> Markdown version of [/jobs/ext/89307-cyber-security-architect](https://www.wearedevelopers.com/jobs/ext/89307-cyber-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Architect - **Company:** DevNull Security - **Location:** Sheffield, UK - **Experience:** Expert - **Salary:** £65,000.0 - £75,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Systems Engineering, Microsoft Azure, Cloud Computing Security, Cloud Engineering, Cyber Security, Software Design Patterns, Systems Development Life Cycle, Sherwood Applied Business Security Architecture, Software Engineering, Data Streaming, Systems Integration, Software Vulnerability Management, Togaf, Purple Team (Cyber Security), Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** May 30, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=95c052414960db03 ## About the Role Do you have a Bachelor's degree?, * Demonstrable experience designing and architecting cybersecurity assessment capabilities in a large enterprise environment, covering at minimum two of the three domains: Exposure Management, Offensive Security, or Code Assessment. * Experience implementing and supporting vulnerability management capabilities at enterprise scale, including vulnerability scanning, centralised reporting, and configuration baseline assessment. * Experience designing and integrating application security testing tools (SAST, DAST, IAST, RASP, SCA) within SDLC processes, including CI/CD pipelines. * Experience architecting offensive security programmes, including scoping, methodology definition, toolchain selection, and integration with remediation workflows. * Experience with External Attack Surface Management (EASM) and continuous exposure monitoring - understanding how to translate asset discovery and exposure data into prioritised risk. * Ability to translate complex technical findings into business risk terms, with experience presenting to senior technical and non-technical stakeholders. * Experience creating architecture strategies, roadmaps, and design patterns and presenting them to diverse audiences. * Experience performing threat modelling and risk assessments to support new technology adoption or design pattern development. * Strong understanding of cloud security across at least one major platform (AWS, Azure, or GCP), including how cybersecurity assessment capabilities apply in cloud-native and hybrid environments. * At least eight years of relevant technical experience, including experience working in a large corporate or regulated environment. * University degree in a technical discipline, or equivalent experience. Relevant industry certifications (OSCP, CREST, CEH, CISSP, or equivalent). Desirable Requirements * Familiarity with standard IT engineering and architecture frameworks (TOGAF, SABSA, or equivalent). * Experience with Purple Team operations and the integration of offensive testing findings into defensive capability improvement. * Familiarity with risk quantification frameworks (CVSS, EPSS, or proprietary models) and how they support prioritisation at scale. * Experience working in a federated global organisation with distributed technology teams. * Ability to work efficiently under pressure with tight timelines across globally distributed teams., The success of cybersecurity assessment architecture will be measured not only by what is delivered, but by how effectively those capabilities are adopted, integrated, and used to reduce real risk across the organisation. The ideal candidate is technically credible, comfortable working across organisational boundaries, and able to operate effectively in a federated environment where influence matters as much as authority., * A collaborative, team-oriented approach with a genuine willingness to share knowledge and develop others. * Openness to constructive challenge and the ability to give clear, direct feedback in return. * A self-starting attitude with the drive to move work forward without waiting for direction. * Intellectual curiosity and a commitment to staying current across a fast-moving threat and tooling landscape. ## Description The Cyber Security Architect is responsible for defining, governing, and continuously improving the architecture of the organisation's cybersecurity assessment capabilities. This means owning the strategic direction of tooling, processes, and integration patterns and ensuring those capabilities translate into meaningful, actionable risk intelligence for the business. The role is architectural and advisory in nature. The successful candidate sets direction, defines standards, and provides expert guidance on tools and services; they do not deliver hands-on assessment or testing activity themselves. The emphasis is on enterprise-scale thinking, stakeholder engagement, and the ability to translate capability requirements into coherent, implementable architecture., * Define and maintain the security architecture for cybersecurity assessment capabilities, including tool selection, integration patterns, data flows, and coverage models across Exposure Management, Offensive Security, and Code Assessment. * Lead the design and implementation of Exposure Management capabilities, including External Attack Surface Management (EASM), continuous vulnerability scanning, configuration baseline assessment, and risk-based prioritisation frameworks. * Design and embed Code Assessment capabilities within existing Software Development Lifecycle (SDLC) processes, covering Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Interactive Application Security Testing (IAST), Runtime Application Self-Protection (RASP), and Software Composition Analysis (SCA). * Translate technical vulnerabilities and assessment findings into material business risk, with clear communication suitable for technical and non-technical audiences, including senior leadership. * Develop and maintain architecture strategies, roadmaps, and design patterns for cybersecurity assessment capabilities, ensuring alignment with the broader enterprise security architecture. * Work with solution architects and engineering teams across business units and functions to apply secure-by-design practices and embed cybersecurity assessment tooling within delivery pipelines. * Conduct threat modelling and complex risk assessments to support new technologies, platforms, and design patterns across the organisation. * Review and recommend enhancements to security standards, controls, and policies related to assessment and testing. * Provide security subject matter expertise to transformation programmes across business units and functions, ensuring security risk is correctly identified and factored into design decisions from the outset. * Support the education and development of solution architects and engineering teams to improve their awareness and application of security testing practices. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Python-Based Data Streaming Pipelines Within Minutes](https://www.wearedevelopers.com/videos/1233-python-based-data-streaming-pipelines-within-minutes) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Why and when should we consider Stream Processing frameworks in our solutions](https://www.wearedevelopers.com/videos/1085-why-and-when-should-we-consider-stream-processing-frameworks-in-our-solutions) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers)