> Markdown version of [/jobs/ext/1202286-lead-security-privacy-and-data-protection-architect-i-ai](https://www.wearedevelopers.com/jobs/ext/1202286-lead-security-privacy-and-data-protection-architect-i-ai). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Security, Privacy and Data Protection Architect- i.AI - **Company:** Department for Science, Innovation and Technology - **Location:** London, UK (Remote available) - **Experience:** Expert - **Salary:** £74,605.0 - £90,756.0 - **Contract:** Temporary contract - **Skills:** Agile Methodology, Artificial Intelligence, Data Analysis, Software System Penetration Testing, Architectural Patterns, Audit Trail, Cyber Security, Databases, Data Sharing, Identity and Access Management, Intrusion Detection and Prevention, Information Systems Security Architecture Professional, Data Streaming, Systems Architecture, Systems Integration, Software Vulnerability Management, Privacy Controls, SC Clearance, Cybercrime, Integration Frameworks, Ddos - **Published:** July 8, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=721e193a331c413c ## About the Role * Experience designing and implementing security architecture in a complex organisation, and applying it at both technical and operational levels * Experience embedding privacy by design and data protection by design into architecture, engineering and service delivery * Strong understanding of the specific security and privacy issues presented by generative AI, and the ability to stay current with emerging best practice in this area * Experience applying cyber security principles, including understanding of infrastructure security, information security, penetration testing, vulnerability management, and mitigating common cyber threats (e.g. DDoS attacks). * Experience understanding, interpreting and applying legal obligations, policies and regulations such as UK GDPR, the Data Protection Act 2018, and other applicable data protection requirements in the design and operation of digital services * Experience identifying and managing privacy and data protection risks in complex systems, including AI-enabled services, third-party integrations and cross-organisational data sharing * Experience leading, contributing to, or advising on Data Protection Impact Assessments (DPIAs) or similar privacy risk assessments, and translating findings into technical or operational controls * Experience analysing and advising on personal data handling, including data flows, minimisation, retention, deletion, access controls, auditability and sharing arrangements * Experience designing, identifying and implementing new technologies within an organisation * Experience prioritising work, working under pressure, and dealing with changing priorities and ambiguity * Experience translating technical security, privacy, data protection or system architecture details and risks to non-technical stakeholders, both verbally and in writing * Experience leading and managing colleagues across multiple disciplines, and escalating concerns within a workstream, team or programme where appropriate * Experience responding to security incidents and working within incident or risk management frameworks * Experience interpreting, explaining and reviewing system architectures * Experience identifying and analysing technical platform vulnerabilities * Experience working with Agile practices and processes * If you meet some of these criteria, but not every single one, we’d still encourage you to apply. Technical skills We'll assess you against these technical skills during the selection process: * Candidates will be asked a scenario question by the panel and should be expected to respond to follow-up questions. Further details will be provided in advance, including the opportunity for candidates to prepare for the technical interview. ## Description Talent: We bring together the UK’s best AI talent across a range of functions. You will work alongside exceptional researchers and top government leaders, staying at the cutting edge of technology. Innovation: We set precedents for what is possible in government. We combine the pace of a start-up with the influence of being at the digital centre of government. You will test new ideas, expand what is possible, and leverage unique government data to create novel solutions. Impact: We are dedicated to using AI as a tool for public good - this can mean improving outcomes in schools, boosting housebuilding or providing more personalised support for those in need. With the backing of the Prime Minister, you will turn technical breakthroughs into real-world applications that affect millions of citizens., The Lead Security, Privacy and Data Protection Architect will be accountable for the security architecture, privacy architecture and data protection design of a government service. This is not solely a cyber security architecture role: it requires someone who can bring together secure by design, privacy by design and data protection by design in the delivery of an AI-enabled public service. Initially, the role will be hands-on and operational. You will help harden the platform against security risks, support monitoring and threat detection, respond to incidents, and build a more systematic approach to security, privacy and data protection assurance. As the service scales, you will define and lead security, privacy and data protection architecture and controls across departments and ALBs using the service, acting as a senior authority in this space. As a Lead Security, Privacy and Data Protection Architect, you will: Shape strategy and influence across government * Build effective relationships with senior stakeholders across departments and ALBs, while engaging with wider cross-government security, privacy and data communities * Communicate and translate technical security, privacy and data protection risks to both technical and non-technical stakeholders * Reach and influence a wide range of people across larger teams, programmes and communities * Own the relationship between DSIT, GDS, adopters and the Information Commissioner’s Office to support best practice in privacy and data protection * Design secure, privacy-conscious architecture * Lead the architecture for the platform, ensuring security by design, privacy by design and data protection by design are embedded throughout the service lifecycle * Research and apply innovative architecture solutions to new or existing problems, and clearly justify and communicate design decisions * Develop vision, principles and strategy for security, privacy and data protection architecture across a project or technology area * Analyse technical solutions and produce architectural patterns that support assurance, quality and scalability * Assess risks relating to AI, integrations, infrastructure, identity, and personal data flows * Define and assure appropriate controls for voice data, transcripts, logs, model inputs and outputs, retention, deletion, auditability and access management * Lead the technical design and implementation of controls around the user-focused platform * Lead on privacy and data protection * Provide expert leadership on privacy and data protection in the design and operation of the service * Ensure the platform meets legal obligations and user expectations for privacy and data protection * Assess and advise on personal data processing, minimisation, retention, deletion, access controls, auditability and data sharing across the platform and adopter integrations * Support or lead Data Protection Impact Assessments (DPIAs), privacy risk assessments and mitigation planning, ensuring outcomes are reflected in technical and operational controls * Work closely with legal, policy, delivery, platform and operations teams to ensure personal data is handled appropriately and lawfully * Drive operational security and assurance * Work with platform and operations teams to secure early deployments * Provide expert input into security incidents, remediation activity and areas for change, while advising on best practice across government * Perform reactive security monitoring and incident support * Respond to alerts and challenges, support investigations, and provide feedback that shapes policy and requirements * Assist with vulnerability triage and remediation tracking * As the service scales, you will also: * Own security, privacy and data protection architecture and strategic frameworks across multiple departments and ALBs * Define advanced controls, monitoring approaches and defence-in-depth patterns * Establish cross-government approaches to privacy assurance, data sharing, retention, accountability and governance * Support continuous assurance in increasingly complex threat and operating environments * Act as a senior security, privacy and data protection authority for the government service, Applications will be sifted against the essential criteria, including relevant experience and motivation for the role. Shortlisted candidates will be invited to a preliminary call. Candidates who pass the initial sift may be progressed to a full sift, or progressed straight to assessment/interview. Those who progress will then attend an interview, which will include questions on their application, a technical assessment, and a behavioural interview. For the technical assessment, candidates will be asked a scenario question by the panel and should be expected to respond to follow-up questions. Further details will be provided in advance, including the opportunity for candidates to prepare for the technical interview. Candidates may use AI tools to support this preparation. Appointment is conditional on successfully completing UK Government SC clearance. Prior clearance is not required — we will sponsor and support you. You should normally have been resident in the UK for 2 of the past 5 years. Employment is conditional on obtaining and maintaining the required clearance(s)., Candidates who meet the minimum benchmark may be placed on a Reserve List for consideration for similar roles, including those at a lower grade. Candidates who narrowly miss the benchmark and are not placed on the Reserve List may still be considered for an offer in a similar role at a lower grade. Please note terms and conditions are attached. Please take time to read the document to determine how these may affect you. Any move to the Department for Science, Innovation and Technology from another employer will mean you can no longer access childcare vouchers. This includes moves between government departments. You may however be eligible for other government schemes, including Tax Free Childcare; for further information visit the Childcare Choices website. DSIT does not normally offer full home working (i.e. working at home); but we do offer a variety of flexible working options (including occasionally working from home). DSIT cannot offer Visa sponsorship to candidates through this campaign. DSIT holds a Visa sponsorship licence but this can only be used for certain roles and this campaign does not qualify. In order to process applications without delay, we will be sending a Criminal Record Check to Disclosure and Barring Service on your behalf. However, we recognise in exceptional circumstances some candidates will want to send their completed forms direct. If you will be doing this, please advise Government Recruitment Service of your intention by emailing Pre-EmploymentChecks.grs@cabinetoffice.gov.uk stating the job reference number in the subject heading. Applicants who are successful at interview will be, as part of pre-employment screening, subject to a check on the Internal Fraud Database (IFD). This check will provide information about employees who have been dismissed for fraud or dishonesty offences. This check also applies to employees who resign or otherwise leave before being dismissed for fraud or dishonesty had their employment continued. Any applicant’s details held on the IFD will be refused employment. A candidate is not eligible to apply for a role within the Civil Service if the application is made within a 5 year period following a dismissal for carrying out internal fraud against government. Feedback Feedback will only be provided if you attend an interview or assessment. Security Successful candidates must undergo a criminal record check. Successful candidates must meet the security requirements before they can be appointed. The level of security needed is security check . See our vetting charter . People working with government assets must complete baseline personnel security standard (opens in new window) checks., * UK nationals * nationals of the Republic of Ireland * nationals of Commonwealth countries who have the right to work in the UK * nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS) * nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS) * individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020 * Turkish nationals, and certain family members of Turkish nationals, who have accrued the right to work in the Civil Service ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [GenAI Security: Navigating the Unseen Iceberg](https://www.wearedevelopers.com/videos/1744-genai-security-navigating-the-unseen-iceberg) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [WeAreDevelopers LIVE - Chrome for Sale? Comet - the upcoming perplexity browser Stealing and leaking](https://www.wearedevelopers.com/videos/1331-wearedevelopers-live-chrome-for-sale-comet-the-upcoming-perplexity-browser-stealing-and-leaking) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) ## Related Articles - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [What Industries Outside of AI Are Hiring The Most AI Experts?](https://www.wearedevelopers.com/magazine/98-what-industries-outside-of-ai-are-hiring-the-most-ai-experts) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Graph and AI Trends 2026: Why Is AI Running but Not Yet Delivering?](https://www.wearedevelopers.com/magazine/680-graph-and-ai-trends-2026-why-is-ai-running-but-not-yet-delivering)