> Markdown version of [/jobs/ext/3101819-security-architect](https://www.wearedevelopers.com/jobs/ext/3101819-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Architect - **Company:** Version 1 Solutions Limited - **Location:** London, UK (Remote available) - **Salary:** £49,000.0 - £66,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cloud Computing, Payment Systems, Identity and Access Management, Information Systems Security Architecture Professional, Key Management, Network Segmentation, Oracle (Applications), PCI Data Security Standards, Systems Development Life Cycle, Zero Trust Network Access, Sherwood Applied Business Security Architecture, Systems Integration, Snowflake, Outsystems, Software Security, CIS Benchmarks, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 27, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5899590241 ## About the Role * We have designed and validated security architectures for enterprise-scale programmes across cloud platforms, application security, identity and access management, and system integration. * We have delivered successful security outcomes and taken clear ownership of the security design decisions behind them. * We have experience securing workloads on AWS and/or Azure, including network segmentation, IAM, encryption, secrets management, and security monitoring. * We understand AppSec practices including secure SDLC, SAST/DAST tooling, API security, and container security in agile delivery contexts. * We have worked directly with clients and senior stakeholders to assess risk, facilitate threat modelling, and build consensus around security approaches. * We communicate clearly with both technical teams and non-technical leadership. * Highly desirable: experience working within GOV.UK digital standards, GDS service assessments, NCSC guidance, and UK government security classifications. * Highly desirable: familiarity with DSP Toolkit or equivalent assurance frameworks. * Highly desirable: experience designing controls for regulated financial environments, including FCA/PRA expectations, PCI-DSS, and secure integration patterns for core banking or payment systems. * Highly desirable: working knowledge of NIST CSF, ISO 27001, CIS Controls, or SABSA. * Highly desirable: holding or working towards CISSP, CISM, CCSP, or equivalent. * Highly desirable: experience assessing and mitigating risks in AI/ML solution architectures, including data exposure, prompt injection, model supply chain, and output integrity. ## Description * We partner with government, financial services, and private sector clients to design security solutions for complex digital risks. * We translate threat landscapes, compliance obligations, and business constraints into practical security architectures. * We work across the full engagement lifecycle from threat modelling and security options analysis through to facilitating design sessions with delivery teams. * We present recommendations to architecture review boards and senior stakeholders. * We define security approaches such as zero-trust for government departments and security controls for cloud migrations. * We guide development teams through secure-by-design decisions. * We embed security thinking early in delivery and keep it there. * We guide and upskill delivery teams on secure-by-design practices. * We help engineers and product managers build security literacy without slowing down delivery. Technologies: * AI * API * AWS * Azure * Cloud * IAM * Support * Network * Oracle * OutSystems * Security * Snowflake * Architect * Embedded ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) - [Hacking AI at the Edge of the Indian Ocean](https://www.wearedevelopers.com/videos/100177-hacking-ai-at-the-edge-of-the-indian-ocean) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)