Security Architect

Manchester
1 month ago
Applications closed

Related Jobs

View all jobs

Security Architect

Security Architect

Security Architect

Security Architect

Security Architect

security architecture & engineering director

We’re looking for a Security Architect responsible for creating, maintaining, and enforcing the frameworks, processes, and technical designs that safeguard N Brown’s data, systems, and overall digital ecosystem. 

You’ll serve as the primary bridge between business priorities and needs, ensuring that all technology initiatives are aligned with robust principles. You’ll join the Architecture Chapter (Governance and Transformation) whilst being embedded within the Information Security Chapter (engineering and operations) and the GRC Team (governance, risk, and compliance). This unique placement enables the role to integrate security as a core element in business transformations, system operations, and governance activities, providing a 360-degree approach to enterprise security. 

What will you be doing? 

Information Security Architecture

Develop enterprise-wide data strategies to ensure the confidentiality, integrity, and availability of information assets.
Establish and maintain standards, policies, and guidelines that align with regulatory frameworks, business objectives, and industry best practices.
Work closely with the Data Governance team to integrate controls for sensitive data across its lifecycle, including classification, storage, access, and transfer.
Drive the adoption of encryption standards and other data protection mechanisms across applications, databases, and file systems.
Cyber Security Architecture

Design and implement layered defence architectures to protect against an ever-evolving threat landscape.
Define the posture for enterprise infrastructure, including network segmentation, secure endpoints, and resilient cloud environments.
Collaborate with engineering teams to build scalable, secure applications following secure coding principles and frameworks.
Develop strategies for integrating monitoring and detection tools (e.g., SIEM, IDS/IPS) into the organisation's IT landscape to provide real-time threat visibility.
Cloud Security Architecture

Define security strategies for hybrid and multi-cloud environments, ensuring consistent protection across all platforms.
Evaluate and recommend cloud-native tools and controls, such as cloud access security brokers (CASBs), cloud firewalls, and key management systems.
Collaborate with Cloud Operations and DevOps teams to implement secure infrastructure-as-code practices and cloud deployment pipelines.
Secure Development Lifecycle (SDL)

Establish and champion the Secure Development Lifecycle across all application development teams.
Provide guidance on secure coding practices, static/dynamic application testing (SAST/DAST), and code review processes.
Work with development teams to ensure security is considered at every stage, from design through deployment.
Introduce automated tools to enhance SDL efficiency, such as vulnerability scanning in CI/CD pipelines.
What skills and experience will you have?

A good understanding of cloud security controls and tooling, ideally in AWS but GCP and Azure will also be beneficial.
Understanding of secure coding and application design principles.
Good knowledge of the ecommerce threat landscape and a pragmatic approach to applying relevant controls to mitigate those threats.
Experience of building strong governance into guard rails.
Experience of applying controls and mitigations iteratively in an agile/DevSecOps environment where all requirements will not be delivered on day one.
Practical experience of governing solutions in an architecture function.
Awareness of IT industry trends and being vendor and technology neutral to enable best-fit solutions to be found.
What’s in it for you?

Hybrid working
24 days holiday (+ 8 bank holidays) with the option to buy an additional 10 days
Annual bonus scheme
Enhanced maternity and adoption leave
Access to Apricity, a self-funding IVF benefit at a reduced rate
Company pension with up to 8% N Brown contribution
Mental Health support both internally and externally, including access to our wellbeing champions and counselling services
A range of financial wellbeing support
Colleague discount across all N Brown brands
Onsite café with subsidised rates and local restaurant discounts!
Life Assurance and Private Medical Insurance
Paid volunteer time – all our colleagues can take a full day paid to volunteer for a charity of their choice
N Brown – who we are and why work for us?
We’re an equal opportunity employer and value diversity. We do not discriminate based on race, religion, colour, national origin, sex, gender, gender expression, sexual orientation, age, marital status, veteran status, or disability status. 

In May 2024 we were delighted to be named one of The Sunday Times Best Places to Work 2024. We work hard to create a happy and inclusive culture for everyone and we’re so proud to have made this list - as voted for by our very own colleagues! 

Ways of Working
We offer hybrid working which varies across the business depending on the role you’re in. Our Head Office is located in the Northern Quarter in Manchester City Centre. So if you are travelling by train, tram or bus we’re perfectly located, plus we’re surrounded by cool cafes, trendy bars and the best places to eat! 

Our working hours are 36.17 per week and our core working hours are between 10am - 4pm. Given we don’t have strict working hours you can find the working pattern that’s right for you. 

What happens when you apply to a role at N Brown?
As soon as we receive your application, we’ll send you an email to let you know. We always aim to come back to you as soon as possible with an update and we really appreciate you taking the time to apply for a role with us. Good luck

Get the latest insights and jobs direct. Sign up for our newsletter.

By subscribing you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Navigating Cybersecurity Career Fairs Like a Pro: Preparing Your Pitch, Questions to Ask, and Follow-Up Strategies to Stand Out

In a world where digital threats are escalating and online infrastructure underpins nearly every aspect of our personal and professional lives, cybersecurity has swiftly become one of the most sought-after career fields. Demand for skilled cybersecurity professionals outstrips supply, both in the UK and globally. From ethical hackers and penetration testers to governance, risk, and compliance (GRC) specialists, the opportunities are extensive—and lucrative. Amidst this surge in demand, cybersecurity career fairs provide an invaluable chance to meet potential employers face-to-face, gain industry insights, and make connections that can accelerate your career trajectory. Unlike applying to countless jobs online, these events bring companies, security leaders, and aspiring candidates together under one roof. When approached with the right strategy, a single conversation at a cybersecurity fair can open the door to your dream job. In this comprehensive guide, we’ll explore how to prepare thoroughly, engage confidently, and follow up effectively after a cybersecurity career fair. By incorporating these insights into your approach, you’ll stand out from the crowd and maximise your chances of securing the perfect role in this fast-growing field.

Common Pitfalls Cyber Security Job Seekers Face and How to Avoid Them

The cyber security industry in the UK and worldwide is experiencing rapid growth. With cyber attacks growing in sophistication and frequency, organisations are investing more resources than ever into defending their digital assets. From penetration testers and threat analysts to security architects and compliance officers, cyber security professionals are in high demand across a variety of sectors—including finance, healthcare, government, and retail. Yet, in spite of this high demand, the process of landing a cyber security role can be more challenging than many candidates anticipate. The stakes are high: prospective employers entrust cyber professionals with their most sensitive data, their compliance posture, and often their core business operations. Therefore, they’re looking for candidates who can demonstrate not just technical know-how, but also excellent communication, adaptability, and an awareness of the broader business context. In this article, we’ll explore the most common pitfalls that cyber security job seekers face, especially in the UK market, and how to avoid them. Whether you’re a recent graduate, a professional transitioning from a different field, or an experienced practitioner aiming for a senior role, these insights will help you stand out and secure the opportunities that fit your skill set and career goals.

Career Paths in Cybersecurity: From Entry-Level Roles to Leadership and Beyond

Cybersecurity has emerged as one of the most critical and fastest-growing fields in technology today. With data breaches and ransomware attacks making headlines, organisations of all sizes and in every sector are recognising the urgent need for robust cybersecurity measures. As a result, professionals with the right mix of technical and strategic skills are in high demand—offering competitive salaries, diverse career paths, and ample opportunities for progression. How do you begin a career in cybersecurity, and how can you advance from technical roles to leadership positions? In this in-depth guide, we explore the cybersecurity career ladder, outlining roles at entry, mid, and senior levels, as well as the key skills, qualifications, and experiences you’ll need to climb it. Whether you’re an aspiring cybersecurity analyst, a seasoned penetration tester, or an IT professional looking to pivot, this article will help you understand the paths available and how to chart your course towards success in the thriving UK cybersecurity market.