Security Architect (Contractor) Cyber Security Consultant
Location: Fully Remote (UK)
Contract Type: Contractor
Contract Length: Immediate start until February 2027
Security Clearance: Active SC Clearance required and must be verifiable
About the Opportunity
We are seeking experienced Security Architects to support the delivery of secure, large-scale technology programmes within highly regulated environments. This is an excellent opportunity for a contractor with strong cloud security expertise and experience operating within central government or wider public sector settings.
Working remotely within a multidisciplinary delivery team, you will provide expert security architecture guidance throughout the full project lifecycle, helping to ensure that solutions are secure by design, aligned to recognised security frameworks, and capable of addressing evolving cyber threats.
What You'll Be Doing
Providing expert secure design advice and guidance to projects from the Discovery phase through to deployment and eventual service retirement.
Ensuring solution and product designs adhere to security standards, architectural blueprints and established security patterns.
Promoting Secure by Design principles and architectural best practice to reduce information risk across services and platforms.
Validating the design, implementation and effectiveness of security controls, working alongside controls testing and assurance teams where required.
Delivering security architecture to support the deployment of large data-driven services across private and public cloud environments, with a particular focus on Microsoft Azure.
Scoping and supporting IT Health Checks (ITHC) and penetration testing activities to identify key security risks and areas for improvement.
Reviewing security testing outcomes and providing practical recommendations, remediation guidance and action plans for identified vulnerabilities.
Identifying security risks arising from proposed solution architectures and defining proportionate mitigations and countermeasures.
Reviewing cyber threat intelligence and emerging attack trends to inform security design decisions and architecture roadmaps.
Delivering threat modelling, security risk assessments and analysis for applications, systems and infrastructure.
Designing practical security controls that align risk to organisational appetite while leveraging native cloud capabilities.
Producing high-quality security architecture artefacts, standards, patterns and blueprints.
What We're Looking For
You will be an experienced Security Architect who is comfortable working within complex stakeholder environments, translating security requirements into practical, business-focused outcomes. You will possess strong communication skills, a collaborative approach, and the ability to balance security, risk and delivery objectives.
Essential Skills & Experience
Proven experience in cybersecurity, security architecture, risk management or related disciplines.
Significant experience delivering security architecture within central government and/or public sector environments.
Minimum of five years' experience in a Security Architect or senior technical security role.
Strong working knowledge of security frameworks including ISO 27001, NIST Cyber Security Framework and CIS Controls v8.
Good understanding of UK Government and NCSC security standards, policies and guidance.
Experience securing cloud environments with a strong Azure focus, including technologies such as Entra ID, Azure Key Vault, Azure Policy and Azure IAM.
Experience working across broader multi-cloud environments including AWS and other cloud platforms.
Knowledge of event-driven and microservices-based architectures using native cloud technologies.
Demonstrable experience conducting threat modelling, security risk assessments and security analysis.
Experience working with controls testing teams and validating control effectiveness.
Experience planning and supporting IT Health Checks and penetration testing engagements.
Working knowledge of cloud security posture management, cloud-native security tooling and endpoint security technologies.
Understanding of Public Key Infrastructure (PKI), cryptography, privileged access management and role-based access control models.
Strong analytical, problem-solving and stakeholder management skills.
Excellent written and verbal communication skills, with the ability to influence technical and non-technical audiences.
Desirable Skills & Certifications
SABSA certification.
TOGAF certification.
CISSP, CISM or equivalent security certification.
Azure Solutions Architect certification.
AWS Certified Solutions Architect certification.
Experience delivering security architecture across large-scale digital transformation programmes.
Experience operating within Agile and DevSecOps delivery environments.
Please note: Active SC Clearance is a mandatory requirement for this role and must be current and capable of being validated.