security architect

Deloitte
Aberdeen, UK
8 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Amazon Web Services Architectural Patterns User Authentication Microsoft Azure Cloud Computing Security Cyber Security Intrusion Detection and Prevention Javaserver Pages Network Security Sherwood Applied Business Security Architecture Security Information and Event Management Cloud Platform System
+6 more
Firewalls (Computer Science) Togaf SC Clearance Deployment Automation Devsecops Vulnerability Analysis

Job description

  • Roles available at multiple seniority levels roles available - suitable for applicants with 5-10+ years’ experience
  • Base Office Location: Bristol or London
  • Mandatory Requirement: Active (or eligible for) UK Security Check (SC) or Developed Vetting (DV) security clearance.

A Security Architect operates as a senior member of the team, responsible for the design of technical security solutions, maintaining documentation and developing architecture patterns and approaches for new technologies and solutions.

The Security Architect will lead the technical engagement and bring together technical security SMEs such as Identity, Security Testing and Privacy to solve the business problem.

As a senior member of the technical team, security architects must develop relationships with key stakeholders, understand a client’s security policy framework, and design solutions that will meet our client requirements.

Our projects vary greatly and your responsibility as a security architect will differ based on the focus of the client engagement and your skillset, but could include and may require you to:

  • Understand clients’ policies and security landscapes and create vision, principles and architecture solutions

  • Articulate, communicate, and justify design decisions to non-technical stakeholders

  • Maintain relationships with senior technical stakeholders

  • Learn new technical solutions from vendors and articulate how they solve client problems by providing the technical design to be adopted (Architecture Patterns)

  • Collaborate with vendors and third-party partners to ensure the security of external systems and data exchanges.

  • Provide specialist technical advice, recommended approaches, recommended security controls, & identify solutions that meet client business objectives.

  • Develop and maintain security architectures, ensuring alignment with business goals, industry standards, established patterns and regulatory requirements.

  • Stay up to date with emerging security threats, technologies, and industry best practices, and provide recommendations for improvement.

  • Conduct security audits and assessments to identify gaps and recommend remediation actions.

  • Conduct risk assessments and scoping vulnerability assessments to identify potential security threats and vulnerabilities.

Requirements

All applicants must be willing and eligible to apply for and obtain UK security clearance to Security Check (SC) or Developed Vetting (DV) level, if not holding an existing clearance.

Candidates will be able demonstrate relevant knowledge & experience through a combination of qualifications and evidence of work history such as:

  • Information Security qualification (or equivalent) e.g. CISSP.

  • In-depth knowledge of security frameworks, standards, and best practices (e.g., ISO 27001, NIST, CIS).

  • Experience as a Security Architect or in a similar role, with a strong track record of designing and implementing security controls and/or solutions and leading technical teams.

  • Experience with architecture methodology such as TOGAF or SABSA

  • Experience of threat and risk modelling

  • Strong understanding of network security, encryption, authentication, and access control mechanisms.

  • Experience with security technologies such as firewalls, intrusion detection/prevention systems, security information and event management (SIEM) systems, and vulnerability assessment tools, and their configuration options.

  • Familiarity with cloud security principles and best practices, including securing cloud-based infrastructure and services (AWS, Azure or Google)

  • Experience of DevSecOps

  • Experience researching technology trends and ways to secure those technologies.

  • Experience with automated deployment techniques and CI/CD pipelines.

  • Experience working in or with Government organisations, including the handling of assets subject to the Government Security Classification Policy.

  • Knowledge of Government cyber requirements related to Defence and Security e.g. Secure by Design, JSP 440.

About the company

Distinctive thinking, deep expertise, innovation and collaborative working. That’s what connects us. That’s what makes us Deloitte. If you want to help solve some of the biggest tech and transformational challenges around, join us. Together, we’ll make an impact that matters.

Cyber

The modern world is more complex than ever before, and we are navigating an ever-changing landscape. We help clients to operate with resilience and grow with confidence to secure success and minimise risk., Deloitte drives progress. Using our vast range of expertise, we help our clients’ become leaders wherever they choose to compete. To do this, we invest in outstanding people. We build teams of future thinkers, with diverse talents and backgrounds, and empower them all to reach for and achieve more.

What brings us all together at Deloitte? It’s how we approach thousands of decisions we make every day. How we behave, our beliefs, and our attitudes. In other words: our values. Whatever we do, wherever we are in the world, we lead the way, serve with integrity, take care of each other, foster inclusion, and collaborate for measurable impact. These five shared values lead every decision we make and action we take, guiding us to deliver impact on how and where it matters most., “The opportunities to make a difference here are huge. We’re constantly encouraged to come up with ideas, so a lot of what we do to drive change comes from within our own workforce.

  • Gurpal, T&T

“Innovation is at the heart of everything we do, so we’re using the latest technologies to constantly improve how we deliver our projects and bring insights to our clients. It means I’m always learning.” - Gurpal, T&T

Our commitment to you

Making an impact is more than just what we do: it’s why we’re here. So, we work hard to create an environment where you can experience a purpose you believe in, the freedom to be you, and the capacity to go further than ever before.

We want you. The true you. Your own strengths, perspective, and personality. So we’re nurturing a culture where everyone belongs, feels supported and heard, and is empowered to make a valuable, personal contribution. You can be sure we’ll take your wellbeing seriously, too. Because it’s only when you’re comfortable and at your best that you can make the kind of impact you, and we, live for.

Your expertise is our capability, so we’ll make sure it never stops growing. Whether it’s from the complex work you do, or the people you collaborate with, you’ll learn every day. Through worldclass development, you’ll gain invaluable technical and personal skills. Whatever your level, you’ll learn how to lead., A career at Deloitte is an opportunity to develop in any direction you choose. Join us and you’ll experience a purpose you can believe in and an impact you can see. You’ll be free to bring your true self to work every day. And you’ll never stop growing, whatever your level.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on apply.deloitte.co.uk

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil ¡ LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira ¡ Coffee With Developers

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia ¡ LIVE

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova ¡ LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin ¡ WWC 2022

1:24 min

Evaluating formal AWS certifications versus raw practical engineering experience

Jan Giacomelli ¡ LIVE

Videos

See all

Related articles

See all