Principal Enterprise Security Architect (Ref: 20694)

Location: Staffordshire, UK; Elgin Ave., London W9 2NR, UK; Scotland; Wales, UKSalary: 71,381 - 85,257 per yearEmployment: FlexibleCategory: ITPosted: 2026-08-04Valid to: 2026-08-16Apply: Ministry of JusticeJob summaryThis position is based NationallyJob descriptionPrincipal Enterprise Security ArchitectLocation: National*Closing Date: 15th AugustInterviews: w/c 1st SeptemberGrade: 6(MoJ candidates who are on a specialist grade, will be able to retain this grade on lateral transfer)Salary (for more information, please see below):London: 75,674 - 93,025 (may include an allowance of up to 17,351)National: 71,381 - 88,900 (may include an allowance of up to 17,519)Working pattern: Full-time, part-time, flexible workingContract Type: PermanentNumber of vacancies: 1Vacancy number: 20694*We offer a hybrid working model, allowing for a balance between remote work and time spent in your local office. Office locations can be found ON THIS MAPPlease note that unless you are an existing member of staff at Justice Digital, Data and Science, the only London location being recruited to is 10 South Colonnade, E14 4PU. We are no longer recruiting to 102 Petty France, SW1H 9AJ.The RolePlease note this role requires you to pass Security Check clearance. Please click on the link for details.We’re recruiting a Principal Enterprise Security Architect to join Justice Digital Data and Science within the Office of the Chief Technology Officer at the Ministry of Justice which is responsible for architecture and engineering across the MoJ. We work in collaboration with individual business units and Executive Agencies to align technology and operate platforms for the benefit of the products and teams dependent upon them. This role is responsible for setting and governing the enterprise‐wide technology direction for the department.This role provides strategic ownership of core enterprise security architecture domains, including identity and access management, cloud security, network and boundary security, endpoint and device security, data protection, secure integration, security monitoring architecture, resilience, and zero trust patterns. You will focus on the cross-cutting security capabilities that underpin all digital services, ensuring they are secure, scalable, reusable and aligned to long-term departmental outcomes.Reporting to the Chief Architect, you will lead and coordinate enterprise security architecture across the department, working closely with senior architects, cyber security leadership, platform teams and major delivery programmes. You will set clear security direction, guardrails and priorities, enabling domain architects and delivery teams to make consistent, risk-informed decisions across MoJ HQ and Executive Agencies.This role operates at departmental scale and long-term horizon. You will balance immediate delivery needs with a 5–10 year security architecture intent, reducing fragmentation and security debt while maximising value from shared platforms, common controls and strategic investments.You’ll receive a range of excellent benefits when you join our department, including:A generous employer pension contribution of 28.97%through the Civil Service Pension Scheme.25 days of annual leave, (increasing to 30 days once you have reached 5 years of service),plus 8 bank holidays and a privilege day for the King’s birthday.Flexible working arrangementsincluding hybrid working, working part time or compressed hours. Designed to support a positive work–life balance.Set and own the enterprise cyber security architecture vision and strategyacross core domains including identity, cloud security, endpoint security, network security, data protection, secure integration and resilience, aligned to the departmental enterprise target state.Act as a senior security authoritywithin the Office of the CTO, providing clear architectural direction and advice to senior leaders, major programmes and investment decisions.Define and evolve enterprise-wide security target states, standards, principles, control patterns and reference architecturesfor shared platforms and services.Establish clear secure-by-design guardrailsthat enable delivery teams to move faster while maintaining confidentiality, integrity, availability, resilience, interoperability and value for money.Provide architectural oversight and assurance for high-risk or strategically significant initiatives, balancing short-term delivery with long-term security sustainability.Lead on security architecture decisions for enterprise-scale transformation, including legacy modernisation, cloud adoption, shared platforms and cross-department integration.Drive adoption of reusable security capabilities and common controls, reducing duplication, inconsistency, unmanaged risk and technical/security debt across the department.Shape and mature security architecture governance, including contribution to architecture boards, technical design authorities, risk forums and the enterprise knowledge base.Work with risk owners and senior stakeholders to enable and inform risk-based decisions, ensuring proportionate controls and pragmatic trade-offs.Research, identify, validate and adopt new security technologies, patterns and methodologies, using innovation where it materially improves outcomes.Build strong relationships across Digital, Technology, Data, Operations and Security leadership to ensure cyber security strategy is integrated with business outcomes and delivery priorities.Employees are allocated 10% of their working time for personal and professional development.A 1k per person learning budget is in place to support all our people, with access to best-in-class conferences and seminars, accreditation with professional bodies, fully funded vocational programmes and e-learning platforms.Compassionate maternity, adoption, and shared parental leave policies, with up to 26 weeks leave at full pay, 13 weeks with partial pay, and 13 weeks further leave. And maternity support/paternity leave at full pay for 2 weeks, too!You can find more details of the Benefits we offer here. To help picture your life at MoJ Justice Digital, Data and Science please take a look at our blog.Who this role is forThis role is for highly experienced security architects who want to operate at enterprise scale and shape the future security foundations of a complex organisation. You may come from an enterprise security, cyber security, technical security, cloud security or platform architecture background and enjoy setting direction, influencing senior leaders and enabling others rather than owning a single solution. You will be comfortable making decisions in ambiguity and acting as a trusted security advisor at the most senior levels.This role aligns against the Principal Security Architect role in the Government Digital and Data Profession Capability Framework.In that framework, principal security architects work on services of high complexity and risk, set long-term strategy, define vision and principles, influence important business and architectural decisions, and solve unprecedented security issues at organisational scale.To help picture your life at Justice Digital, please refer to the standard Justice Digital blog and digital strategy materials used in the base template.Key ResponsibilitiesYou will:If this feels like an exciting challenge, something you are enthusiastic about, and want to join our team please read on and apply!Person SpecificationEssentialSignificant experience operating as a senior cyber security or security architectwithin a large, complex organisation, setting direction across enterprise-scale services, platforms or infrastructure.Deep expertise in one or more enterprise security domains such as identity and access management, cloud security, network security, endpoint security, data protection, security monitoring, or resilience, with sufficient breadth to lead across multiple domains.Proven experience defining enterprise security strategies, target states, standards or reference architecturesthat have been adopted across multiple teams or organisations.Strong systems-thinking skills, with the ability to understand and manage dependencies, threats, vulnerabilities, risks and trade-offs across complex technology estates.Experience designing secure systemsand applying architecture patterns and principles to solve complex security challenges.Strong background in enabling and informing risk-based decisions, including advising senior risk owners on proportionality, tolerance and treatment options.Experience influencing senior stakeholders and decision-makers, acting as a trusted advisor on complex, high-risk security decisions.Excellent communication skills, with the ability to clearly explain security strategy, architecture and risk to both technical and non-technical audiences, including at senior levels.Deep and current understanding of security technology, attack paths, defensive controls and the security implications of digital transformation.Willingness to be assessed against the requirements for SC clearanceWe welcome the unique contribution diverse applicants bring and do not discriminate based on culture, ethnicity, race, nationality or national origin, age, sex, gender identity or expression, religion or belief, disability status, sexual orientation, educational or social background or any other factor.Our values are Purpose, Humanity Openness and Together. Find out more here about how we celebrate diversity and an inclusive culture in our workplace.The Civil Service is committed to attract, retain and invest in talent wherever it is found. To learn more please see the Civil Service People Plan and the Civil Service D&I Strategy.Salary Information**Base salary for this role is from 71,381 to 80,419 (National) or from 75,674 to 85,257 (London).New entrants to the Civil Service joining the MoJ are expected to start at the minimum of the pay band.Existing Civil Servants moving on a level transferwill retain their current base salary or move to the minimum of the pay band for the role, whichever is higher.Existing Civil Servants who are promotedwill either move to the bottom of the new grade’s pay band or receive a 10% uplift, whichever provides the greater increase.Candidates may also be eligible for a non‐pensionable Government Digital & Data Allowance of up to 17,351 per year (London) or 17,519 (National).This is a temporary allowance, reviewed annually and may be retained, amended, or withdrawn.The final offer will reflect the skills and experience you demonstrate during the assessment process.How to ApplyIn Justice Digital, Data and Science, we recruit using a combination of the Government Digital and Data Profession Capabilityand Success Profiles Frameworks. We shall assess a combination of your Experience, Technical skills and Behaviours during the assessment process.Stage 1 - Application and sift:To apply for this position, you must submit the following as part of your application:A CV detailing your career history (including any relevant qualifications). Your CV will be assessed against the essential criteria outlined within the Person Specification of this advert.A Personal Statement(no more than 750 words) which should outline your experience and skills, giving clear examples of work undertaken. It should specifically address the following 2 criteria listed below, using a separate paragraph for each.- Significant experience operating as a senior cyber security or security architect within a large, complex organisation, setting direction across enterprise-scale services, platforms or infrastructure.- Proven experience defining enterprise security strategies, target states, standards or reference architectures that have been adopted across multiple teams or organisations.A diverse sift panel will review the information in your CV and Personal Statement to assess the sift criteria specified above. We operate an anonymous shortlisting process. Please ensure your CV and Personal Statement do not include your name or any other identifying details.Should we receive a high volume of applications, a pre-sift based on “Significant experience operating as a senior cyber security or security architect within a large, complex organisation, setting direction across enterprise-scale services, platforms or infrastructure” will be conducted before the sift.Please access the following link for guidance on how to apply - Application GuidanceStage 2 - Interviews:Successful candidates who meet the required standard will then be invited to a panel interview held via Microsoft Teams. At interview stage, you will be assessed against the following Success Profile elements - Experience, Technical and the following Behaviours:Seeing the Big PictureDelivering at PaceMaking Effective DecisionsLeadershipCommunicating and InfluencingAs part of your interview, you will be asked to deliver a 5-minute presentation that assesses your technical capability. Further details will be provided if successful at sift.Appointments are made strictly in merit order. In the event that two or more candidates receive identical interview scores, the criterion “Significant experience operating as a senior cyber security or security architect within a large, complex organisation, setting direction across enterprise-scale services, platforms or infrastructure” will be applied as the primary lead criterion to determine the final merit order.Should you be unsuccessful in the role that you have applied for but demonstrate the capability for a role at a lower level, we reserve the right to discuss this opportunity with you and offer you the position without needing a further application.A reserve list may be held for up to 12 months, from which further appointments may be made.Use of Artificial IntelligenceArtificial Intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance for more information on appropriate and inappropriate use.Terms & ConditionsPlease review our Terms and Conditions which set out how we recruit and provide further information related to the role and salary arrangements.If you have any questions, please feel free to contact digitalanddatarecruitment@justice.gov.ukPerson specificationPlease refer to attached Job DescriptionBenefitsAlongside your salary of 71,381, Ministry of Justice contributes 20,679 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides (opens in a new window).Access to learning and developmentA working environment that supports a range of flexible working options to enhance your work life balanceA working culture which encourages inclusion and diversityA Civil Service pension with an employer contribution of 28.97%Annual LeavePublic HolidaysSeason Ticket AdvanceFor more information about the recruitment process, benefits and allowances and answers to general queries, please click the below link which will direct you to our Candidate Information Page. Link: Things you need to knowArtificial intelligenceArtificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance (opens in a new window) for more information on appropriate and inappropriate use.Selection process detailsHow to ApplyIn Justice Digital, Data and Science, we recruit using a combination of the Government Digital and Data Profession CapabilityandSuccess Profiles Frameworks. We shall assess a combination of your Experience, Technical skills and Behaviours during the assessment process.Stage 1 - Application and sift:To apply for this position, you must submit the following as part of your application:A CV detailing your career history (including any relevant qualifications). Your CV will be assessed against the essential criteria outlined within the Person Specification of this advert.A Personal Statement (no more than 750 words) which should outline your experience and skills, giving clear examples of work undertaken. It should specifically address the following 2 criteria listed below, using a separate paragraph for each.Significant experience operating as a senior cyber security or security architect within a large, complex organisation, setting direction across enterprise-scale services, platforms or infrastructure.Proven experience defining enterprise security strategies, target states, standards or reference architectures that have been adopted across multiple teams or organisations.A diverse sift panel will review the information in your CV and Personal Statement to assess the sift criteria specified above. We operate an anonymous shortlisting process. Please ensure your CV and Personal Statement do not include your name or any other identifying details.Should we receive a high volume of applications, a pre-sift based on “Significant experience operating as a senior cyber security or security architect within a large, complex organisation, setting direction across enterprise-scale services, platforms or infrastructure” will be conducted before the sift.Please access the following link for guidance on how to apply - Application GuidanceStage 2 - Interviews:Successful candidates who meet the required standard will then be invited to a panel interview held via Microsoft Teams. At interview stage, you will be assessed against the following Success Profile elements - Experience, Technical and the following Behaviours:Seeing the Big PictureDelivering at PaceMaking Effective DecisionsLeadershipCommunicating and InfluencingAs part of your interview, you will be asked to deliver a 5-minute presentation that assesses your technical capability. Further details will be provided if successful at sift.Appointments are made strictly in merit order. In the event that two or more candidates receive identical interview scores, the criterion “Significant experience operating as a senior cyber security or security architect within a large, complex organisation, setting direction across enterprise-scale services, platforms or infrastructure” will be applied as the primary lead criterion to determine the final merit order.Should you be unsuccessful in the role that you have applied for but demonstrate the capability for a role at a lower level, we reserve the right to discuss this opportunity with you and offer you the position without needing a further application.A reserve list may be held for up to 12 months, from which further appointments may be made.Feedback will only be provided if you attend an interview or assessment.SecuritySuccessful candidates must undergo a criminal record check.Successful candidates must meet the security requirements before they can be appointed. The level of security needed is security check (opens in a new window).See our vetting charter (opens in a new window).People working with government assets must complete baseline personnel security standard (opens in new window) checks.Nationality requirementsThis job is broadly open to the following groups:UK nationalsnationals of the Republic of Irelandnationals of Commonwealth countries who have the right to work in the UKnationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS) (opens in a new window)nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS)individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020Turkish nationals, and certain family members of Turkish nationals, who have accrued the right to work in the Civil ServiceFurther information on nationality requirements (opens in a new window)Working for the Civil ServiceThe Civil Service Code (opens in a new window) sets out the standards of behaviour expected of civil servants.We recruit by merit on the basis of fair and open competition, as outlined in the Civil Service Commission's recruitment principles (opens in a new window).The Civil Service embraces diversity and promotes equal opportunities. As such, we run a Disability Confident Scheme (DCS) for candidates with disabilities who meet the minimum selection criteria.Diversity and InclusionThe Civil Service is committed to attract, retain and invest in talent wherever it is found. To learn more please see theCivil Service People Plan (opens in a new window) and the Civil Service Diversity and Inclusion Strategy (opens in a new window).Apply and further informationOnce this job has closed, the job advert will no longer be available. You may want to save a copy for your records.Contact point for applicantsJob contact : Name : SSCL Recruitment Enquiries TeamEmail : moj-recruitment-vetting-enquiries@resourcing.soprasteria.co.ukTelephone : 0345 241 5359Recruitment teamEmail : moj-recruitment-vetting-enquiries@resourcing.soprasteria.co.ukFurther informationAppointment to the Civil Service is governed by the Civil Service Commission’s Recruitment Principles. If you feel a department has breached the requirement of the Recruitment Principles and would like to raise this, please contact SSCL (Moj-recruitment-vetting-enquiries@gov.sscl.com) in the first instance. If the role has been advertised externally (outside of the Civil Service) and you are not satisfied with the response, you may bring your complaint to the Commission. For further information on bringing a complaint to the Civil Service Commission please visit their web pages: AttachmentsPrincipal Enterprise Security Architect_JD Opens in new window (docx, 58kB)

Job Details

Company
Government Recruitment Service
Location
Sheffield, UK
Hybrid / Remote Options
Posted