Security Architect
Security Architect - D365
1 or 2 days a month on site in Kent - South-East England
Support Cybersecurity Architecture
- Support major business transformation programmes by developing and integrating secure cybersecurity architectures across enterprise systems and networks.
- Design solutions capable of supporting:
- Multi-level security requirements.
- Multiple data classification levels across geographically distributed environments.
Security Documentation
- Produce and maintain security architecture and systems security engineering documentation throughout the programme lifecycle.
- Ensure security deliverables are aligned with organisational and regulatory requirements.
Identity & Access Management
- Provide architectural guidance for enterprise Identity and Access Management (IAM) solutions.
- Support the design of secure authentication, authorisation and access control models.
Secure Configuration Management
- Ensure secure configuration management principles are embedded throughout programme delivery.
- Promote security best practices across solution implementation.
Security Architecture & Compliance
- Ensure all new and enhanced systems align with enterprise cybersecurity architecture principles, policies and standards.
- Support compliance with applicable security and regulatory frameworks.
Business Risk & Critical Services
- Work with business stakeholders to identify and prioritise critical business services and functions.
- Ensure appropriate security controls are incorporated into solution designs.
Security Assurance
- Conduct security architecture reviews throughout programme delivery.
- Identify security gaps, risks and areas of non-compliance.
- Support the development and delivery of Security Risk Management Plans.
Security Impact Assessment
- Assess the impact of new systems, integrations and interfaces on the existing technology landscape and organisational security posture.
- Recommend appropriate mitigation strategies where required.
Security Design Reviews
- Evaluate security architectures and technical designs against both functional and non-functional requirements.
- Ensure solutions meet security, resilience and operational standards.
Security Controls
- Determine appropriate technical and procedural security controls for enterprise systems and networks.
- Ensure security requirements are documented and incorporated into solution delivery.
Stakeholder Collaboration
- Work closely with Enterprise Architecture, Cyber Security, Infrastructure and Delivery teams.
- Contribute to technology governance, risk management, compliance reporting and architecture assurance activities.