Managing Security Architect
Soprasteria UkRole Overview
As Managing Security Architect, you will be responsible for embedding security best practices and secure by design principles into our wide ranging client engagements. Reporting to the Security Architecture Lead within Cyber Security, you will work on a range of security activities, collaborating closely with teams and architects across the organisation to ensure security is embedded into their solutions, rather than bolted on.
You will develop security architecture blueprints and documentation, such as high level design documents, perform security gap analysis to develop roadmap activities, and review architecture design documentation. Taking a risk based approach, and using industry standard security architecture frameworks, you will design security controls to address the current and future cyber security threat landscape, whilst being aligned to our clients’ overall business objectives.
Ideally you will have experience and a clear understanding of industry best practices from NCSC and NIST, frameworks such as SABSA and have experience in Secure by Design.
Your leadership and expertise will be critical in fostering a strong culture of secure by design across Sopra Steria and you will play a leading role in helping our clients understand their security challenges, in order to design relevant security controls to improve their security posture, specific to their risk appetite.
This
is an opportunity to lead at the front line of cyber security delivering value
to our client base.
Key Responsibilities
- Lead on security activities for large client engagements, specifically in Defence, Government and high‑assurance environments
- Lead the analysis of existing and proposed solution architectures for security risk, mitigating security controls, and applying secure architecture principles and practices to improve the security posture
- Identify customer requirements and demonstrate creativity and innovation in designing solutions for the benefit of the customer
- Document the detailed implementation of security controls in high-level and low-level designs and define testing requirements
- Lead security aspects of bid responses and opportunity identification
- Build security control roadmaps that align organisational plans with regulatory and contractual requirements
- Lead security aspects of bid responses and opportunity identification
- Build security control roadmaps that align organisational plans with regulatory and contractual requirements
- Be an active participant within the Cyber Security Centre of Excellence