Director - Cyber Security Architect
We are seeking an experienced Cybersecurity Solutions Architect to join our Information Security team and play a key role in strengthening the organisation's security posture across all business units.
The organisation operates within a complex and highly interconnected technology environment, supported by a broad range of platforms, applications, infrastructure, cloud services, and emerging technologies. This role will be responsible for ensuring that security is embedded into the design and delivery of enterprise-wide technology solutions from the outset.
The Cybersecurity Solutions Architect will act as a senior technical leader and trusted advisor, providing security architecture expertise across major technology initiatives. The successful candidate will combine strategic thinking with strong hands-on technical knowledge and will work closely with technology, engineering, infrastructure, application, cloud, risk, and business teams.
This position requires the ability to translate business and technology requirements into secure, scalable, and practical architecture designs, while ensuring alignment with enterprise security standards, regulatory expectations, and industry best practices.
Key Responsibilities
Security Architecture Design and Development
Design and define secure architecture for enterprise systems, applications, cloud platforms, infrastructure, networks, and digital services.
Develop security architecture principles, standards, reference architectures, design patterns, and reusable security controls.
Ensure that security requirements are incorporated throughout the technology lifecycle, from initial concept and design through implementation and production operations.
Provide architectural guidance across areas including identity and access management, cloud security, application security, network security, data protection, container security, and infrastructure security.
Develop target-state security architectures that support the organisation's long-term technology and business strategy.
Security Solution Design Review
Review solution architectures, technical designs, and implementation plans to identify security risks, control gaps, and areas for improvement.
Assess new and existing technology solutions to ensure alignment with internal security policies, architecture standards, and regulatory requirements.
Work closely with project teams, engineers, developers, and technology vendors to recommend practical security controls and remediation measures.
Participate in architecture review boards, governance forums, and major technology project discussions.
Provide security approval, recommendations, or risk-based guidance for complex technology initiatives.
Strategic Security Guidance and Roadmap Development
Advise senior technology and business stakeholders on security architecture, emerging risks, and strategic security priorities.
Contribute to the development and maintenance of the organisation's security architecture roadmap.
Identify opportunities to improve security maturity, simplify security controls, and strengthen resilience across the technology environment.
Align security architecture initiatives with broader enterprise architecture, technology transformation, cloud adoption, and digitalisation programmes.
Support the development of security investment proposals, capability plans, and multi-year implementation roadmaps.
Provide guidance on balancing security requirements with business needs, usability, scalability, and operational efficiency.
Threat Modelling and Risk Assessment
Conduct threat modelling, architecture risk assessments, and security design assessments for critical systems and applications.
Identify potential attack paths, trust boundaries, vulnerabilities, and control weaknesses within proposed and existing solutions.
Recommend appropriate preventive, detective, and responsive security controls based on risk and business criticality.
Support the assessment of risks relating to cloud platforms, containers, APIs, artificial intelligence, third-party services, and emerging technologies.
Work with cyber risk and governance teams to document security risks, compensating controls, and remediation plans.
Provide technical input into security exceptions, risk acceptance decisions, and control-assurance activities.
Technology Evaluation and Proof of Concept
Evaluate new security technologies, platforms, and architectural approaches to determine their suitability for the organisation.
Lead or support proof-of-concept exercises, technical assessments, and product evaluations.
Assess the security capabilities, scalability, integration requirements, operational impact, and commercial viability of potential solutions.
Collaborate with vendors and internal stakeholders during technology-selection and implementation processes.
Maintain awareness of emerging cyber threats, security trends, regulatory developments, and new technology risks.
Provide recommendations on the adoption of security tools and capabilities that enhance protection, visibility, automation, and resilience.
Technical Leadership and Collaboration
Act as a subject-matter expert and senior technical escalation point for cybersecurity architecture and engineering matters.
Provide technical leadership across complex security initiatives and transformation programmes.
Mentor security engineers, architects, and technology professionals on secure architecture and design practices.
Build strong working relationships with infrastructure, cloud, application, data, enterprise architecture, engineering, risk, audit, and business teams.
Communicate complex security risks and technical concepts clearly to both technical and non-technical stakeholders.
Support incident-response, root-cause analysis, and remediation activities where architectural weaknesses or security-design issues are identified.
Qualifications and Experience
Master's degree in Computer Science, Information Security, Cybersecurity, Engineering, or a related technical discipline.
At least 15 years of experience across information technology or cybersecurity.
A minimum of eight years of progressive cybersecurity experience, with a strong focus on security architecture, security engineering, or enterprise security design.
Proven experience designing and implementing robust, scalable, and defence-in-depth security architectures.
Strong knowledge of enterprise technology environments, including cloud platforms, applications, infrastructure, networks, APIs, identity systems, and data platforms.
In-depth understanding of containerisation and orchestration technologies, including Kubernetes and Docker, as well as associated security controls and best practices.
Strong knowledge of container security areas such as image security, runtime protection, cluster security, secrets management, network policies, access controls, and software supply-chain security.
Demonstrated expertise in artificial intelligence security architecture, including the risks and controls associated with AI platforms, machine-learning workloads, generative AI, large language models, and AI-enabled applications.
Experience assessing security risks associated with model deployment, data exposure, prompt manipulation, access controls, third-party models, and AI infrastructure.
Strong understanding of security architecture frameworks, threat-modelling methodologies, secure design principles, and risk-assessment approaches.
Proven technical leadership capabilities, with experience guiding complex security projects, architecture programmes, engineering teams, or cross-functional initiatives.
Strong stakeholder-management skills and the ability to influence senior technology and business leaders.
Excellent analytical, problem-solving, and decision-making capabilities.
Ability to operate effectively within a complex, fast-paced, and highly collaborative enterprise environment.
Certifications
CISSP certification is required.
An architecture-focused certification or specialisation, such as ISSAP, is strongly preferred.
Additional certifications in cloud security, enterprise architecture, Kubernetes security, or AI security would be advantageous.
Communication Skills
Fluent in English, with strong verbal, written, and presentation skills.
Excellent business-writing capability, with the ability to prepare architecture documents, security standards, risk assessments, technical recommendations, and executive-level materials.
Ability to explain complex cybersecurity concepts in a clear and practical manner to both technical and non-technical audiences.
FAQs
Congratulations, we understand that taking the time to apply is a big step. When you apply, your details go directly to the consultant who is sourcing talent. Due to demand, we may not get back to all applicants that have applied. However, we always keep your CV and details on file so when we see similar roles or see skillsets that drive growth in organisations, we will always reach out to discuss opportunities.
Yes. Even if this role isn’t a perfect match, applying allows us to understand your expertise and ambitions, ensuring you're on our radar for the right opportunity when it arises.
We also work in several ways, firstly we advertise our roles available on our site, however, often due to confidentiality we may not post all. We also work with clients who are more focused on skills and understanding what is required to future-proof their business.Â
That's why we recommend registering your CV so you can be considered for roles that have yet to be created.Â
Yes, we help with CV and interview preparation. From customised support on how to optimise your CV to interview preparation and compensation negotiations, we advocate for you throughout your next career move.