Overview
You will shape and strengthen security architecture in a hands-on, technical leadership role within the Information Security team. You’ll translate security strategy into secure designs, controls and standards, while prototyping and validating implementations across identity, cloud, data, endpoints, apps, networks and third parties. A key aspect is guiding secure AI adoption, including Microsoft 365 Copilot and related technologies. You will lead security architecture reviews, threat modelling, and incident response readiness, driving measurable security outcomes.
Responsibilities
- Define and maintain security architecture across identity, endpoints, networks, cloud, SaaS, data, applications and integration platforms
- Design and implement modern security controls with Zero Trust and secure-by-design principles, emphasizing automation
- Lead security architecture reviews and threat modelling for major projects and emerging technologies
- Act as technical lead for AI security, establishing controls for Microsoft 365 Copilot, AI agents and custom AI apps
- Provide senior technical oversight across security monitoring, detection engineering, incident response and recovery capability
- Lead or support responses to complex or high-severity security incidents with internal teams and SOC/partners
- Improve vulnerability and exposure management prioritising remediation with risk and threat intel
- Support technical implementation and evidence for ISO 27001, Cyber Essentials Plus and other obligations
- Provide clear, risk-based technical advice to senior leaders and technology owners
- Coach technology teams in secure design and engineering practices
Key requirements
- Demonstrable experience in cyber security architecture or security engineering at senior level
- Microsoft-centric security design experience (365, Entra ID, Defender XDR, Sentinel, Azure, Purview)
- Strong knowledge across identity, Zero Trust, cloud/data/endpoint/network/application/API security and secure software development
- Experience in security architecture reviews, threat modelling, standards, reference architectures
- Practical incident response, detection engineering, threat hunting, vulnerability management and security automation
- Automation skills using Python, PowerShell, Logic Apps, Azure Functions, APIs, IaC
- Working knowledge of ISO 27001, Cyber Essentials Plus, NIST CSF and AI security/governance frameworks
- Ability to explain complex risk to senior stakeholders and influence delivery without formal authority
- Practical, outcome-focused with ownership and ability to validate controls
- Collaborative approach
- calm under pressure
- clear communication to both technical and non-technical audiences
- Microsoft 365 security stack (Defender XDR, Entra ID, Defender for Cloud Apps)
- Azure security and governance
- Zero Trust architecture
…
