improvements.
- Support secure technology adoption and major transformation initiatives.
Essential Experience
- We are looking for candidates with strong experience across both Security Architecture and Data/Cloud Security.
- You should have:
- Significant experience as a Security Architect, Cyber Security Architect, Security Solution Architect or Enterprise Security Architect.
- Proven experience delivering end-to-end security architecture within large and complex organisations.
- Strong knowledge of security architecture governance, including standards, patterns, design reviews and architecture assurance.
- Strong Data Protection / Data Security Architecture experience.
- Experience with data classification, discovery, inventory, labelling, governance, retention/disposal and lifecycle controls.
- Understanding of security controls for both structured and unstructured data.
- Strong Microsoft Azure Security architecture experience.
- Good knowledge of AWS, SaaS and hybrid/multi-cloud security.
- Experience securing enterprise applications, infrastructure and cloud platforms.
- Understanding of IAM, Zero Trust, encryption, key management and access-control principles.
- Ability to translate risk assessments and regulatory requirements into technical security architecture.
- Experience working within regulatory frameworks such as GDPR, DORA, PCI-DSS, SOX and/or SWIFT CSP.
- Excellent communication skills with the ability to engage with senior stakeholders, architects, engineers, risk and compliance teams.
Highly Desirable
- Experience with Microsoft Purview, particularly Information Protection, data classification, sensitivity labelling, DLP and information governance.
- Experience defining data-protection architecture across Azure and Microsoft 365 environments.
- Financial Services, Banking, Payments, Market Infrastructure or other highly regulated/critical infrastructure experience.
- Experience with security architecture frameworks such as SABSA, TOGAF or similar.
- Knowledge of DevSecOps and secure SDLC practices.
- Experience working within Agile delivery environments and across multiple release trains.
- Relevant certifications such as CISSP, CCSP, SABSA, TOGAF, Azure Security/Architecture, CISM or equivalent.