> Markdown version of [/jobs/ext/1392753-security-architect-and-engineering-lead](https://www.wearedevelopers.com/jobs/ext/1392753-security-architect-and-engineering-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Architect and Engineering Lead - **Company:** Nhbc - **Location:** Milton Keynes, UK (Remote available) - **Experience:** Expert - **Salary:** £81,000.0 - £86,000.0 - **Contract:** Permanent contract - **Skills:** Identity and Access Management, Software Vulnerability Management, Delivery Pipeline - **Published:** July 23, 2026 - **Apply:** https://www.nhbc.co.uk/careers/job-opportunities?advertid=2973 ## About the Role We're looking for an experienced security leader who combines strategic thinking with deep technical expertise and a collaborative leadership style., * Proven experience defining and governing enterprise security architecture across complex technology environments, establishing principles, standards and security patterns that enable secure, resilient and scalable solutions. * A strong track record of embedding secure-by-design principles and influencing architects, engineers, delivery teams and business stakeholders to deliver security as an integral part of technology change. * Hands-on experience designing, implementing and integrating enterprise security technologies across hybrid environments, including Microsoft platforms, Azure, AWS, SaaS and IaaS. * Significant expertise across key security domains, including security governance, security operations and SIEM, network security, cloud security, identity and access management (IAM), vulnerability management and security assurance. * Strong knowledge of modern security engineering practices, including DevSecOps, CI/CD security, infrastructure as code, automated testing and continuous assurance within development pipelines. * Experience working across large-scale transformation programmes and product or delivery teams, providing technical leadership and security design assurance throughout the delivery lifecycle. * Excellent stakeholder engagement and influencing skills, with the ability to build trusted relationships across technology, operations, risk, assurance and business functions. * Strong analytical and problem-solving skills, with the ability to balance business objectives, risk and technical considerations to make informed decisions. * Excellent communication skills, able to translate complex technical concepts into clear, practical advice for both technical and non-technical audiences. * Demonstrable leadership experience, with the ability to inspire, coach and influence teams and drive a culture of continuous improvement and engineering excellence. ## Description At NHBC, we're committed to protecting the systems, services and data that support the UK house-building industry. As our Principal Security Architecture & Engineering Lead, you'll play a pivotal role in defining how security is embedded across our technology landscape, ensuring resilience, trust and confidence in everything we deliver. This is a strategic leadership role with significant technical influence. Working closely with the Chief Information Security Officer (CISO), you'll define and evolve our enterprise security architecture, establish secure-by-design principles and lead the engineering of security capabilities that protect our critical business services. You'll collaborate across architecture, engineering, infrastructure and delivery teams to ensure security is integrated into every stage of technology change. If you're passionate about modern security architecture, cloud technologies, engineering excellence and influencing change at enterprise scale, we'd love to hear from you. What you'll be doing As Principal Security Architecture & Engineering Lead, you will: * Partner with the CISO to define and deliver NHBC's enterprise security architecture, supporting critical business services and regulatory expectations. * Establish and maintain security architecture principles, standards, patterns and control frameworks across on-premises, cloud and third-party environments. * Provide security architecture leadership and governance through Architecture Design Authority and other technical governance forums. * Develop and contribute to solution architectures, ensuring security requirements are built into designs from the outset. * Define functional and non-functional security requirements that support secure, resilient and scalable technology solutions. * Champion secure-by-design practices across technology delivery, embedding consistent, proportionate and auditable security controls. * Drive the adoption of DevSecOps practices, working through matrix leadership with engineering and delivery teams to integrate security throughout development pipelines. * Partner with engineering, infrastructure and operational teams to design, implement and integrate security capabilities across the enterprise technology estate. * Lead technical security risk assessments, design assurance and remediation activities to strengthen controls and reduce enterprise risk. * Oversee the secure integration of third-party services and remote access solutions, ensuring controls align with business criticality and risk appetite. * Support cyber incident response and recovery by ensuring architectures enable effective detection, containment and rapid restoration of services. ## Related Videos - [How will artificial intelligence change the future of software testing?](https://www.wearedevelopers.com/videos/85-how-will-artificial-intelligence-change-the-future-of-software-testing) - [Starting business without breaking the bank: Self hosted OSS productivity ecosystem](https://www.wearedevelopers.com/videos/1219-starting-business-without-breaking-the-bank-self-hosted-oss-productivity-ecosystem) - [What is the real price of one successful line of code?](https://www.wearedevelopers.com/videos/1921-what-is-the-real-price-of-one-successful-line-of-code) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Climate vs. Weather: How Do We Sustainably Make Software More Secure?](https://www.wearedevelopers.com/videos/357-climate-vs-weather-how-do-we-sustainably-make-software-more-secure) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)