Overview
In this role you will shape secure client IT architectures and drive transformation journeys. You will draw on Enterprise Security or Security Solutions Architecture to identify objectives, risks and controls, and to design end-to-end security solutions. You’ll communicate with both technical and non-technical stakeholders and contribute to governance, risk and compliance efforts. This is a client-facing advisory role with a focus on secure design, risk management and continuous improvement. You will work within a collaborative security practice that values innovation and development of market-ready offerings.
Responsibilities
- Contribute to delivering and refining a coherent secure design for client end-to-end solutions
- Develop conceptual, logical and high-level designs with embedded security controls aligned to business requirements and risk appetite
- Articulate and justify design recommendations at security architecture assurance gates
- Produce design documentation, risk assessments, stakeholder presentations and communicate to senior technical and non-technical audiences
- Contribute to reference architecture and established patterns, principles and guidelines
- Develop the Security Practice’s skills and capabilities; provide coaching to junior team members
- Create collateral to support Security Consulting propositions and service offerings
- Contribute to client proposals with cross-team collaboration
- Develop and present Information Security Management Plans addressing regulatory, legal and compliance requirements
- Identify risks and emerging threats; quantify risk and lead mitigation plans
- Coordinate with Service Management to ensure partner/supplier compliance and KPI verification
- Collaborate with 1st–3rd lines of defense on cyber security, data privacy and regulatory considerations
- Enhance governance, risk and compliance aligned to policy and industry best practice
- Ensure ongoing metrics collection and reporting to enable risk-based decisions
- Challenge existing processes to drive continuous improvement and clearly define responsibilities
- Review and verify documentation of security controls
Key requirements
- Awareness of industry security frameworks (NIST CSF, NIST 800-53, NCSC CAF) and related guidance
- Good networking knowledge (switching, routing, firewalls)
- Awareness or experience with Cloud concepts in AWS and/or Microsoft Azure
- Understanding of native security capabilities within Cloud platforms (AWS/Azure)
- Understanding of modern security concepts, threat landscape, malware, analytics and threat intelligence
- Knowledge of security testing and vulnerability management (e.g., pen testing, CVSS/CVE)
- Experience with standards such as ISO 27001, 27002, 27017, 27108
- Minimum of 5 years in Cyber Security
- Certifications such as CISSP, CISM, CCSP, CRISC or equivalent
- Experience with at least two domains (e.g., IAM, PKI, SIEM, SOAR, cryptography, AD, virtualization, server hardening, etc.)
- Strong teamwork and attention to detail
- Excellent written and verbal communication
- Self-motivation and responsibility
- NIST CSF, NIST 800-53, NCSC guidelines
- Networking (switching, routing, firewalls)
- Cloud security concepts in AWS and Azure
…
