Enterprise Security Architect (Financial Services)

Jobleads
London
2 weeks ago
Applications closed

Related Jobs

View all jobs

Enterprise Security Architect (Financial Services)

Enterprise Security Architect (Financial Services) (Basé à London)

Enterprise Security Architect (Basé à Manchester)

Enterprise Security Architect (Basé à London)

Enterprise Security Architect / Central Scotland or UK Based

▷ (19/04/2025) Enterprise Security Architect, Public SectorAccounts

Enterprise Security Architect (Financial Services)

My client, a Financial Services firm, based in London, is looking for an Enterprise Security Architect, to join their growing team. You would have to work two days per week in London.

Job purpose:

My client is seeking a highly skilled and strategic Enterprise Security Architect reporting to the Enterprise Security Architecture Manager, to lead the design, implementation, and continuous improvement of Security Architecture across the enterprise. In this role, you will collaborate with senior leadership, key stakeholders, and cross-functional teams to define and align security strategies with business objectives, ensuring security alignment to business objectives, evolving threat landscapes, and industry standards across the enterprise to mitigate risks and address emerging threats.

The Enterprise Security Architect will play a pivotal role in developing and enforcing the enterprise security architecture strategy and roadmap, developing patterns and conducting capability gap assessments whilst maintaining integration into the company's business and technology landscape. You will be responsible for maturing the security architecture practice, defining principles and input into policies and standards that span multiple business domains and technical environments, including cloud, infrastructure, and applications.

This position requires deep expertise in security architecture, a strong understanding of risk management, and the ability to influence and guide key decisions at the enterprise level.

Key responsibilities include:

  • Lead the development and execution of the enterprise security architecture strategy and roadmaps, working closely with senior leadership, Enterprise Architecture, and technical teams to align security initiatives with broader business goals.
  • Drive the integration of security across the enterprise.
  • Champion security across multiple divisions, ensuring security is embedded into the design and implementation of products, services, and technology solutions.
  • Provide thought leadership and guidance on security risks, policies, and controls to senior management and stakeholders, influencing key business decisions.
  • Collaborate with internal and external stakeholders to ensure the security architecture supports business objectives, ensuring scalability, compliance, and future state.
  • Develop and enforce security architecture frameworks, policies, and standards to guide the secure implementation of IT solutions across the enterprise, with particular emphasis on Cloud Security, SaaS, and IaaS models, ensuring alignment with industry best practices and evolving regulatory requirements.
  • Familiarity with SABSA framework and its six layers, particularly in risk management and security strategy development.
  • Lead efforts to assess and mature security practices across the enterprise.
  • Stay abreast of industry trends, frameworks, and regulations (e.g., GDPR, ISO 27001/2, SANS Top 20 Critical Security Controls, NIST CSF, SP 800-53, PFMI, CPMI ISOCO and FFIEC handbook, SABSA) to ensure the organization is proactive in addressing emerging security threats and compliance challenges.
  • Foster relationships with key functional teams such as IT, Compliance, Operations, Finance, HR, Internal Audit, and Enterprise Risk to support current and future initiatives.
  • Keep informed of new and emerging security threats & assess effectiveness of current controls to identify opportunities for program improvement.
  • Provide expert-level security architecture design, analysis, and consultation to enterprise-wide programs, ensuring security risks are appropriately mitigated during the planning and design stages.
  • Work closely with technology teams, including Infrastructure, Cloud, Development, and Security, to embed security into solutions from the outset.
  • Oversee and guide assessments of new technologies, vendors, and third-party services to ensure compliance with enterprise security standards and reduce potential risk exposure.
  • Lead and guide project and program managers to ensure the integration of security architecture across various initiatives, with a focus on scalability, compliance, and risk management.
  • Define, monitor, and enforce security architecture governance processes to ensure that security standards and controls are met across the enterprise.

Knowledge, skills and abilities:

  • 8+ years of experience in information security, with a strong background in security architecture across large, complex enterprise environments.
  • Proven ability to design, implement, and lead security initiatives across cloud, network, application, and infrastructure domains.
  • Extensive experience working with senior leadership and stakeholders to drive strategic security initiatives, influencing decisions at the enterprise level.
  • Strong understanding of security frameworks, including NIST CSF, SABSA etc, and the ability to apply them in diverse environments.

Qualifications and certifications:

  • Degree in a technology discipline (Computer Science, Information Management, Computer Engineering, Cybersecurity or equivalent).
  • Professional certifications such as CISSP, CISA, CISM, CRISC, SABSA, or equivalent.
  • Deep expertise in risk management frameworks, including ISO 27001, NIST SP 800-53, and SANS Top 20 Critical Security Controls.
  • Experience with cloud security solutions and services.

If this role is of interest please apply to this job advertisement or call me on .

About the job

Contract Type: FULL_TIME

Focus: Information Security

Workplace Type: Hybrid

Experience Level: Director

Location: London

Salary: £140,000 - £160,000 per annum

Job Reference: USK5DA-11D77E58

Date posted: 4 April 2025

Consultant: Darius Goodarzi

#J-18808-Ljbffr

Get the latest insights and jobs direct. Sign up for our newsletter.

By subscribing you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Contract vs Permanent Cybersecurity Jobs: Which Pays Better in 2025?

Cybersecurity has become one of the fastest-growing and most crucial fields in modern business. With high-profile breaches dominating headlines and the ongoing digital transformation exposing organisations to new threats, companies across the UK are competing to attract skilled cybersecurity professionals. Roles range from penetration testers (pen testers) and SOC (Security Operations Centre) analysts to compliance officers, cloud security architects, threat intelligence analysts, and CISOs (Chief Information Security Officers). As demand continues to surge, cybersecurity salaries have climbed accordingly, and businesses have turned to more flexible hiring practices. Alongside permanent employment, many professionals explore short-term day‑rate contracting or fixed-term contracts (FTCs), searching for the ideal balance of pay, job security, and growth opportunities. Which arrangement truly pays better in 2025—and which best aligns with your ambitions? In this article, we dive into the contract vs. permanent debate with a focus on cybersecurity roles. We will examine the current market, the structure of day‑rate vs. FTC vs. permanent positions, the pros and cons of each, and some hypothetical pay comparisons. By the end, you should have a clearer sense of which career path might suit your situation and goals—whether you are a seasoned specialist aiming for top rates, or an up-and-coming analyst seeking a stable environment to develop in.

Cyber Security Jobs for Non‑Technical Professionals: Where Do You Fit In?

Defence Needs More Than Hackers in Hoodies When headlines warn of ransomware crippling hospitals or deepfakes swaying elections, we picture hoodie‑clad hackers and elite penetration testers. Yet the reality of the UK’s cyber security sector is broader—and desperately short of talent. The Department for Science, Innovation & Technology (DSIT) estimates a shortfall of 11,200 cyber security professionals in 2024, while 43 % of advertised roles require governance, risk or communication skills rather than hands‑on technical exploits. Put plainly: if you can guide policy, manage projects, interpret regulations or inspire behaviour change, cyber security wants you. This guide highlights the fastest‑growing non‑technical roles, the transferable skills you already possess, and a concrete 90‑day plan to land a cyber security job—no packet sniffers required.

BAE Systems Cybersecurity Jobs in 2025: Your Complete UK Guide to Protecting Governments, Businesses and Critical Infrastructure

From securing the Royal Navy’s new Dreadnought submarines to foiling multimillion‑pound fraud rings, BAE Systems Digital Intelligence (DI)—formerly Detica—sits at the sharp end of global cyber defence. Head‑quartered in Guildford with hubs in Gloucester, Leeds and London, the 5,500‑strong DI business delivers threat‑intelligence platforms, secure‑by‑design software and 24/7 SOC services to government and commercial clients worldwide. With escalating ransomware, AI‑driven disinformation and complex supply‑chain threats, BAE plans to expand its UK cyber workforce by 20 % in 2025. Whether you’re a graduate passionate about reverse engineering, a DevSecOps engineer who loves IaC, or an incident‑response pro comfortable in high‑side environments, this guide explains how to land a BAE Systems cybersecurity job in 2025.