Security Architect

Micro IT Global Ltd
Bristol, United Kingdom
1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Compensation
£ 57K

Job location

Bristol, United Kingdom

Tech stack

Access Network
Amazon Web Services (AWS)
Computing Platforms
Azure
Software as a Service
Cloud Computing
Computer Security
Information Systems
Data Centers
Infrastructure as a Service (IaaS)
Identity and Access Management
Network Segmentation
Platform as a Service (PAAS)
Sherwood Applied Business Security Architecture
Service Development Studio
Zachman Framework
Data Classification
User Controls
Malware
Firewalls (Computer Science)
Togaf
Information Technology
Operational Systems
Multiplatform
Microservices

Job description

  • Develop and maintain a security architecture process that enables the enterprise to develop and implement security solutions and capabilities that are clearly aligned with the business, technology, threat, and customer drivers
  • Develop security strategy plans and roadmaps based on sound enterprise architecture practices
  • Develop and maintain security architecture artefacts (e.g., models, templates, standards, patterns & procedures) that can be used to leverage security capabilities in projects and operations
  • Track developments and changes in the digital business and threat environments to ensure that they're adequately addressed in security strategy plans and architecture artefacts
  • Participate in application and infrastructure projects, and commercial product/service development activities to provide security design and consultancy advice
  • Draft security procedures and standards to be reviewed and approved
  • Determine baseline security configuration standards for operating systems (e.g., OS hardening), network segmentation, identity, and access management (IAM) and cyber products and services
  • Develop standards and practices for data encryption and tokenization in the organization, based on the organization's data classification criteria
  • Conduct or facilitate threat modelling of services and applications that tie to the risk, data and industry drivers associated with the service or application
  • Validate IT infrastructure and other reference architectures for security best practices and recommend changes to enhance security and reduce risks, where applicable
  • Validate security configurations and access to security infrastructure tools, including firewalls, IPSs, WAFs and anti-malware/endpoint protection systems for both internal and commercial utilisation
  • Review network segmentation to ensure the least privilege for network access
  • Liaise with the Procurement team to conduct security assessments of existing and prospective vendors, especially those with which the organization shares intellectual property (IP), as well as regulated or other protected data:

o Software as a service (SaaS) provider o Cloud/infrastructure as a service (IaaS) provider o Managed service providers (MSPs) o Payroll providers

  • Evaluate the statements of work (SOWs) for these providers to ensure that adequate security protections are in place. Assess the providers' SSAE 16 SOC 1 and SOC 2 audit reports (or alternative sources) for security-related deficiencies and required "user controls" and report any findings to the Director, Security Engineering and Procurement teams
  • Support the testing and validation of internal and commercial security controls, as directed by the Director, Security Engineering
  • Review security technologies, tools and services, and make recommendations to the broader security and product development teams for their use, based on security, financial, operational and commercial metrics
  • Liaise with other security architects and security practitioners to share best practices and insights

Requirements

  • A bachelor's or master's degree or equivalent in computer science, information systems or another related field; or equivalent work experience is desired
  • Professional security management certification, such as a Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA) or other similar credentials, is desired
  • Formal training in a relevant enterprise architecture methodology (for example, the Zachman Framework or TOGAF)
  • Combined IT and security work experience, with a broad exposure to infrastructure/network and multiplatform environments
  • Expert knowledge of security issues, techniques and implications across all existing computer platforms, including datacentre, networks, cloud (IaaS/PaaS/SaaS), micro-services and emerging/maturing technology platforms
  • Experience in using an enterprise architecture methodology (for example, Zachman, TOGAF and Gartner frameworks)
  • Knowledge of a security-specific architecture methodology (for example, SABSA).
  • Knowledge or exposure to Cloud technologies, such as IaaS, SaaS & PaaS deployments, with detailed knowledge of Azure & AWS being highly desirable
  • Experience or exposure to projects involving the UK MoD and/or HMG Standards
  • Individuals with SC clearance or who are eligible to apply for SC are highly desirable

About the company

We are currently recruiting for a Security Architect on behalf of a leading Global SATCOMS company based in the UK. So if you are a Security Architect and are looking for a new opportunity where you can make your career take off " Quite Literally", then look no further!

Apply for this position