> Markdown version of [/jobs/ext/1904871-security-architect](https://www.wearedevelopers.com/jobs/ext/1904871-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # security architect - **Company:** Deloitte - **Location:** Aberdeen, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Architectural Patterns, User Authentication, Microsoft Azure, Cloud Computing Security, Cyber Security, Intrusion Detection and Prevention, Javaserver Pages, Network Security, Sherwood Applied Business Security Architecture, Security Information and Event Management, Cloud Platform System, Firewalls (Computer Science), Togaf, SC Clearance, Deployment Automation, Devsecops, Vulnerability Analysis - **Published:** August 3, 2026 - **Apply:** https://apply.deloitte.co.uk/UKCareers/Login?jobId=24465 ## About the Role All applicants must be willing and eligible to apply for and obtain UK security clearance to Security Check (SC) or Developed Vetting (DV) level, if not holding an existing clearance. Candidates will be able demonstrate relevant knowledge & experience through a combination of qualifications and evidence of work history such as: * Information Security qualification (or equivalent) e.g. CISSP. * In-depth knowledge of security frameworks, standards, and best practices (e.g., ISO 27001, NIST, CIS). * Experience as a Security Architect or in a similar role, with a strong track record of designing and implementing security controls and/or solutions and leading technical teams. * Experience with architecture methodology such as TOGAF or SABSA * Experience of threat and risk modelling * Strong understanding of network security, encryption, authentication, and access control mechanisms. * Experience with security technologies such as firewalls, intrusion detection/prevention systems, security information and event management (SIEM) systems, and vulnerability assessment tools, and their configuration options. * Familiarity with cloud security principles and best practices, including securing cloud-based infrastructure and services (AWS, Azure or Google) * Experience of DevSecOps * Experience researching technology trends and ways to secure those technologies. * Experience with automated deployment techniques and CI/CD pipelines. * Experience working in or with Government organisations, including the handling of assets subject to the Government Security Classification Policy. * Knowledge of Government cyber requirements related to Defence and Security e.g. Secure by Design, JSP 440. ## Description * Roles available at multiple seniority levels roles available - suitable for applicants with 5-10+ years' experience * Base Office Location: Bristol or London * Mandatory Requirement: Active (or eligible for) UK Security Check (SC) or Developed Vetting (DV) security clearance. A Security Architect operates as a senior member of the team, responsible for the design of technical security solutions, maintaining documentation and developing architecture patterns and approaches for new technologies and solutions. The Security Architect will lead the technical engagement and bring together technical security SMEs such as Identity, Security Testing and Privacy to solve the business problem. As a senior member of the technical team, security architects must develop relationships with key stakeholders, understand a client's security policy framework, and design solutions that will meet our client requirements. Our projects vary greatly and your responsibility as a security architect will differ based on the focus of the client engagement and your skillset, but could include and may require you to: * Understand clients' policies and security landscapes and create vision, principles and architecture solutions * Articulate, communicate, and justify design decisions to non-technical stakeholders * Maintain relationships with senior technical stakeholders * Learn new technical solutions from vendors and articulate how they solve client problems by providing the technical design to be adopted (Architecture Patterns) * Collaborate with vendors and third-party partners to ensure the security of external systems and data exchanges. * Provide specialist technical advice, recommended approaches, recommended security controls, & identify solutions that meet client business objectives. * Develop and maintain security architectures, ensuring alignment with business goals, industry standards, established patterns and regulatory requirements. * Stay up to date with emerging security threats, technologies, and industry best practices, and provide recommendations for improvement. * Conduct security audits and assessments to identify gaps and recommend remediation actions. * Conduct risk assessments and scoping vulnerability assessments to identify potential security threats and vulnerabilities. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk)