Lead Security Architect
- Civil Service
- Full Time
- Darlington
- 58,092 - 63,483
Job Description
Job summary
Here at the Ministry of Housing and Local Communities (MHCLG), we work on things that make a real difference to peoples lives. Whether it's through the homes we live in, the work of our local councils, or the communities were all a part of, our work is at the top of the political agenda. We have ambitious and far-reaching outcomes to achieve this year and, if youre thinking of joining us, theres never been a more exciting time. We have circa 3,500 staff who are based in 20 offices across the UK.
We are looking for a highly skilled Lead Security Architect to shape and deliver our organisations security architecture strategy. You will ensure our digital and cloud services are secure, resilient, and aligned with government standards, working across Azure and AWS environments. As a Lead Security Architect, you will: Set security architecture direction, standards and governance approach. Set direction and contribute to, as well as create, reusable cloud design patterns that embed security standards and controls, while providing expert security architecture guidance and advice. Collaborate with Enterprise Architects, Platform Architects, and Cyber Security teams. Embed secure by design principals across programmes and projects. Conduct design reviews for projects and platform teams artefacts ensuring alignment with security best practices, standards and policies.
You will enable teams to deliver secure, innovative digital services at scale, balancing risk and compliance with modern technology solutions.
Find out more about our Digital teams and what they are working on through our MHCLG Digital blog. Please note that MHCLG do not offer visa sponsorship and applicants will need a valid visa for the duration of your employment.
Job description
As a Lead Security Architect, you'll:
- Lead the design and assurance of secure system architectures, defining reusable patterns, principles, and guardrails for complex cloud and network services in collaboration with Enterprise Architects
- Act as a trusted technical advisor to product, cyber, architecture, and engineering teams, enabling the delivery of secure, scalable, cloud hosted service
- Communicate security and risk considerations effectively to both technical and nontechnical stakeholders, aligning expectations and building consensus
- Drive risk based decision making through threat modelling, structured risk assessments, and assurance of major change and transformation initiatives
- Develop, maintain, and embed architectural standards, policies, and models that align with regulatory and organisational requirements
- Ensure services adhere to NCSC and wider government SecurebyDesign principles throughout the delivery lifecycle
- Provide architectural and security guidance, mentoring, and support; foster a culture of collaboration, inclusion, and continuous improvement across engineering and architecture communities
- Contribute to the organisation's future state architecture, including cloud migration strategies and platform modernisation initiatives
- Offer line management, coaching, and thought leadership to build high performing teams and an environment that encourages innovation and professional growth
Person specification
As a Lead Security Architect, youll have:
- Demonstratable track record in designing and assuring secure architectures across premises environments and major cloud platforms (AWS and Azure)
- Strong experience producing enterprise patterns, templates, and reusable architectural designs
- Deep expertise in AWS/Azure security, governance, architecture practices, and crossplatform service design including AIrelated services
- Strong understanding of security in the SDLC (shiftleft), including GitHub, Terraform, Microsoft 365 Defender, Databricks, and Zero Trust
- In depth knowledge of security frameworks and regulatory requirements (GDPR, PCI DSS, etc.)
- Expertise in network security: segmentation, firewalls, VPNs, IDS/IPS
- Familiarity with IAM, SIEM, DLP, encryption, vulnerability management, and SOAR
- Strong understanding of application security for web, APIs, and microservices, including secure coding and threat modelling
- Demonstrated leadership within enterprise architecture; able to set standards and guide teams effectively
- Ability to deliver enterprise architectures and security roadmaps, especially for cloud transformation; strong senior level stakeholder management
- Professional security or cloud security certifications (e.g., CISSP, SABSA, AWS Security Specialty, Microsoft Cybersecurity Architect Expert)
- Experience applying SecurebyDesign and Gov Assure approaches across government or large federated organisations
- Experience in AI security, including emerging model threats, data interaction risks, and appropriate mitigation strategies