Security Architect - Product and Application Security

Harrington Starr
Greater London, UK
1 day ago
Apply on www.collegerecruiter.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Amazon Web Services Microsoft Azure Cloud Computing Cloud Computing Security Encodings Cyber Security Continuous Integration DevOps Distributed Systems Identity and Access Management Information Systems Security Architecture Professional Systems Development Life Cycle
+9 more
Software Engineering Software Vulnerability Management Spring Cloud Software Security Cloudformation Kubernetes Terraform Devsecops Microservices

Job description

Security Architect - Secure by Design Cloud, Application & Product Security

Location: London (Hybrid)

We’re partnering with a leading global financial organisation to recruit a Security Architect to join a high-performing Secure by Design team.

This is an opportunity to influence how security is embedded across modern technology platforms from the earliest stages of design through to production. Rather than acting as a traditional governance function, you’ll work alongside engineering, architecture and product teams to ensure security enables innovation while supporting resilience, performance and regulatory expectations.

The environment is highly technical, supporting cloud-native applications, distributed systems and mission-critical platforms where availability, scalability and speed are essential.

The Role

As a Security Architect, you’ll act as a trusted advisor to engineering and technology teams, providing practical security guidance throughout the software delivery lifecycle. You’ll review solution designs, assess security risks and help shape architectures that are secure, scalable and fit for purpose.

You’ll be involved in some of the organisation’s most complex technology initiatives, partnering with architects, developers and technical leaders to influence key design decisions while balancing security, operational requirements and delivery objectives.

Key responsibilities include:

  • Embedding Secure by Design principles across cloud and application development initiatives.
  • Conducting security architecture and design reviews for new platforms and services.
  • Performing risk-based security assessments and recommending pragmatic mitigation strategies.
  • Advising on secure architecture for cloud-native, containerised and distributed environments.
  • Working closely with engineering teams to integrate security into the Software Development Lifecycle (SDLC).
  • Supporting Product Security initiatives across customer-facing and internal platforms.
  • Developing reusable security patterns, reference architectures and technical standards.
  • Collaborating with DevOps teams to improve security automation within CI/CD pipelines.
  • Helping engineering teams adopt secure engineering practices without impacting delivery velocity.

What We’re Looking For

You’ll bring experience in several of the following areas:

  • Security Architecture and Secure by Design
  • Cloud Security (AWS, Azure and/or GCP)
  • Application Security and Product Security
  • Secure Software Development Lifecycle (SSDLC)
  • Threat Modelling and Security Design Reviews
  • DevSecOps and CI/CD Security
  • Kubernetes, Containers and Microservices Security
  • Infrastructure as Code (Terraform, CloudFormation or similar)
  • Vulnerability Management and Secure Engineering
  • Identity and Access Management
  • Risk Assessment and Security Consultancy

You’ll be comfortable engaging with both technical and business stakeholders, translating complex security concepts into practical guidance and helping teams make informed, risk-based decisions.

Exposure to regulated environments, enterprise-scale technology platforms or financial services would be advantageous, although candidates from other complex engineering environments are also encouraged to apply.

Why Apply?

This is an opportunity to join a collaborative engineering-focused security team where you’ll have genuine influence over the design of modern cloud platforms and digital products. You’ll work with experienced architects and engineering teams on large-scale technology programmes, helping shape security strategy while remaining close to technology and delivery.

If you’re passionate about Secure by Design, cloud security and enabling engineering teams to build secure, resilient applications at scale, we’d love to hear from you.

Requirements

You’ll bring experience in several of the following areas:

  • Security Architecture and Secure by Design
  • Cloud Security (AWS, Azure and/or GCP)
  • Application Security and Product Security
  • Secure Software Development Lifecycle (SSDLC)
  • Threat Modelling and Security Design Reviews
  • DevSecOps and CI/CD Security
  • Kubernetes, Containers and Microservices Security
  • Infrastructure as Code (Terraform, CloudFormation or similar)
  • Vulnerability Management and Secure Engineering
  • Identity and Access Management
  • Risk Assessment and Security Consultancy

You’ll be comfortable engaging with both technical and business stakeholders, translating complex security concepts into practical guidance and helping teams make informed, risk-based decisions.

Exposure to regulated environments, enterprise-scale technology platforms or financial services would be advantageous, although candidates from other complex engineering environments are also encouraged to apply.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.collegerecruiter.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

3:17 min

Optimizing character encoding with Kim variable byte encoding

Douglas Crockford Douglas Crockford · World Congress 2024

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

Videos

See all

Related articles

See all