> Markdown version of [/jobs/ext/3032453-principal-security-architect](https://www.wearedevelopers.com/jobs/ext/3032453-principal-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Security Architect - **Company:** Sustainrecruit - **Location:** Bridgend, UK - **Experience:** Expert - **Salary:** £100,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Data as a Services, Identity and Access Management, Intrusion Detection and Prevention, Network Security, Microsoft Security Essentials, Azure Active Directory, Zero Trust Network Access, Sherwood Applied Business Security Architecture, Security Information and Event Management, Software Engineering, Cyber Threat Analysis, HybridCloud, Togaf, Microsoft InTune, Information Technology, Microsoft Sentinel, Cloud Migration, CIS Benchmarks, Devsecops - **Published:** September 23, 2026 - **Apply:** https://www.careerjet.co.uk/job/gb59f74b20c0e76f08912d831192aa0ad3/eaa ## About the Role Security Architecture * Proven experience operating as a Lead, Principal or Enterprise Security Architect. * Strong understanding of enterprise security architecture methodologies. * Experience designing security solutions within large and complex organisations. * Deep knowledge of security frameworks and regulatory requirements. Microsoft Security Expertise * Extensive experience with: * Microsoft Sentinel * Microsoft Defender XDR * Microsoft Defender for Cloud * Microsoft Entra ID * Azure Security Services * Microsoft Purview, * SOC Operations * Threat Detection Engineering * Incident Response * Threat Intelligence * Security Monitoring Cloud & Infrastructure * Strong Azure security architecture experience. * Knowledge of hybrid cloud environments. * Experience securing: * Identity platforms * Networks * Endpoints * Applications * Data services Consulting & Stakeholder Management * Excellent client-facing and communication skills. * Ability to engage effectively at Board, Executive and Technical levels. * Strong workshop facilitation and presentation skills. * Commercial awareness and experience supporting sales engagements. Desirable Experience * Managed Security Services (MSSP) environments. * Security Operations Centre transformation programmes. * DevSecOps and secure software development practices. * OT/ICS security experience. * Public sector, financial services or regulated industry experience. * Experience working within a UK IT Services, Consulting or Systems Integrator organisation. Certifications Highly desirable certifications include: * Microsoft Certified: Cybersecurity Architect Expert (SC-100) * Microsoft Security Operations Analyst (SC-200) * CISSP * CCSP * SABSA * TOGAF * Azure Solutions Architect Expert * Certified Cloud Security Professional (CCSP) * GIAC Security Certifications ## Description We are seeking an experienced and commercially minded Principal Security Architect to join an established a rapidly growing IT Service Provider. This is a senior client-facing role responsible for leading the design, assurance and delivery of complex security solutions across enterprise and public sector customers. The successful candidate will act as a trusted advisor to C-level stakeholders, security leaders, and technical teams, helping clients develop and implement security strategies, architectures and operational capabilities that reduce risk and support business objectives. A key focus of the role will be security monitoring and detection capabilities, with demonstrable expertise in Microsoft Sentinel, SIEM/SOAR design, security operations transformation and cloud-native security architectures. Working closely with sales, delivery and technical teams, you will provide thought leadership, contribute to solution development, support pre-sales engagements and lead security architecture initiatives across a diverse customer base., Client Advisory & Leadership * Act as the lead Security Architect across assigned Managed Services clients. * Act as a trusted security advisor to client stakeholders, including CIOs, CISOs and security leadership teams. * Lead security architecture engagements from discovery through design and implementation. * Define security strategies, roadmaps, target architectures, and governance standards. * Produce and assure HLDs, LLDs, and reference architectures aligned to Zero Trust and Secure by Design principles. * Lead architecture for Microsoft Entra ID, Active Directory, Identity Governance, PIM, Conditional Access, SSO, Federation, and B2B/B2C identity. * Provide architectural ownership across the Microsoft security stack, including Defender, Sentinel, Purview, Intune, Security Copilot, Azure Security, and Microsoft 365 Security & Compliance. * Translate business requirements into secure, scalable and practical security solutions. * Present architectural recommendations and security strategies to executive audiences. * Lead security workshops, assessments and roadmap development activities. Security Architecture * Define and maintain enterprise security architectures aligned with business objectives. * Design security controls across cloud, hybrid and on-premise environments. * Develop security reference architectures, standards and patterns. * Ensure solutions align with recognised frameworks including: * NCSC Cyber Assessment Framework * NIST Cyber Security Framework * ISO 27001 * CIS Controls * Zero Trust principles Microsoft Security & Sentinel * Lead the architecture, deployment and optimisation of Microsoft Sentinel environments. * Design SIEM and SOAR solutions to enhance threat detection, incident response and operational efficiency. * Create and optimise analytics rules, detection use cases, automation playbooks and dashboards. * Drive security monitoring maturity programmes and SOC transformation initiatives. * Integrate Sentinel with Microsoft Defender technologies and third-party security platforms. * Advise clients on security operations processes, reporting and threat management. Cloud Security * Design secure cloud-native architectures across Microsoft Azure environments. * Support cloud migration and transformation programmes. * Define security controls covering: * Identity and Access Management * Privileged Access * Data Protection * Network Security * Security Monitoring * Threat Detection and Response Pre-Sales & Business Development * Support sales and account teams in developing cyber security opportunities. * Lead technical discussions during bids, tenders and client presentations. * Contribute to proposals, statements of work and solution documentation. * Assist with service innovation and development of new cyber security offerings. * Represent the organisation at client events, conferences and industry forums. Governance & Assurance * Perform architecture reviews and security assurance activities. * Assess risk and provide pragmatic remediation recommendations. * Produce high-quality architecture documentation and design artefacts. * Provide technical leadership and mentoring to architects, consultants and engineers. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [Building Security Champions](https://www.wearedevelopers.com/videos/193-building-security-champions) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems)