Senior Security Architect

Senior Security Architect - Contract - Hybrid

Our client is seeking an experienced Cyber Security Architect/Security Architect to play a pivotal role in designing and implementing the security architecture underpinning the organisation's future operating model. Working closely with executive stakeholders, enterprise architects, IT leadership, operational teams and external partners, the successful candidate will define the security architecture required to support a secure, scalable and compliant operation from inception.

This role will focus on the creation of both High-Level Designs (HLDs) and Low-Level Designs (LLDs) across technology, operational technology (OT), cloud, applications, networks and identity services, ensuring security is Embedded into the target operating model from the outset.

Key Responsibilities:

Security Architecture & Design

  • Lead the development of security architecture for a newly established business function.
  • Produce High-Level Designs (HLDs) and Low-Level Designs (LLDs) covering enterprise security controls and platforms.
  • Define security principles, standards and architecture patterns aligned with business objectives.
  • Ensure security is Embedded throughout the target operating model and technology landscape.

Target Operating Model (TOM)

  • Work alongside business and technology leaders to design secure operating model capabilities.
  • Translate business requirements into practical security architecture solutions.
  • Support the development of governance frameworks, policies, processes and security controls.
  • Ensure alignment between business, operational and technology security requirements.

Infrastructure & Cloud Security

  • Design secure hybrid infrastructure architectures.
  • Define cloud security controls across Azure, AWS and/or multi-cloud environments.
  • Implement security architectures supporting workload migration and digital transformation initiatives.
  • Provide guidance on network segmentation, connectivity and secure access models.

Operational Technology (OT) & Industrial Security

  • Support the design and protection of operational environments where applicable.
  • Assess risks associated with connected assets, machinery, IoT and operational technology.
  • Develop security architectures that support both IT and OT environments.
  • Ensure security designs are fit for highly operational and safety-critical environments.

Identity & Access Management

  • Define enterprise identity and access management strategies.
  • Develop privileged access management and role-based access control approaches.
  • Design modern authentication and Zero Trust security frameworks.

Risk & Compliance

  • Conduct security risk assessments and architecture reviews.
  • Ensure solutions align with industry standards and regulatory requirements.
  • Support audit and assurance activities.
  • Develop security controls supporting ISO27001, NIST and Cyber Essentials requirements.

Stakeholder Management

  • Engage with senior business and technology stakeholders.
  • Present security architectures and recommendations to executive audiences.
  • Collaborate with solution architects, infrastructure teams, programme managers and third-party suppliers.
  • Provide technical leadership and mentoring where required.

Required Experience:

  • Extensive experience as a Security Architect, Cyber Security Architect or Lead Security Consultant.
  • Proven track record delivering security architecture within large-scale transformation programmes.
  • Strong experience developing both High-Level Designs (HLDs) and Low-Level Designs (LLDs).
  • Experience contributing to Target Operating Model (TOM) design and implementation.
  • Demonstrable expertise across infrastructure, cloud, network, application and identity security domains.
  • Experience within Automotive, Heavy Construction, Manufacturing, Engineering, Utilities or other industrial environments.
  • Strong understanding of operational technology (OT), industrial control systems (ICS) and associated cyber security challenges.
  • Experience working within complex multi-supplier environments.

Technical Expertise:

Security Architecture

  • Enterprise Security Architecture
  • Security-by-Design Principles
  • Zero Trust Architecture
  • Secure Network Design
  • Security Governance Frameworks

Cloud Security

  • Microsoft Azure
  • AWS
  • Cloud Security Controls
  • Secure Landing Zones
  • Cloud Identity & Access Management

Infrastructure Security

  • Network Segmentation
  • Firewalls & Security Gateways
  • Endpoint Security
  • Data Protection
  • Secure Remote Access

Identity & Access Management

  • Azure AD/Entra ID
  • Privileged Access Management (PAM)
  • Multi-Factor Authentication (MFA)
  • RBAC and Conditional Access

Governance & Compliance

  • ISO27001
  • NIST Cyber Security Framework
  • Cyber Essentials Plus
  • Risk Assessment & Threat Modelling

If you are looking for your next opportunity, please contact me on my mobile.

Job Details

Company
Boss Professional Services
Location
United Kingdom
Employment Type
Contract
Salary
GBP Annual
Posted