Application Security Architect
Role details
Job location
Tech stack
Job description
In return, youll join a collaborative and inclusive culture that values innovation and supports development. Youll benefit from flexible working arrangements, excellent civil service benefits, and the opportunity to be part of a high-profile mission that impacts millions of people and the UKs energy future.
We have a critical purpose to lead the development of secure digital systems and architecture within our organisation, combating cyber threats and strengthening resilience across the UKs energy landscape through trusted design, strategic leadership, and expert guidance., * To support the team deliverables, utilising your expertise to ensure successful outcomes across collaborating teams and strategies that can be used in the long term across the whole organisation.
- Leverage a variety of sources to continuously maintain Ofgem Cyber Reference Architecture with principles, requirements, patterns, anti-patterns, implementation, engineering and operational maintenance options.
- Influence key organisational and architectural decisions and interact with senior stakeholders across organisations to reach and influence a wide range of people across larger teams and communities.
- Security Architecture Design: Develop and maintain secure architecture patterns for applications and services.
- Threat Modelling & Risk Assessment: Conduct threat modelling and risk assessments to identify vulnerabilities and recommend mitigation strategies.
- Secure SDLC Integration: Embed security practices into the software development lifecycle, including code reviews, static analysis, and secure coding standards.
- Stakeholder Engagement: Communicate security risks and solutions effectively to technical and non-technical audiences, influencing secure design decisions.
- Security Testing & Validation: Oversee penetration testing, vulnerability management, scanning, and remediation activities.
- Policy & Compliance Alignment: Ensure application security aligns with organisational policies, GDS standards, and regulatory requirements.
- Innovation & Advisory: Provide expert advice on emerging security technologies and trends, including AI, cloud-native security, and zero-trust architectures.
Key Outputs and Deliverables
- Use applied security expertise to develop and maintain solutions that align with Ofgem Cyber guidance, to support the improvement of cyber resilience for the organisation.
- Use applied security expertise to identify key programme and technical risks, leading the design of mitigating security architectures.
- Document expert cyber architecture design reviews of operator system architectures to identify security weaknesses, recommend mitigations and ensure security requirements are integrated into product backlogs and user stories.
- Identify and Document Cyber Risks within the Secure by Design lifecycle.
- Provide expert advice on security architecture implications of technological trends when applied to existing systems, and how innovative technologies change the security approach required.
- Effectively communicate difficult risk and security concepts in accessible ways that can be clearly understood by business leaders. Contribute to and develop risk communication strategies.
- Attend, lead and provide expert input to Specialist Interest Groups to share security best practice across the sector.
- Follow a methodical and repeatable approach to reviewing the security of a system architecture and describe that approach.
- Contribute to new and innovative security architecture guidance for others to re-use through architecture blueprints and reusable design patterns.
- Lead and support the development of penetration test scopes, reports, and remediation plans., You will then be asked to provide a 1250 word personal statement evidencing how you meet the essential and desirable skills and capabilities listed in the role profile. Please ensure you demonstrate clearly, within your supporting statement, how you meet each of the criteria listed in the role profile.
The personal information we have collected from you will be shared with Cifas who will use it to prevent fraud, other unlawful or dishonest conduct, malpractice, and other seriously improper conduct. If any of these are detected, you could be refused certain services or employment. Your personal information will also be used to verify your identity. Further details of how your information will be used by us and Cifas, and your data protection rights, can be found by [https://www.cifas.org.uk/fpn]. Feedback will only be provided if you attend an interview or assessment.
Security
Successful candidates must undergo a criminal record check. Successful candidates must meet the security requirements before they can be appointed. The level of security needed is security check .
See our vetting charter . People working with government assets must complete baseline personnel security standard (opens in new window) checks., * UK nationals
- nationals of the Republic of Ireland
- nationals of Commonwealth countries who have the right to work in the UK
- nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS)
- nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS)
- individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020
- Turkish nationals, and certain family members of Turkish nationals, who have accrued the right to work in the Civil Service
Requirements
Do you have experience in TOGAF?, * Expertise in security architecture and applied security capability. (Lead criteria)
- Certified to one, more or equivalent of CISSP, GICSP, GRID, SABSA, or TOGAF. (Lead criteria)
- Knowledge of microservices, containerisation, and cloudnative security models
- Practitioner in information risk assessment and risk management.
- Experience in Secure by Design (Cabinet Office Guidance) application security, secure software design, and architecture.
- Experience in the process of developing and managing a range of options and decisions aligning with organisational priorities.
Desirable Criteria:
- Experience of working in the energy sector.
- Experience in automated security testing.
- Experience with frameworks such as OWASP, NIST, ISO 27001, and CAF., Certified to one, more or equivalent of CISSP, GICSP, GRID, SABSA, or TOGAF., * Seeing the Big Picture
- Changing and Improving
- Making Effective Decisions
- Communicating and Influencing
Benefits & conditions
Alongside your salary of £61,446, OFGEM contributes £17,800 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides. Ofgem can offer you a comprehensive and competitive benefits package which includes; up to 30 days annual leave. Excellent training and development opportunities. The opportunity to join the Civil Service pension arrangements which include a valuable range of benefits. Flexible working hours and family friendly policies. Restaurant and subsidise gym (London only). Interest free season ticket loan.