Cloud Security Architect

Company: Reply
Apply for the Cloud Security Architect
Location:
Job Description:

Overview

In this role you will own cloud security architecture and governance for multi-cloud environments, advising financial services and public sector clients. You will translate complex threats into actionable guidance and drive security roadmaps with executive stakeholders. You contribute to a security-centric culture by shaping reference architectures, policies, and compliant programmes. This is a high-impact consulting position that blends deep technical skill with strategic risk management and client-facing leadership.

Responsibilities

  • Design and own cloud security architecture across AWS, Azure, and/or GCP with reusable reference patterns
  • Define enterprise security policies, controls frameworks, and governance documentation aligned to standards
  • Lead risk assessments, threat modelling, and security posture evaluations for cloud and SaaS environments
  • Drive compliance programmes (ISO 27001, Cyber Essentials Plus, PCI DSS)
  • Support DevSecOps adoption and integrate security tooling into CI/CD pipelines
  • Engage executives with security risk reporting, remediation guidance, and roadmaps
  • Lead or contribute to Security Champions communities of practice
  • Provide security assurance for software development and third-party onboarding (SSPM tooling, SaaS security)
  • Architect secure identity solutions (centralised and federated models)
  • Support incident response planning and business continuity for cloud services
  • Contribute to FinOps activities from a cybersecurity cost and sustainability perspective

Key requirements

  • Cloud Security Architect or Senior Security Consultant experience
  • AWS Certified Security – Specialty required; CISSP/CRISC/CCSP preferred
  • Hands-on experience securing workloads on AWS and/or Azure (GCP helpful)
  • Experience in financial services and/or public sector security architectures
  • ISO 27001 and/or Cyber Essentials Plus experience or accreditation
  • Terraform and secure CI/CD pipeline design
  • Strong knowledge of TCP/IP, DNS, VPN, IPSEC
  • Excellent stakeholder engagement and communication to senior audiences
  • Mentoring, security communities involvement, enabling secure innovation
  • Eligible for UK Security Check clearance
  • stakeholder engagement
  • clear communication
  • analytical mindset
  • AWS; Azure; GCP security
  • ISO 27001; Cyber Essentials Plus; PCI DSS
  • Terraform; Infrastructure as Code; CI/CD security

Posted: September 14th, 2026