Overview
In this role you will drive enterprise Zero Trust strategy and architecture to secure complex environments. You will lead security transformation initiatives and align architectures with modern identity-centric principles. Your work spans risk-focused design across cloud, network, and endpoints, delivering resilient, defense-aligned security postures. You will partner with senior stakeholders to shape policy, standards and engineering practices, delivering measurable improvements in security and resilience. This is an opportunity to influence mission-critical security programmes in a DV-cleared setting.
Pay / Benefits
- highly competitive salary
- comprehensive benefits package
- enhanced pension
- private medical insurance
- flexible and hybrid working options
- professional development and industry certification support
Responsibilities
- Define and deliver enterprise-wide Zero Trust strategies and roadmaps
- Design Zero Trust architectures aligned to NIST 800-207 principles
- Implement identity-first security models across users, devices, applications and data
- Develop continuous verification and adaptive access control frameworks
- Lead micro-segmentation and least privilege initiatives across enterprise environments
- Architect defence-in-depth security solutions across network, cloud, endpoint and application layers
- Lead security architecture reviews and technical security assessments
- Develop security standards, reference architectures and design patterns
- Architect and implement enterprise IAM, MFA and SSO solutions
- Design Conditional Access and Privileged Access Management capabilities
- Lead identity governance and administration initiatives
- Develop secure authentication and authorisation frameworks
- Ensure access management aligns with Zero Trust and least privilege principles
- Assess cyber threat landscapes and design threat-informed security architectures
- Lead security risk assessments and vulnerability management programmes
- Design incident response, threat intelligence and cyber defence capabilities
- Architect security monitoring, detection and response solutions
- Develop cyber resilience and business continuity frameworks
- Design cloud security architectures across Azure, AWS and hybrid environments
- Architect endpoint protection, DLP and advanced threat protection solutions
- Design application security, API security and secure SDLC integration
- Architect Security Operations Centre (SOC) and SIEM capabilities
- Lead security technology evaluation, selection and implementation programmes
- Lead security technical teams and provide architectural mentoring
- Establish security design standards, architecture patterns and governance processes
- Drive technical decision-making through security design reviews
- Document security architecture decisions and design specifications
- Support organisational security transformation programmes
- Act as the subject matter expert for Security Architecture and Zero Trust initiatives
- Present security recommendations to senior leadership and programme stakeholders
- Lead architecture workshops and customer engagement activities
- Communicate complex security concepts to both technical and non-technical audiences
Key requirements
- Minimum 10 years’ experience in Cyber Security and Information Security
- At least 5 years’ experience in a Security Architect role
- Proven experience delivering enterprise-scale Zero Trust transformation programmes
- Strong background in defence, aerospace, government or highly regulated sectors
- Experience leading security transformation and modernisation initiatives
- Deep expertise in Zero Trust Architecture principles and implementation methodologies
- Strong knowledge of NIST 800-207 and modern security architecture frameworks
- Expert understanding of Identity & Access Management technologies
- Experience with Microsoft Entra ID, Conditional Access, PIM and PAM solutions
- Strong understanding of network security, micro-segmentation and secure access technologies
- Proficiency in cloud security across Azure, AWS or equivalent platforms
- Knowledge of SIEM, EDR/XDR, DLP, CASB, ZTNA, WAF and firewalls
- Understanding of cryptography, encryption standards and secure communication protocols
- Familiarity with MOD security requirements, defence standards and accreditation processes
- Knowledge of ISO 27001, NIST CSF and CIS Controls frameworks
- Exceptional strategic thinking with strong technical depth
- Outstanding communication and stakeholder engagement skills
- Strong problem-solving and analytical capabilities
- Proven ability to influence technical teams and executive stakeholders
- Passion for cyber security innovation and continuous improvement
- communication
- stakeholder engagement
- problem-solving
- Zero Trust Architecture
- NIST 800-207
- Identity & Access Management (IAM)
…
