Engineer the Quantum RevolutionYour expertise can help us shape the future of quantum computing at Oxford Ionics.

View Open Roles

Principal Security Architect

Tesco UK
London
4 days ago
Create job alert

We are seeking a highly skilled and experienced Principal Security Architect, who will be responsible for ensuring that all enterprise platforms and solutions align with our existing security framework and industry standards. This role requires a deep understanding of security principles, technologies, and best practices to protect our information assets and ensure compliance with regulatory requirements. The focus will be on collaborating with key stakeholders across various domains to enable our technology colleagues to work efficiently and manage their environments effectively. You will perform comprehensive risk assessments, develop strategies to mitigate threats, and ensure alignment with organisational security principles and best practices.

  • Design and implement robust security architectures for enterprise-wide capabilities, which our technology teams rely on regularly to operate their services and perform their day-to-day tasks efficiently, addressing identified threats and vulnerabilities.
  • Conduct thorough risk assessments for new systems and existing environments, reviewing their designs and architectures to ensure they meet modern security requirements, identifying security risks, and recommending mitigation strategies.
  • Influence and guide other teams to implement security solutions by collaborating across functions to integrate security principles and ensure systems align with business needs.
  • Ensure all enterprise platforms align with our existing security framework and industry standards, while collaborating with other enabling and architecture teams to integrate security into all aspects of the organisation's operations.
  • Evaluate and enhance security processes to improve their efficiency and comprehensiveness.
  • Continuously monitor and respond to emerging security trends and threats to workplace environments, virtualisation technologies, and databases.
  • Develop and maintain security architecture documentation, including policies, diagrams, and procedural guides.
  • Act as an SME and advise on the security of the cloud, workplace, and infrastructure control plane capabilities such as virtualisation layers.
  • Lead and participate in internal technology initiatives to implement secure enterprise systems, ensuring alignment with security frameworks and organisational goals to enhance security posture.



Soft Skills:

  • Proven leadership experience as a technical individual contributor in complex organisations.
  • Analytical mindset with a proactive approach to identifying and solving security challenges.
  • Strong communication and interpersonal skills to articulate complex security concepts to diverse audiences.
  • Ability to work collaboratively with cross functional teams while managing multipleinitiatives.
  • Demonstrated curiosity and flexibility in applying knowledge and advice.

Technical Skills:

  • Demonstrable experience and expertise in designing, implementing, and applyingbalanced controls from security frameworks such as NIST, CIS, ISO 27001, and MITRE.
  • Expertise in security controls and best practices for cloud-based workplace environments.
  • Proficiency in Microsoft cloud security, compliance capabilities, identity and accessmanagement, and threat protection, including Microsoft Defender, Microsoft Entra, andMicrosoft Purview.
  • Expertise with on-prem virtualisation and container platforms.
  • Familiarity with virtualisation security best practices and endpoint security.
  • Proficiency in securing databases (e.g., SQL, NoSQL).
  • Proficiency in risk analysis, security controls management planning, and disaster recoveryplanning.
  • Experience with security technologies such as firewalls, intrusion detection/preventionsystems, and encryption.

Qualifications & Experience:

  • Strong knowledge of security frameworks and standards (e.g., NIST, ISO 27001).
  • Bachelor's degree in Computer Science, Information Technology, or equivalent experience.
  • Minimum of 5 years in a security architecture role.
  • Professional certifications such as SABSA, CISSP, CISM, or TOGAF are highly desirable.



Our vision at Tesco is to become every customer's favourite way to shop, whether they are at home or out on the move. Our core purpose is ‘Serving our customers, communities and planet a little better every day’. Serving means more than a transactional relationship with our customers. It means acting as a responsible and sustainable business for all stakeholders, for the communities we are part of and for the planet.
We are proud to have an inclusive culture at Tesco where everyone truly feels able to be themselves. At Tesco, we not only celebrate diversity, but recognise the value and opportunity it brings. We're committed to creating a workplace where differences are valued, and make sure that all colleagues are given the same opportunities. We’re proud to have been accredited Disability Confident Leader and we’re committed to providing a fully inclusive and accessible recruitment process. For further information on the accessibility support we can offer, please click here.
We’re a big business and we can offer a range of diverse full-time & part-time working patterns across our many business areas, which means that we can find something that works for you. We work in a more blended pattern - combining office and remote working. Our offices will continue to be where we connect, collaborate and innovate. If you are applying internally, please speak to the Hiring Manager about how this can work for you - Everyone is welcome at Tesco.


#J-18808-Ljbffr

Related Jobs

View all jobs

Principal Security Architect

Principal Security Architect | Glasgow, UK

Principal Security Architect

Principal Security Engineer

Principal Security Engineer

Principal Security Analyst – UK

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Pre-Employment Checks for Cyber Security Jobs: DBS, References & Right-to-Work and more Explained

The cyber security sector in the UK stands at the forefront of protecting national infrastructure, business operations, and personal data from increasingly sophisticated cyber threats. As organisations across all sectors recognise cyber security as a critical business function, employers are implementing the most rigorous pre-employment screening processes in the technology industry to ensure they recruit professionals capable of defending against advanced persistent threats and maintaining the highest standards of security and trustworthiness. Whether you're a penetration tester, security analyst, incident response specialist, or chief information security officer, understanding the comprehensive vetting requirements is essential for successfully advancing your career in this security-critical field. This detailed guide explores the extensive background checks and screening processes you'll encounter when applying for cyber security positions in the UK, from fundamental eligibility verification to the most stringent security clearance requirements and specialised threat intelligence assessments.

Why Now Is the Perfect Time to Launch Your Career in Cyber Security: The UK's Digital Defence Revolution

The United Kingdom faces an unprecedented cyber security challenge that presents an extraordinary career opportunity. With cyber attacks increasing by 300% year-on-year and the average cost of a data breach reaching £4.24 million, Britain urgently needs skilled cyber security professionals to defend its digital infrastructure, protect citizens' data, and maintain national security in an increasingly connected world. If you've been considering a career change or seeking to future-proof your professional trajectory, cyber security represents one of the most secure, well-compensated, and socially impactful career choices available. The convergence of escalating threats, skills shortage, government investment, and regulatory requirements has created a perfect storm of opportunity that shows no signs of abating.

Automate Your Cyber Security Jobs Search: Using ChatGPT, RSS & Alerts to Save Hours Each Week

Cyber roles drop across consultancies, MSSPs, hyperscalers, banks, gov & start-ups every day—often buried in ATS portals or duplicated across boards. The fix is simple: put discovery on autopilot with keyword-rich alerts, RSS feeds & a reusable ChatGPT workflow that triages listings, ranks fit, & tailors your CV in minutes. This copy-paste playbook is built for www.cybersecurityjobs.tech readers. It’s UK-centric, practical, & designed to save you hours each week. What You’ll Have Working In 30 Minutes A role & keyword map spanning SecOps/Detection, DFIR, AppSec, Cloud Security, GRC, Red Team, Threat Intel, IAM/PAM, OT/ICS & Vulnerability Management. Shareable Boolean search strings for Google & job boards to cut noise fast. Always-on alerts & RSS feeds delivering fresh roles to your inbox/reader. A ChatGPT “Cyber Job Scout” prompt that deduplicates, scores fit & outputs tailored actions. A simple pipeline tracker so deadlines & follow-ups never slip.