Security Architect - Urgent!
Cloud Consulting have an urgent requirement for an experienced Security Architect to work on a high-profile project for a leading company.
The role is a hybrid one - 2 days p/week on-site in London, and 3 days remote, and is inside of IR35.
The security architect will create and design security for the client's systems and services, maintaining security documentation and develop architecture patterns and security approaches to the new technologies.
At this role level, you will:
- undertake structured analysis of technical issues, translating this analysis into technical designs that describe a solution
- be consulted about design and provide design patterns
- identify deeper issues that need fixing
- look for opportunities to collaborate and reuse components, communicating with both technical and non-technical stakeholders
- align designs with Enterprise Architecture
Main Activities
- Documenting service assets
- Sourcing a threat assessment
- Performing threat modelling
- Performing a security risk assessment
- Agreeing security controls set for your service
- Responding to and mitigating security risks
- Assessing the effectiveness of security controls
- Implementing a vulnerability management process
- Managing observability
- Evaluating the security impact of changes
Skills
Analysis
- apply the approach to real problems and consider all relevant information
- apply appropriate rigour to ensure a full solution is designed and achieves the business outcome
Communication
- demonstrate a deep understanding of security concepts and can apply them to a technical level
- effectively translate and accurately communicate security and risk implications to technical and non-technical stakeholders
- successfully respond to challenges
- manage stakeholder expectations and be flexible, adapting to stakeholder reactions to reach consensus
Designing secure systems
- design and review system architectures through the application of patterns and principles
Enabling and informing risk-based decisions
- work with risk owners to advise and give feedback
- advise on risk impact and whether it's within risk tolerance
- describe different risk methodologies and how these are applied, as well as the proportionality of risk
Security technology
- explain the effect of vulnerabilities on current and future designs
- share information on a range of systems, but may specialise in one
Understanding security implications of transformation
- interpret and apply an understanding of policy and process, business architecture, and legal and political implications to assist the development of technical solutions or controls
If you are interested, please forward a copy of your C.V in the first instance.