Security Architect - Azure, Zero Trust, SASE
Security Architect - Azure, Zero Trust, SASE
London/Hybrid - 40% office attendance
A leading international firm is seeking an experienced Security Architect to own and develop its enterprise security architecture strategy across cloud, on-premises and hybrid environments.
Working within the Strategy and Architecture team, you will act as the firm's technical authority on cybersecurity. You will define security standards, patterns and roadmaps while ensuring security is Embedded into the design and implementation of new technologies, platforms and services.
The role will work closely with the CTO, CISO, Information Security, Risk and Compliance teams, as well as architects and senior business stakeholders across the firm.
Key responsibilities:
- Own the enterprise security architecture strategy, vision and roadmap.
- Design security solutions across Azure, on-premises, hybrid and network environments.
- Develop and maintain security architecture standards, principles, patterns and high-level designs.
- Lead the architectural approach to Zero Trust and SASE.
- Embed security requirements into new products, platforms and technology projects.
- Assess technology vendors and recommend appropriate security solutions.
- Advise on identity and access management, network segmentation, encryption, data residency and cloud security.
- Contribute to Architecture Review Boards and technical design authorities.
- Translate ISO 27001, NIST, CIS, GDPR and other regulatory requirements into practical architectural controls.
- Help define security standards governing the safe adoption of AI and machine-learning technologies.
- Act as a trusted security adviser to senior technology and business stakeholders.
Required experience:
- Proven experience working as a Security Architect within a law firm or in-house legal environment.
- Strong experience designing enterprise security solutions across Azure, cloud, on-premises and hybrid environments.
- Practical knowledge of Zero Trust and SASE architectures.
- Experience with technologies including ZTNA, CASB, identity and access management, Firewalls, NAC and network segmentation.
- Strong Azure networking knowledge, including VNETs, VNET peering and VNET gateways.
- Experience owning security designs from strategy and roadmap through to implementation.
- Strong understanding of security architecture frameworks, ISO 27001, NIST, GDPR and data-residency requirements.
- Experience producing architectural documentation, standards, security patterns and non-functional requirements.
- Confidence presenting architectural recommendations to CTO, CISO and senior stakeholder audiences.
Desirable experience:
- CISSP certification.
- TOGAF certification, with CISM or SABSA also advantageous.
- Experience with Zscaler, Palo Alto Prisma or comparable SASE platforms.
- Knowledge of AI-security risks such as data leakage, prompt injection, model integrity and supply-chain threats.
- Understanding of encryption, BYOK and hardware security modules.
- Experience with Azure PaaS services such as APIM, Azure AI Foundry and Logic Apps.
This is an opportunity to take genuine ownership of security architecture within a complex, internationally distributed organisation and influence how emerging cloud, data and AI technologies are adopted securely.