Security Architect - London
6 month Contract
Hybrid - 2 days onsite
Rate - Negotiable - Inside IR35
SECURITY CLEARANCE - MUST
- Please note that candidates must hold or be able to gain UK SC level Security Clearance or higher. Therefore, we can only accept applications from British Nationals who meet these criteria. Candidates with dual Nationality must flag this during the recruitment process
Role Profile
The Security Architect will Contribute to the design, implementation and ongoing development of the security architecture of the client's IT systems.
The Security Architect will draw upon Enterprise Security Architecture or Security Solutions Architecture to Contribute to:
- Identify business objectives, user needs, risk appetite and cyber security obligations
- Identify vulnerabilities, perform threat modelling, undertake risk assessment, evaluate the effectiveness of security controls
- Verify and evidence alignment to 'Secure by Design' principles, corporate security policy/standards as well as industry recognised frameworks and best practice
Responsibilities
- Thrive as a consultant seeking the variety and challenge of engaging with different clients and variety of technologies and solution types.
- Developing security vulnerabilities and techniques for applying effective controls.
- Contribute to the development of secure system without close supervision.
- Contribute to security requirements for new systems or changes to existing systems without close supervision.
- Execute technical management tasks in respect to ongoing client projects.
CORE SKILLS AND EXPERIENCE
- Awareness and understanding of industry security frameworks and guidance such as NIST CSF, NIST 800-53, NCSC CAF and other NCSC guidelines
- Good knowledge of networking (switching, routing, Firewalls)
- Awareness or limited experience with the design concepts associated with adoption of Cloud platforms (AWS and/or Microsoft Azure)
- An understanding of the native security capabilities and some practice within Cloud platforms (AWS and/or Microsoft Azure)
- Understanding of modern security concepts, common attack vectors, malware, security analytics and threat intelligence.
- An understanding of security testing and vulnerability management is important (including pen testing/ITHC, CVSS/CVE)
- Some experience working with security standards such as ISO 27001, 27002, 27017, 27108 etc
DESIRABLE SKILLS AND EXPERIENCE
- Minimum of 5 years of experience in Cyber Security
- Any One of the certifications (CISSP, CISM, CCSP, CRISC) or equivalent experience
- Good knowledge covering at least 2 of the following examples (this list is not exhaustive): AD, Cryptography, End User Computing, IAM, PKI, Server hardening, SIEM, SOAR, virtualization (VMware)