Location: Manchester/London/Birmingham - 1 day per week onsite, plus 1 day per month in Birmingham
Work Pattern: Hybrid - 1 day onsite per week
Rate: £850 per day
IR35 Status: Inside IR35
Clearance: SC Mandatory
Overview
We are seeking an experienced Security Technical Assurance Architect to support a large-scale UK public sector transformation programme delivering shared, business-critical services across multiple departments. The successful candidate will provide independent technical security assurance across solution designs, ensuring they are secure by design, proportionate to risk and compliant with NCSC guidance, departmental policy and UK GDPR/Data Protection Act 2018. Working closely with delivery teams, suppliers, commercial and information assurance colleagues, you will define and run assurance activities, identify weaknesses in proposed designs and guide remediation through to governance approval. Success in this role means security risks are understood, evidenced and managed, allowing the programme to pass its assurance gates with confidence.
Key Responsibilities
- Lead technical security assurance of solution designs, reviewing high and low level designs against security requirements, NCSC guidance and departmental security policy.
- Define and deliver assurance activities for the programme, aligning them to the wider assurance framework, risk management practices and governance gates.
- Identify vulnerabilities and weaknesses within proposed designs and recommend controls proportionate to the perceived risk.
- Conduct threat modelling (eg STRIDE) and document, quantify and track technical security risks with Security Risk and Assurance teams.
- Draft and maintain programme security requirements and non-functional requirements, translating them into deliverable work packages for delivery teams.
- Scope, plan and oversee IT health checks and penetration testing, interpret findings and work with delivery teams and suppliers to remediate vulnerabilities.
- Work with commercial and supplier assurance teams to ensure suppliers meet contractual security schedules and comply with all governance gates.
- Support the production of Data Protection Impact Assessments (DPIAs), Records of Processing Activities (ROPA) and Business Impact Assessments, working with data protection and legal stakeholders.
- Chair or contribute to security design authorities, governance boards and cross-departmental security working groups.
- Embed security within the development lifecycle and DevOps practices, working alongside Agile/Scrum teams.
- Provide clear, pragmatic security advice and guidance to technical and non-technical stakeholders at all levels.
Essential Skills
- Strong commercial experience working as a Security Architect with a clear focus on technical security assurance of complex, large-scale systems.
- In-depth knowledge of Secure by Design principles and a risk-based approach to security architecture.
- Strong working knowledge of NCSC guidance, including the Cloud Security Principles, and security frameworks such as ISO 27001, CIS Critical Security Controls, NIS and Cyber Essentials Plus.
- Hands-on experience of threat modelling (eg STRIDE) and identifying design-level vulnerabilities.
- Experience scoping penetration tests/IT health checks and interpreting reports to drive remediation.
- Solid understanding of cloud and network security architecture, including public cloud (AWS or Azure), perimeter security, secure configuration and device hardening.
- Knowledge of application, API and web security standards such as OWASP.
- Working knowledge of UK GDPR and the Data Protection Act 2018, including contributing to DPIAs and ROPA.
- Experience working with suppliers, commercial teams and governance boards to evidence and assure security compliance.
- Excellent communication and stakeholder management skills, with the ability to influence at senior level and across departmental boundaries.
- Previous experience within the UK Public Sector.
- Willingness to attend site 1 day per week (Manchester, London or Birmingham) and travel to Birmingham 1 day per month.
- SC Clearance (Mandatory).
Nice To Have
- CISSP, CISSP-ISSAP, CCSP or NCSC Certified Professional (CCP) Security Architect certification.
- Central Government experience, ideally within DWP, HMRC or on cross-government shared service programmes.
- Experience assuring ERP or large SaaS platform implementations.
- Experience drafting security schedules for commercial contracts or supporting bid evaluation.
- Experience of Data Sharing Agreements across government departments.
- DevSecOps experience and familiarity with CI/CD security tooling.
- Experience leading or mentoring security architects and engineers.