Cybersecurity Architect (SC cleared)

City of London
2 weeks ago
Create job alert

Cybersecurity Architect

6 months

London - hybrid

Active SC clearance required

Inside ir35

We are seeking a Cybersecurity Architect to join our Data and Application Security team. Our Data Security services cover a wide range of areas, including Data Loss Prevention (DLP), Cloud Access Security Brokers (CASB), Data Access Governance (DAG), data-at-rest encryption, PKI (Public Key Infrastructure) key management, and Q-Safe services. On the Application Security side, we provide comprehensive coverage across white-box and Gray-box testing, as well as consulting services for DevSecOps engineering.

Key areas of expertise include:

DevSecOps: Strong focus on integrating security into the software development lifecycle, automating security practices into CI/CD pipelines, and ensuring seamless collaboration between security and development teams. Experience with automated SCA (Software Composition Analysis), SAST (Static Application Security Testing), and DAST (Dynamic Application Security Testing) to identify vulnerabilities early and throughout development.
Application Security: Proficiency in application security testing, including white-box and gray-box testing methodologies. Strong experience in DevSecOps engineering, securing cloud-native and on-premises applications, and managing runtime protection.
Infrastructure as Code (IaC) Security: Expertise in securing IaC (Infrastructure as Code) configurations, ensuring secure provisioning, configuration management, and continuous monitoring of infrastructure.
Cloud-Native Application Protection Platform (CNAPP): Securing cloud-native applications, microservices, containers, and Kubernetes environments by identifying and mitigating vulnerabilities and misconfigurations across the application lifecycle.
Cloud Security Posture Management (CSPM): Utilizing CSPM tools to ensure proper configuration and compliance with security policies across cloud environments (AWS, Azure, GCP).
Workload Protection: Ensuring runtime security for applications, containers, and infrastructure, focusing on protecting workloads from vulnerabilities, threats, and attacks in both cloud and on-prem environments.
Data Security (DLP, CASB, DAG, PKI): Knowledge of Data Loss Prevention (DLP) solutions to prevent unauthorized data access or leakage, CASB for securing cloud applications, and Data Access Governance (DAG) for managing access to sensitive data. Proficiency in PKI architecture and key management, including the management of cryptographic keys, key ceremonies, and other related key management processes.
Data-at-Rest Encryption & Key Management: Expertise in implementing data-at-rest encryption strategies, ensuring the protection of stored data, and managing key management solutions for encryption keys throughout their lifecycle. Knowledge of Q-Safe for securing sensitive data and cryptographic key management.The ideal candidate will have:

Hands-on experience with DevSecOps tools and frameworks, integrating security into CI/CD pipelines and automated workflows.
Proficiency in cloud-native security tools and services (e.g., Prisma Cloud, Palo Alto, CNAPP, CSPM, IaC security).
Strong application security skills, including static and dynamic application testing, as well as real-time protection for cloud-based applications.
Master key ceremony experience, along with a deep understanding of PKI architecture, cryptographic key management, and best practices for secure key generation and lifecycle management.
Deep knowledge of data protection, encryption standards, Q-Safe, and PKI systems, ensuring compliance and governance across both application and data security

Related Jobs

View all jobs

Vehicle Security Architect

Technical Architect

Security Architect

Project Lead Engineer

Project Lead Engineer

Project Lead Systems Engineer

Get the latest insights and jobs direct. Sign up for our newsletter.

By subscribing you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Transitioning from Academia to the Cyber Security Industry: How Researchers Can Harness Their Skills to Protect Commercial Environments

Cyber security has become a mission-critical field in an era where data breaches, ransomware attacks, and sophisticated hacking techniques threaten businesses and public institutions alike. As digital transformation touches nearly every facet of modern life, the need for highly skilled individuals capable of defending systems and networks continues to grow. For PhDs and academic researchers with expertise in areas like cryptography, network security, or threat intelligence, this presents an exciting opportunity to deploy your analytical prowess in a high-impact, fast-paced commercial setting. In this guide we’ll explore how academics can successfully pivot from the research lab to the cyber security industry. Learn how to apply rigorous, theory-driven approaches to real-world challenges, from designing secure software architectures to neutralising advanced persistent threats. By embracing the industry’s urgency and end-to-end mindset, you can transform your scholarly insights into robust, market-facing security solutions that protect companies and users on a global scale.

Which Cyber Security Career Path Suits You Best?

Discover Your Ideal Role in the World of Digital Defence Cyber threats grow more complex by the day—ranging from sophisticated nation-state attacks to persistent phishing scams. In response, cybersecurity has become one of the fastest-expanding and most in-demand fields. If you’re exploring a career in cybersecurity, you might wonder which specialised role aligns best with your skills and aspirations. This quiz will help you identify your ideal cybersecurity path, from penetration testing to threat intelligence and beyond.

The Ultimate Glossary of Cyber Security Terms: Your Comprehensive Guide to Protecting the Digital World

As our daily lives become increasingly entwined with digital technologies, cybersecurity has emerged as one of the most critical and rapidly evolving fields. From safeguarding personal data on social media to protecting vital infrastructure and corporate networks, cyber threats loom in every corner of our connected world. Whether you’re just entering the workforce, looking to pivot your career, or a seasoned professional sharpening your skill set, understanding core terminology is essential to thrive in this domain. That’s why we’ve prepared this comprehensive glossary of cybersecurity terms and optimised for your career development. We’ll walk through the building blocks of cybersecurity—covering fundamental concepts, advanced techniques, and the latest trends—so you can confidently navigate this complex landscape. If you’re keen to explore or advance your career, be sure to check www.cybersecurityjobs.tech for roles spanning penetration testing, incident response, threat intelligence, and more.