Overview
As Security Architect, you will lead security architecture for a major transformation programme, embedding security across identity, endpoints, M365, applications, and networks. You will balance security with delivery, guiding risk-based decisions and ensuring controls are practical during coexistence and target-state transitions. You’ll articulate security principles and provide independent assurance of designs and migration approaches. The role is on-site in London with a 50/50 hybrid option and offers a meaningful chance to shape secure, future-ready services for the public sector.
Pay / Benefits
- Autonomy to develop and grow
- Impactful project work contributing to society
- Strong leadership and collaborative environment
- LinkedIn Learning and management development
- Flexible working (home/part-time)
- 25 days annual leave + bank holidays + option to buy 5 days
Responsibilities
- Establish and maintain security architecture principles, patterns, standards and control requirements for the programme
- Define security design-assurance criteria and assess technical designs against requirements
- Assess threats, risks, vulnerabilities and control gaps across current, coexistence, transition and target states
- Develop proportionate security controls for secure coexistence between existing and new services
- Define and assure Zero Trust principles across identity, devices, applications, data and network access
- Collaborate with identity and directory architecture to secure authentication and administrative controls
- Define security requirements for endpoint, email, data, applications and networks
- Establish monitoring, logging, threat detection and incident response requirements
- Review designs to identify security weaknesses and remediation needs
- Assess migration strategies from a security perspective and document residual risk and treatments
- Maintain visibility of significant security risks and owner accountability
- Provide security input into programme plans, designs, testing and handover
- Support security testing and assurance activities prior to migrations or go-live
- Align designs with security policies, standards, data protection obligations and regulatory requirements
- Produce and maintain security architecture documentation (HLDs, threat models, risk assessments, etc.)
- Offer risk-based security recommendations to leadership and stakeholders
- Drive continuous improvement of security controls as the transformation progresses
Key requirements
- Extensive experience as Security Architect in complex enterprise environments
- Strong knowledge of Microsoft Entra ID, Microsoft 365, Azure, endpoint security, networks and application security
- Understanding of hybrid and cloud security architectures and legacy transition challenges
- Proven application of Zero Trust, least privilege, privileged access and defence-in-depth principles
- Identity and access security expertise including authentication, Conditional Access and administrative controls
- Experience designing security controls for endpoints, email, data, applications, infrastructure and networks
- Strong logging, monitoring, threat detection and incident-response knowledge
- Threat modelling, risk assessment, control mapping and architecture assurance experience
- Experience assessing security risks in migration, coexistence and cutover
- Understanding of data protection, information governance and regulatory requirements
- Ability to translate technical risks into clear business impacts and recommendations
- Strong technical writing skills for architecture documentation
- Pragmatic security professional who balances risk with delivery
- Strong communication with senior stakeholders
- Collaborative, able to challenge designs constructively
- Microsoft Entra ID
- Microsoft 365
- Azure
…
