Senior Enterprise Security Architect - 6 Month Initial Contract - Hybrid in London - Inside IR35
Senior Enterprise Security Architect - 6 Month Initial Contract - Hybrid in London - Inside IR35
Role Overview
We are looking for a Senior Enterprise Security Architect to join on a 6-month contract based primarily in London (4 days on-site), with travel to sites for workshops as required. The role leads the foundational implementation of CIS Critical Security Controls across the enterprise, transitioning the organisation's security posture to a robust, CIS-aligned framework deeply integrated across infrastructure, cloud environments, and business operations.
Key Responsibilities
- Lead the end-to-end design and roadmap for implementing CIS Controls (v8), mapping current technical controls to the framework across IG1, IG2, and IG3 implementation groups
- Define and enforce secure architecture patterns for on-premises, hybrid, and multi-cloud (AWS/Azure/GCP) environments, ensuring compliance with CIS Benchmarks for OS, cloud platforms, and network devices
- Develop enterprise-wide security policies, standards, and procedures, and oversee technical implementation in collaboration with DevOps, Network Engineering, and IT Operations teams
- Establish and mature enterprise vulnerability management processes and design automated asset inventory solutions as foundational prerequisites for CIS implementation
- Act as the primary SME, communicating security requirements, risk posture, and programme milestones to executive leadership and technical teams, including board-level reporting
Top 5 Skills
- 10+ years in cybersecurity with at least 5 years in a senior architecture role, and deep hands-on experience implementing CIS Critical Security Controls in large-scale enterprise environments
- Strong cloud security expertise across AWS, Azure, and GCP, with advanced proficiency in IaC (Terraform, Ansible, or Bicep) and Security as Code automation principles
- Expert knowledge of CIS Benchmarks for Linux and Windows OS hardening, with experience applying automated configuration management at scale
- Broad security tooling experience across vulnerability management (Tenable, Qualys, Rapid7), EDR/XDR (CrowdStrike, SentinelOne), and SIEM/SOAR platforms (Splunk, Sentinel)
- Proven senior stakeholder management and communication skills with the ability to articulate complex security risks to executive audiences - desirable: CISSP, CISSP-ISSAP, or cloud security certifications
Contract Details:
- Rate: £700 per day inside IR35
- Location: London (4x a week)
- Duration: 6 Month Initial Contract