> Markdown version of [/jobs/ext/1569861-security-architect](https://www.wearedevelopers.com/jobs/ext/1569861-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Architect - **Company:** John Lewis Partnership - **Location:** London, UK (Remote available) - **Salary:** £80,411.0 - **Contract:** Permanent contract - **Skills:** Agile Methodology, Artificial Intelligence, Amazon Web Services, Software as a Service, Cloud Computing, Cyber Security, Information Systems Security Architecture Professional, PCI Data Security Standards, Systems Development Life Cycle, Zero Trust Network Access, Software Safety, Sherwood Applied Business Security Architecture, Security Information and Event Management, Software Vulnerability Management, Google Cloud, Large Language Models, Technical Debt, HybridCloud, Togaf, Devsecops, Security Orchestration, Automation & Response - **Published:** July 15, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5800464192 ## About the Role * Agile & Technical Architecture Delivery: An adaptable, engineering-focused mindset with proven experience working across multiple service and domain teams through Agile and domain-based delivery models. * Core Security Frameworks & Methodologies: Practical experience facilitating threat modeling workshops, working within DevSecOps/SecOps environments, applying Zero Trust philosophies, and utilizing the NIST Cybersecurity Framework. * Hybrid-Cloud & Infrastructure Knowledge: Expert knowledge of securing data and workloads across Google Cloud/Workspace, Amazon Web Services, Zscaler, and commodity SaaS applications. * Critical Influence & Leadership: Proven ability to empower and influence others to make decisions, resolve challenges, and deliver outcomes that line up with the overarching business strategy. * Emerging Tech & Threat Awareness: A strong understanding of attacker tools, techniques, and procedures (alongside pragmatic mitigations) and practical experience securing AI/LLM deployments. * Advanced Architecture Frameworks: Experience designing SOC architectures (SIEM, SOAR, vulnerability management) and defining secure development lifecycles (SDLC). * Regulated Environments & Evaluation: Experience working within regulated environments (such as PCI-DSS) and leading product evaluation and tool selection processes. * Professional Certifications: Industry-recognized credentials such as TOGAF, SABSA, CISSP, CCSP, ISSAP, CEH, or platform-specific certifications (GCP Professional Cloud Architect/Security Engineer, Zscaler Zero Trust Associate, CSA Trusted AI Safety Expert). * Retail Business Domain Knowledge: An understanding of retail business capabilities and processes, with the ability to benchmark against marketplace good practice to drive competitive advantage. ## Description The John Lewis Partnership (JLP) continually invests in its security capabilities, recognizing the trust our customers place in our brand and the information they provide to us. The Partnership is accelerating the use of data and insight to enhance the experience and relevance our Partners and technology systems provide to our customers. Working as an integrated team member or as an advisor to service and domain teams, this role is responsible for designing security solutions, patterns, and blueprints across our data, platforms, cloud, and network capabilities to support our strategic intent within an ever-changing threat landscape. * Design End-to-End Security Solutions: Create effective, efficient, repeatable, and sustainable security solutions and patterns across cloud platforms (AWS, GCP) and traditional hosting environments to make a tangible difference to business security. * Embed Best Practice & Reduce Risk: Ensure security architecture best practices are brought to bear during solution design activities undertaken by delivery teams and third parties to reduce delivery cost, operational risk, and technical debt. * Democratize Secure Delivery: Enable architects and engineers across the enterprise through clear design principles, patterns, blueprints, and guardrails to help scale and democratize secure delivery. * Provide Commercial & Contractual Counsel: Advise and consult on the commercial and contractual implications of existing or new obligations, specifically reviewing contractual terms of technologies and business services being procured within your domain. * Drive Cross-Functional Collaboration: Partner closely with the CISO function, architecture, and engineering teams to ensure security capabilities bring intended value, actively optimizing opportunities through solution evangelism. * Monitor & Advise on Industry Trends: Stay up-to-date with shifts in technology, retail, and socio-economic trends, influencing internal technology and business decisions to support JLP's long-term strategic aims., * Modern Security Architecture Expertise: Extensive experience taking roadmap intent and combining it with good practice with business context and strong stakeholder engagement to define clear, outcome-focused solutions. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Building Well-Architected applications](https://www.wearedevelopers.com/videos/691-building-well-architected-applications) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)