Security Architect (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Security Architect (Cybersecurity): Designing, assuring, and delivering secure solutions across client engagements with an accent on Secure by Design principles and threat modelling. Focus on defining security architectures, ensuring compliance with ISO 27001/NIST, and mitigating risks early in the lifecycle.
Location: Must have active SC Clearance; based at client locations in London or working remotely.
Salary: £550 - £600 per day (Outside IR35)
Company
is an award-winning digital, data, and solutions consultancy serving the UK public sector and central government.
What you will do
- Develop and maintain secure architecture patterns aligned with business and technical requirements.
- Embed Secure by Design principles throughout the entire solution lifecycle to prevent retrofitting controls.
- Lead and facilitate threat modelling exercises using STRIDE and attack trees.
- Conduct risk assessments across systems, applications, and infrastructure to define mitigations.
- Ensure adherence to industry standards such as ISO 27001, NIST, and government security policies.
- Collaborate with stakeholders and agile delivery teams to embed security into solution designs.
Requirements
- Active Security Clearance (SC) is mandatory for this role.
- Proven experience as a Security Architect or in a senior security role within complex environments.
- Practical expertise in threat modelling and risk analysis.
- Deep understanding of security frameworks: ISO 27001, NIST, CIS, OWASP, and NCSC guidance.
- Experience in the UK Public Sector (GovAssure, NCSC CAF, HMG Security Policy Framework).
- Knowledge of cloud security across AWS, Azure, or GCP and identity and access management.
Culture & Benefits
- Work for an award-winning consultancy with over 35 years of experience in the UK public sector.
- Opportunity to deliver high-quality solutions that impact citizens and consumers.
- Flexible work arrangements including remote options or client-site presence.
- Contract position determined to be outside IR35.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →