Lead Security Architect

SiXworks an IBM company
Farnborough, UK
8 days ago
Apply on www.collegerecruiter.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Agile Methodology Artificial Intelligence Amazon Web Services Apache HTTP Server Microsoft Azure Cyber Security Information Technology Consulting Continuous Integration Digital Technology Information Systems Security Architecture Professional Javaserver Pages Machine Learning
+11 more
MongoDB Node.Js Software Engineering TypeScript SC Clearance Kubernetes Information Technology Apache Kafka Apache Nifi Devsecops Docker

Job description

Lead Security Architect - SiXworks, an IBM company

We are looking to recruit a Lead Security Architect to join us on fast-moving, innovative, and influential work underway in the Defence and Security Sector.

What do we look for in a Security Architect?

As a Lead Security Architect in a cutting-edge technology environment, you will have a challenging, vastly interesting, and technically diverse role.

Key Responsibilities and Tasks

  • Risk Management within a Defence and Security Sector;
  • Security/Cyber architectures proportionate to the GSC of the systems;
  • Security architectures delivered in conjunction with other IT Architects and SMEs;
  • Apply security design specifics to develop the security architecture;
  • Strategic direction of Security projects;
  • Producing evidence to meet various MOD regulations;
  • Designing options and solutions to mitigate vulnerabilities;
  • Working with various teams across the business including Software Engineering, DevSecOps Engineering, Infrastructure Engineering, Agile and Cyber Security;
  • Either holds or has recently held government security clearance already, or is suitable for and willing to go through the vetting process (suitability includes an absence of a serious criminal record, a right to work and live in the UK, and preferably a record of 5 years’ UK residency).

Experience (Essential)

  • Able to perform Risk management using industry approved methodologies (such as NIST 800-53). Identification of suitable risk management activities (technical, physical, or procedural) to treat/mitigate the identified risks;
  • Support development in a secure by design methodology;
  • Be able to work at a technical level with teams;
  • Identification / design / selection of appropriate security components to provide security enforcing functions (e.g. network, endpoints, cryptography, authentication, authorisation, data inspection etc) for a variety of infrastructures including cloud environments;
  • Legal and regulatory topics that merit consideration when conducting various activities in the field of cyber security;
  • Creation of security documentation to support the development of a system, these could include: security Aspects, Risk Assessment, Risk Management, Security Policies, Security Test Plans/Results, Evaluation documents;
  • Knowledge of JSP 604 / 453 and creation of assurance artefacts;
  • High standards in written report and design documentation.

Experience (Nice to have)

  • Knowledge and experience of Agile, DevSecOps, CI/CD principles and their application in secure environments;
  • Appreciation of the constraints and requirements imposed on development within secure, safety-critical environments;
  • Concepts and technologies that are used to engineer systems which inherently protect systems;
  • Understanding of MOD and other departmental IT in defence and security;
  • Experience of working with MOD Accreditors;
  • Knowledge of Onsite / project tech stack includes but is not limited to Azure, AWS, Docker, Kubernetes, Apache (NiFi, Kafka), NodeJS, Typescript, MongoDB, AI, Machine Learning etc.

About SiXworks

SiXworks is a leading provider of secure digital solutions, specialising in digital experimentation and focused on fail-safe-fast cutting-edge technology solutions deployed in highly secure environments. We are unified in our mission to accelerate innovation and adoption of secure, digital technology to improve the operational agility of Defence and National Security. This is an exciting time for us, we have ambitious plans for continued growth and development, and we are seeking to add brilliant, experienced, motivated, and passionate people to our team to work with us on this journey.

What can we offer in return?

SiXworks offers a unique work culture around our core principles Agility, Security, Innovation, Quality, Collaboration and Inclusivity. Together, these six principles form SiXworks’ NORTH STAR, guiding the organisation towards success. This is reflected in the raft of benefits available to all our employees.

A word on UK Security Clearance

Due to the secure nature of the position and working environment, you must have, or be eligible to obtain Security Clearance. More details relating to UK Security Clearance can be found here on the GOV.UK website.

Notice

SiXworks recognises the benefits of Reserve service to Country, Company and individual. We support Reservists and actively encourage them to apply. We are not considering submissions from agencies.

Seniority level

Mid-Senior level

Employment type

Contract

Job function

Information Technology

Industries

IT Services and IT Consulting and Defence and Space Manufacturing

Requirements

  • Able to perform Risk management using industry approved methodologies (such as NIST 800-53). Identification of suitable risk management activities (technical, physical, or procedural) to treat/mitigate the identified risks;
  • Support development in a secure by design methodology;
  • Be able to work at a technical level with teams;
  • Identification / design / selection of appropriate security components to provide security enforcing functions (e.g. network, endpoints, cryptography, authentication, authorisation, data inspection etc) for a variety of infrastructures including cloud environments;
  • Legal and regulatory topics that merit consideration when conducting various activities in the field of cyber security;
  • Creation of security documentation to support the development of a system, these could include: security Aspects, Risk Assessment, Risk Management, Security Policies, Security Test Plans/Results, Evaluation documents;
  • Knowledge of JSP 604 / 453 and creation of assurance artefacts;
  • High standards in written report and design documentation., * Knowledge and experience of Agile, DevSecOps, CI/CD principles and their application in secure environments;
  • Appreciation of the constraints and requirements imposed on development within secure, safety-critical environments;
  • Concepts and technologies that are used to engineer systems which inherently protect systems;
  • Understanding of MOD and other departmental IT in defence and security;
  • Experience of working with MOD Accreditors;
  • Knowledge of Onsite / project tech stack includes but is not limited to Azure, AWS, Docker, Kubernetes, Apache (NiFi, Kafka), NodeJS, Typescript, MongoDB, AI, Machine Learning etc.

About the company

SiXworks is a leading provider of secure digital solutions, specialising in digital experimentation and focused on fail-safe-fast cutting-edge technology solutions deployed in highly secure environments. We are unified in our mission to accelerate innovation and adoption of secure, digital technology to improve the operational agility of Defence and National Security. This is an exciting time for us, we have ambitious plans for continued growth and development, and we are seeking to add brilliant, experienced, motivated, and passionate people to our team to work with us on this journey.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.collegerecruiter.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

45 sec

Working securely with Node.js path application programming interfaces

Sonya Moisset · World Congress 2023

2:01 min

Migrating existing applications from MongoDB to Postgres

Nikita Shamgunov Nikita Shamgunov · World Congress 2024

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · World Congress 2026 Europe

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

Videos

See all

Related articles

See all