Назад
Company hidden
4 дня назад

Security Architect (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Security Architect (Cybersecurity): Designing application security architecture across cloud-native services, mobile applications, APIs, AI-enabled features, and legacy systems with an accent on identity, API protection, threat modeling, and secure engineering. Focus on securing Amazon Bedrock and agentic applications, establishing practical architecture guardrails, and balancing regulatory risk with transformation and delivery needs.

Location: Bristol, UK; hybrid working with two office days per week. Permanent full-time role, Monday to Friday, 37.5 hours per week. Employment sponsorship is not available.

Company

hirify.global is a UK investment platform for private investors, helping customers save and invest through digital financial services.

What you will do

  • Own application security architecture and maintain reference architectures, patterns, standards, and guardrails across web, mobile, API, cloud-native, and legacy environments.
  • Design security patterns for authentication, authorization, service identity, secrets management, cryptography, secure data handling, REST APIs, and GraphQL.
  • Define security architecture for Amazon Bedrock, agentic applications, third-party AI, and AI-assisted developer tooling.
  • Lead threat modeling and security design reviews using STRIDE and OWASP methods, driving mitigations and risk decisions to closure.
  • Embed SAST, DAST, SCA, secrets scanning, container assurance, software supply chain controls, and secure-by-default capabilities into CI/CD delivery.
  • Advise architecture governance and collaborate with engineering, cyber security, risk, compliance, penetration testing, and vulnerability management teams.

Requirements

  • Substantial senior-level experience in security architecture, with application security as the primary focus.
  • Experience designing secure AWS cloud-native architectures, with strong understanding of containers and Kubernetes.
  • Practical expertise in OAuth 2.0, OpenID Connect, SAML, advanced authorization models, and service-to-service authentication.
  • Hands-on API security experience across REST and GraphQL, including authorization design and platform-specific failure modes.
  • Experience securing mixed estates, leading threat modeling and design reviews, and integrating security into Agile and CI/CD workflows.
  • Must be able to work from the UK and attend the Bristol office two days per week; employment sponsorship is unavailable.

Nice to have

  • Financial services or other regulated-sector experience.
  • Mobile application security, software supply chain security, secure SDLC, or Amazon Bedrock experience.
  • Knowledge of OWASP guidance for LLMs, agentic applications, application security, API security, and ASVS.
  • FIDO2, passwordless authentication, or Azure experience.
  • CISSP, CCSP, AWS Security Specialty, CSSLP, SABSA, SANS GCSA, or Microsoft Cybersecurity Architect Expert certification.

Culture & Benefits

  • Continuous learning and a workplace built around service, quality, innovation, and opportunity.
  • Discretionary annual bonus and annual pay review.
  • 25 days of holiday plus bank holidays and an additional Christmas closure day.
  • Enhanced parental leave, pension contributions of up to 11%, income protection, life insurance, and private medical insurance.
  • Health screening, wellbeing support, fitness access, travel-to-work schemes, and two paid volunteering days per year.

Hiring process

  • Two-stage process consisting of an introductory call followed by a competency and behavioral interview with a technical assessment.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →