IT Risk Advisor, Operations & Design
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Provide technical security architecture oversight across projects and BAU operations, ensuring secure-by-design principles are embedded across cloud and on-premises environments. Influence design, change, and governance decisions, reduce risk exposure, and support engineering teams with pragmatic, business-aligned security guidance without slowing delivery.
IT Risk Advisor specialising in secure-by-design architecture to provide technical security oversight across both project delivery and BAU operations. This role sits within technology governance, ensuring robust, proportionate security controls are embedded across evolving environments.
You will work closely with architects, engineers, and operational teams to influence design decisions, review risk, and ensure security is consistently integrated without impacting delivery pace.
Security Architecture Governance:
- Define and maintain security architecture patterns, standards, and reference designs across cloud and on-premises environments
- Establish secure configuration baselines and promote consistent adoption
- Contribute to architecture governance forums (e.g. Architecture Review Board)
- Review and assess high-risk design exceptions, ensuring risks are understood and managed
- Drive adoption of secure-by-design principles across engineering teams
Project Security Advisory:
- Provide hands-on security architecture guidance to delivery teams
- Conduct threat-informed design reviews and support appropriate control selection
- Apply secure patterns, reference architectures, and hardening standards
- Enable early engagement to minimise downstream risk and rework
Operational Security Oversight (BAU):
- Participate in Change Advisory Boards, providing security review and challenge
- Review and approve high-risk firewall and configuration changes
- Assess configurations across cloud (Azure) and on-premises infrastructure
- Identify misconfigurations and exposure risks against defined baselines
- Support prioritisation and remediation of high-risk and zero-day vulnerabilities
- Provide pragmatic, operationally aligned security recommendations
- Help reduce attack surface and improve resilience across IT operations
Requirements
- Previous experience in a security architect or similar role
- Knowledge of regulatory frameworks (e.g. NIS2, Cyber Resilience Act)
- Industry certifications such as CISSP, GICSP, or equivalent
- Degree in Computer Science, Information Security, or relevant discipline
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
IT Salaries in UK
The Most Popular IT Jobs on the Market
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents