The Role
You will shape secure technical solutions from early design through to delivery, ensuring architecture decisions are proportionate to risk and meet relevant government security expectations.
The role will involve providing clear security direction to engineering and architecture teams, contributing to assurance activity, and helping to resolve complex security challenges across the programme.
Key Responsibilities
- Design and review secure architectures across cloud, on-premise and integrated technology environments.
- Define pragmatic security controls, patterns and design principles for new and evolving services.
- Lead security design reviews, threat modelling and risk assessments, providing clear recommendations and mitigation plans.
- Support delivery teams with secure approaches to identity, access, data protection, network security, encryption, monitoring and vulnerability management.
- Produce high-quality security architecture artefacts, including security designs, control mappings, risk documentation and assurance evidence.
- Engage with governance forums, technical authorities and delivery stakeholders to explain risks, challenge decisions and gain agreement on security approaches.
Essential
- Active SC clearance.
- Proven experience working as a Security Architect, Cyber Security Architect or senior security design consultant.
- Background designing secure cloud and hybrid solutions, ideally across AWS and/or Azure.
- Strong understanding of security architecture, risk management, threat modelling and security assurance.
- Experience of IAM, privileged access, encryption, network security, logging/SIEM, vulnerability management and secure integrations.
- Ability to work with technical and non-technical stakeholders, translating security risks into practical delivery decisions.
- Previous experience within central government, law enforcement, defence or another highly regulated environment.
Desirable
- CISSP, CISM, SABSA, CCSP or a comparable security architecture/information-security qualification.
- Knowledge of NCSC guidance, government security standards and secure-by-design principles.
- Experience of DevSecOps, cloud-native security, CI/CD assurance and container/Kubernetes security.
- Previous Home Office experience.
The Details
- Contract role
- 12 months initial duration
- Outside IR35
- Up to £550 per day
- Fully remote
- Active SC clearance required