> Markdown version of [/jobs/ext/2258008-security-architect](https://www.wearedevelopers.com/jobs/ext/2258008-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Architect - **Company:** Version 1 Solutions Limited - **Location:** Edinburgh, UK (Remote available) - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Payment Systems, Identity and Access Management, Key Management, Microsoft Software, Network Segmentation, Oracle (Applications), PCI Data Security Standards, Systems Development Life Cycle, Red Hat Enterprise Linux, Zero Trust Network Access, Sherwood Applied Business Security Architecture, Systems Integration, Snowflake, Outsystems, Software Security, Enterprise Integration, CIS Benchmarks, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 26, 2026 - **Apply:** https://www.collegerecruiter.com/job/2815172718-security-architect ## About the Role * You have designed and validated security architectures for enterprise-scale programmes across cloud platforms, application security, identity and access management, and system integration, and can point to successful outcomes and take clear ownership of the security design decisions that got there. * Cloud and application security: experience securing workloads on AWS and/or Azure, including network segmentation, IAM, encryption, secrets management, and security monitoring. You understand AppSec practices including secure SDLC, SAST/DAST tooling, API security, and container security in agile delivery contexts. * Experience directly working with clients and senior stakeholders to assess risk, facilitate threat modelling, and build consensus around security approaches, and you communicate clearly with both technical teams and non-technical leadership., * GOV.UK and public sector compliance: experience working within GOV.UK digital standards, GDS service assessments, NCSC guidance, and UK government security classifications (Official, Secret). Familiarity with DSP Toolkit or equivalent assurance frameworks. * Financial services security: experience designing controls for regulated financial environments, including FCA/PRA expectations, PCI-DSS, and secure integration patterns for core banking or payment systems. * Security frameworks and standards: working knowledge of NIST CSF, ISO 27001, CIS Controls, or SABSA, and holds or is working towards CISSP, CISM, CCSP, or equivalent. * GenAI security: experience assessing and mitigating risks in AI/ML solution architectures, including data exposure, prompt injection, model supply chain, and output integrity. ## Description Company Description Version 1 has celebrated 30 years in business and continues to be trusted by global brands to deliver technology and transformation solutions that drive customer success. Our deep expertise enables our customers to navigate the rapidly evolving technology landscape. We foster strong partnerships with global technology leaders including Microsoft, AWS, Oracle, Red Hat, OutSystems, Snowflake, ensuring that our customers are provided with the highest quality solutions and services. Job Description As a Security Architect, you'll partner with government, financial services, and private sector clients to design security solutions that address their most complex digital risks. You'll translate threat landscapes, compliance obligations, and business constraints into practical security architectures, working across the full engagement lifecycle, from threat modelling and security options analysis to facilitating design sessions with delivery teams and presenting recommendations to architecture review boards and senior stakeholders. Whether you'll be defining a zero-trust approach for a government department, designing security controls for a bank's cloud migration, or guiding development teams through secure-by-design decisions, you'll bring both depth and pragmatism. Your background in cloud security, application security, and public sector compliance means clients can trust your advice on what works in enterprise environments. You'll join our central architecture practice alongside experienced Technology Principals and Solution Architects. Security in delivery teams is often under-served; your role is to change that by embedding security thinking early and keeping it there. That includes guiding and upskilling delivery teams on secure-by-design practices and helping engineers and product managers build security literacy without slowing down delivery. Qualifications * You have designed and validated security architectures for enterprise-scale programmes across cloud platforms, application security, identity and access management, and system integration, and can point to successful outcomes and take clear ownership of the security design decisions that got there. * Cloud and application security: experience securing workloads on AWS and/or Azure, including network segmentation, IAM, encryption, secrets management, and security monitoring. You understand AppSec practices including secure SDLC, SAST/DAST tooling, API security, and container security in agile delivery contexts. * Experience directly working with clients and senior stakeholders to assess risk, facilitate threat modelling, and build consensus around security approaches, and you communicate clearly with both technical teams and non-technical leadership. Highly Desirable * GOV.UK and public sector compliance: experience working within GOV.UK digital standards, GDS service assessments, NCSC guidance, and UK government security classifications (Official, Secret). Familiarity with DSP Toolkit or equivalent assurance frameworks. * Financial services security: experience designing controls for regulated financial environments, including FCA/PRA expectations, PCI-DSS, and secure integration patterns for core banking or payment systems. * Security frameworks and standards: working knowledge of NIST CSF, ISO 27001, CIS Controls, or SABSA, and holds or is working towards CISSP, CISM, CCSP, or equivalent. * GenAI security: experience assessing and mitigating risks in AI/ML solution architectures, including data exposure, prompt injection, model supply chain, and output integrity. Benefits * Share in our success with a Quarterly Performance-Related Profit Share Scheme. * Strong career progression and mentorship coaching through our Strength in Balance and Leadership schemes with a dedicated quarterly Pathways Career Development programme. * Flexible and remote working. * Financial wellbeing initiatives: pension, private healthcare cover, life assurance, financial advice and employee discount scheme. * Employee wellbeing schemes: gym discounts, bike-to-work, fitness classes, mindfulness workshops, employee assistance programme and generous holiday allowance, enhanced maternity and paternity leave, marriage/civil partnership leave and special leave policies. * Educational assistance and incentivised certifications and accreditations including AWS, Microsoft, Oracle, and Red Hat. * Reward schemes including Annual Excellence Awards and a Call-Out platform. * Environment, social and community initiatives allowing involvement in local fundraising and development opportunities as part of diversity, inclusion and belonging initiatives. Equal Opportunity Version 1 is an equal opportunities employer. We are committed to building a diverse, inclusive and respectful workplace where everyone feels valued and able to thrive. We welcome applications from people of all backgrounds, identities and lived experiences, and we value the different perspectives people bring. Accessibility If you need reasonable adjustments at any stage of the recruitment process, please contact . We will consider all requests carefully, respectfully and confidentially. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) - [Hacking AI at the Edge of the Indian Ocean](https://www.wearedevelopers.com/videos/100177-hacking-ai-at-the-edge-of-the-indian-ocean) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)