> Markdown version of [/jobs/ext/22469-security-architect](https://www.wearedevelopers.com/jobs/ext/22469-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Architect - **Company:** iO Associates - **Location:** Andover, UK - **Contract:** Contract - **Skills:** Java (Programming Language), .NET Framework, Active Directory, Active Directory Federation Services, Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Continuous Integration, Data Architecture, DevOps, Enterprise Architecture Framework, Identity and Access Management, Information Systems Security Architecture Professional, Lightweight Directory Access Protocols (LDAP), OAuth, Open Web Application Security, Openid Connect, Sherwood Applied Business Security Architecture, Security Assertion Markup Language (SAML), Secure Coding, Web Application Security, Single Sign-On, Software Engineering, Toolchain, Zachman Framework, Togaf, SC Clearance, Devsecops - **Published:** May 14, 2026 - **Apply:** https://computerjobs.com/gb/en/mob/job/F9D77C0214F4D23211 ## About the Role * Degree-level education (or equivalent experience). * Able to work independently and within multi-disciplinary delivery teams. * Strong communication skills: able to articulate and present architectural options, trade-offs, and risk-based recommendations to a range of stakeholders (including senior audiences). * Strong consulting capability and stakeholder management skills. * Customer-focused; able to build trust quickly and operate effectively in client-facing environments. * Organised, self-starting, adaptable, and able to manage changing priorities. * Collaborative team player who supports continuous learning and knowledge sharing. Technologies, methodologies & frameworks: * Relevant industry certifications (one or more), eg CISSP, SABSA, CISM, CEH, Microsoft Cybersecurity Architect Expert, AWS Certified Security - Specialty (or equivalent). * Strong practical experience in threat modelling, risk articulation, and security assurance. * Deep understanding of security concepts and their application to modern technical solutions. * Experience with secure architecture patterns, standards, and enabling technologies. * Knowledge of DevSecOps security toolchains and secure CI/CD practices. * Experience with Secure Software Development Lifecycle (SSDLC) processes and methodologies. * Strong understanding of secure handling of personal data and privacy principles (eg, GDPR). * Familiarity with solution security best practice such as OWASP and relevant national guidance for cloud security principles. Desirable skills: * Experience working in highly secure/regulated environments. * Active SC clearance. * Exposure to enterprise architecture frameworks (eg, TOGAF, Zachman). * Experience with architecture modelling tools (eg, Sparx Enterprise Architect). * Background delivering within UK public sector or defence programmes. * Cloud security architecture experience (Azure and/or AWS). * DevOps and CI/CD tooling and practices. * Identity & access technologies: SSO, SAML, OAuth2, OpenID Connect, Active Directory, ADFS, LDAP. * Secure development knowledge (Java and/or .NET) and secure web application/data architecture patterns. * Experience designing secure solutions across on-prem, hybrid, and cloud hosting models. ## Description Security Architect - Contract (OutsideIR35) Role summary: You will join an established architecture capability supporting large, complex public-sector programmes. You will design and assure secure solutions that meet business and technical needs, maintaining architectural integrity and delivering against agreed time, cost and quality outcomes. As the Security Architect, you will ensure that critical services are securely designed and delivered to a high standard. You'll apply secure-by-design best practice to minimise risk, guide delivery teams, and provide pragmatic security architecture leadership across multiple workstreams. Key responsibilities: * Collaborate with multi-disciplinary teams to ensure security and architecture are considered throughout the full delivery life cycle. * Provide security architecture leadership for moderately complex projects and programmes. * Develop and maintain security solution architectures aligned to enterprise direction and delivery constraints. * Understand the client environment, technology ecosystem, interdependencies, and relevant reference architectures. * Work with stakeholders (including assurance/accreditation functions) to identify security requirements and risks, assess impacts, and assure solution design and build. * Support scoping, remediation planning, and responses to IT Health Checks (ITHC) and third-party penetration testing. * Define, document, and communicate security reference architectures for programmes of work. * Promote secure-by-design principles, contributing to internal standards, policies, patterns, and ways of working. * Apply architectural principles during solution design to reduce risk and improve resilience. * Identify and mitigate security threats using recognised threat modelling techniques and best practice methods. * Ensure adherence to applicable corporate, industry, national, and international security standards. * Provide guidance, mentoring, and leadership to engineering and architecture teams; help define best practices. * Support pre-sales activity: contribute to bids/proposals, estimation and planning, client workshops, proofs of concept, and demonstrations. * Contribute to business development and industry propositions with architecture input. * Maintain awareness of the evolving security landscape, vulnerabilities, and their impact on proposed/operational solutions. * Develop specialist knowledge in one or more security architecture domains and share knowledge across the wider practice. Essential competencies; Personal attributes: * Degree-level education (or equivalent experience). * Able to work independently and within multi-disciplinary delivery teams. * Strong communication skills: able to articulate and present architectural options, trade-offs, and risk-based recommendations to a range of stakeholders (including senior audiences). * Strong consulting capability and stakeholder management skills. * Customer-focused; able to build trust quickly and operate effectively in client-facing environments. * Organised, self-starting, adaptable, and able to manage changing priorities. * Collaborative team player who supports continuous learning and knowledge sharing. Technologies, methodologies & frameworks: * Relevant industry certifications (one or more), eg CISSP, SABSA, CISM, CEH, Microsoft Cybersecurity Architect Expert, AWS Certified Security - Specialty (or equivalent). * Strong practical experience in threat modelling, risk articulation, and security assurance. * Deep understanding of security concepts and their application to modern technical solutions. * Experience with secure architecture patterns, standards, and enabling technologies. * Knowledge of DevSecOps security toolchains and secure CI/CD practices. * Experience with Secure Software Development Lifecycle (SSDLC) processes and methodologies. * Strong understanding of secure handling of personal data and privacy principles (eg, GDPR). * Familiarity with solution security best practice such as OWASP and relevant national guidance for cloud security principles. Desirable skills: * Experience working in highly secure/regulated environments. * Active SC clearance. * Exposure to enterprise architecture frameworks (eg, TOGAF, Zachman). * Experience with architecture modelling tools (eg, Sparx Enterprise Architect). * Background delivering within UK public sector or defence programmes. * Cloud security architecture experience (Azure and/or AWS). * DevOps and CI/CD tooling and practices. * Identity & access technologies: SSO, SAML, OAuth2, OpenID Connect, Active Directory, ADFS, LDAP. * Secure development knowledge (Java and/or .NET) and secure web application/data architecture patterns. * Experience designing secure solutions across on-prem, hybrid, and cloud hosting models. If interested, please send me your contact information and most recent CV! ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)