Security Solution Architect

Morson Group
London, UK
14 days ago
Apply on www.totaljobs.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Artificial Intelligence Amazon Web Services Microsoft Azure Cloud Computing Cyber Security High-Level Architecture Identity and Access Management Information Systems Security Architecture Professional Zero Trust Network Access Sherwood Applied Business Security Architecture Software Engineering Google Cloud
+5 more
Multi-Cloud Togaf Infrastructure Automation Frameworks ISO/IEC 27002 Devsecops

Job description

The Senior Security Solutions Architect is a tactical, results-driven role responsible for addressing specific business challenges by designing, implementing, and maintaining robust security solutions across the technology ecosystem. You will serve as a critical bridge, interpreting the strategic directives of Enterprise Architecture to create project-specific architectures that are secure by design. Your work will ensure that solutions are delivered within budget and on time while remaining functionally suitable and resilient against evolving threats.

Core Responsibilities

  • Architectural Design & Solutioning: Lead the development of High-Level Designs (HLDs) and Low-Level Designs (LLDs), ensuring all technical solutions align with security principles such as Zero Trust and ā€œdefence in depthā€.

  • Security Risk Management: Lead comprehensive security risk assessments for critical systems, developing mitigation strategies that balance security requirements with operational needs and business agility.

  • Cloud & Infrastructure Security: Design and validate secure architectures for multi-cloud and hybrid environments (AWS, Azure, GCP), focusing on platform protection, network resilience, and digital sovereignty.

  • Threat Modelling & Analysis: Establish and implement a tactical threat modelling methodology (e.g., STRIDE, PASTA) to identify design flaws early in the development lifecycle, ensuring security is ā€œbuilt-inā€ rather than ā€œbolted onā€.

  • Identity & Access Management (IAM): Establish robust IAM and Identity Relationship Management (IRM) policies, ensuring least privilege principles are enforced across both human and non-person entities.

  • DevSecOps Integration: Collaborate with software development teams to ā€œshift left,ā€ integrating security automated checks and ā€œpolicy as codeā€ directly into CI/CD pipelines.

  • Technical Governance & Compliance: Act as a Technical Design Authority (TDA), reviewing artifacts for accuracy and maintaining the programme’s technical standards against frameworks like NIST SP 800-207 and ISO 27001.

Future-Focused Technical Scope

  • AI Governance: Guide the responsible implementation of AI and Machine Learning, ensuring models are transparent, ethically anchored, and secure against AI-driven attacks.

  • Post-Quantum Cryptography (PQC): Validate cryptographic inventories and drive crypto-agility to prepare the organisation for the transition to quantum-safe encryption.

Requirements

  • Years of Experience: 7+ years in IT security, with at least 3 years specifically in security architecture.

  • Technical Expertise: Deep understanding of system design, software engineering, and infrastructure automation.

  • Framework Proficiency: Hands-on experience with SABSA, TOGAF, and the ISO 27002 framework.

Behavioural Competencies

  • Strategic Thinking: Ability to develop long-term solutions that anticipate future challenges while remaining flexible.

  • Communication & Influence: Exceptional skills in translating complex security concepts for non-technical stakeholders and influencing teams without direct authority.

  • Analytical Problem Solving: Proficiency in troubleshooting and technical analysis to resolve cross-stream architectural conflicts.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.totaljobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira Ā· Coffee With Developers

1:22 min

Overcoming developer challenges in multi-cloud environments

Sandeep Pal Sandeep Pal Ā· Coffee With Developers

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil Ā· LIVE

1:24 min

Evaluating formal AWS certifications versus raw practical engineering experience

Jan Giacomelli Ā· LIVE

1:20 min

Introduction to multi-cloud development infrastructure

Sandeep Pal Sandeep Pal Ā· Coffee With Developers

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia Ā· LIVE

Videos

See all

Related articles

See all