The Role
As the Security Architect, you will lead the design, implementation and assurance of security controls across Back End platforms and endpoint environments operating within secure, offline (air-gapped) networks.
Working closely with infrastructure, platform and security teams, you will ensure solutions meet UK Government and MOD security standards while supporting security accreditation and operational assurance activities.
Key Responsibilities
- Lead the architecture and design of enterprise security solutions.
- Design platform security controls aligned to NIST Cybersecurity Framework and MOD security policies.
- Deliver enterprise Anti-Virus, Endpoint Protection and Endpoint Detection & Response (EDR) capabilities.
- Design vulnerability management frameworks, scanning strategies and remediation processes.
- Develop secure patching, update and threat intelligence processes for air-gapped environments.
- Produce High Level Designs (HLDs), Low Level Designs (LLDs), security architecture documentation and operational procedures.
- Support security assurance, compliance assessments and accreditation activities.
- Work closely with infrastructure and engineering teams to ensure secure-by-design delivery.
- Define penetration testing scope for Back End platforms and endpoint environments.
- Engage with technical and business stakeholders across secure customer sites.
Essential Skills & Experience
- Proven experience as a Security Architect or senior Security SME.
- Strong background designing enterprise security architectures within secure or regulated environments.
- Experience with: Endpoint Protection, Endpoint Detection & Response (EDR), Anti-Virus platforms, Vulnerability Management, Endpoint Hardening, Platform Security Controls.
- Experience working within air-gapped or highly secure environments.
- Strong understanding of vulnerability assessment, remediation and risk management.
- Experience producing technical design documentation including HLDs, LLDs and security architecture documents.
- Excellent stakeholder management and communication skills.
Security & Compliance Knowledge
- Experience working with one or more of the following is highly desirable: NIST Cybersecurity Framework, NCSC Cyber Security Design Principles, Secure by Design, JSP 440, JSP 604, JSP 453, Security Accreditation & Assurance, Risk Management & Compliance.