At a Glance
- Tasks: Define and improve cybersecurity architecture, ensuring effective risk intelligence for the business.
- Company: Join a leading cybersecurity consultancy with a focus on innovation and collaboration.
- Benefits: Remote-first work culture, competitive salary, and opportunities for professional growth.
- Other info: Dynamic environment with a focus on teamwork and continuous learning.
- Why this job: Make a real impact in cybersecurity by shaping strategies and guiding teams.
- Qualifications: 8+ years in cybersecurity architecture and experience with security assessment tools.
The predicted salary is between 80000 - 100000 £ per year.
Dev/Null Security is a leading cybersecurity consultancy specializing in security solution architecture, engineering, implementation, and operational support. With decades of experience, our expert teams protect high-value systems from advanced threats. We provide exceptional consulting services and deliver value at every step, focusing on Strategy and Advisory, Consulting and Managed Services, and Privileged Access Management. Dev/Null Security is dedicated to safeguarding critical assets and helping clients navigate complex cybersecurity challenges.
Purpose of the Role
The Cyber Security Architect is responsible for defining, governing, and continuously improving the architecture of the organisation's cybersecurity assessment capabilities. This means owning the strategic direction of tooling, processes, and integration patterns and ensuring those capabilities translate into meaningful, actionable risk intelligence for the business. The role is architectural and advisory in nature. The successful candidate sets direction, defines standards, and provides expert guidance on tools and services; they do not deliver hands‑on assessment or testing activity themselves. The emphasis is on enterprise‑scale thinking, stakeholder engagement, and the ability to translate capability requirements into coherent, implementable architecture.
Key Responsibilities
- Define and maintain the security architecture for cybersecurity assessment capabilities, including tool selection, integration patterns, data flows, and coverage models across Exposure Management, Offensive Security, and Code Assessment.
- Lead the design and implementation of Exposure Management capabilities, including External Attack Surface Management (EASM), continuous vulnerability scanning, configuration baseline assessment, and risk‑based prioritisation frameworks.
- Design and embed Code Assessment capabilities within existing Software Development Lifecycle (SDLC) processes, covering Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Interactive Application Security Testing (IAST), Runtime Application Self‑Protection (RASP), and Software Composition Analysis (SCA).
- Translate technical vulnerabilities and assessment findings into material business risk, with clear communication suitable for technical and non‑technical audiences, including senior leadership.
- Develop and maintain architecture strategies, roadmaps, and design patterns for cybersecurity assessment capabilities, ensuring alignment with the broader enterprise security architecture.
- Work with solution architects and engineering teams across business units and functions to apply secure‑by‑design practices and embed cybersecurity assessment tooling within delivery pipelines.
- Conduct threat modelling and complex risk assessments to support new technologies, platforms, and design patterns across the organisation.
- Review and recommend enhancements to security standards, controls, and policies related to assessment and testing.
- Provide security subject matter expertise to transformation programmes across business units and functions, ensuring security risk is correctly identified and factored into design decisions from the outset.
- Support the education and development of solution architects and engineering teams to improve their awareness and application of security testing practices.
Experience Required
- Demonstrable experience designing and architecting cybersecurity assessment capabilities in a large enterprise environment, covering at minimum two of the three domains: Exposure Management, Offensive Security, or Code Assessment.
- Experience implementing and supporting vulnerability management capabilities at enterprise scale, including vulnerability scanning, centralised reporting, and configuration baseline assessment.
- Experience designing and integrating application security testing tools (SAST, DAST, IAST, RASP, SCA) within SDLC processes, including CI/CD pipelines.
- Experience architecting offensive security programmes, including scoping, methodology definition, toolchain selection, and integration with remediation workflows.
- Experience with External Attack Surface Management (EASM) and continuous exposure monitoring — understanding how to translate asset discovery and exposure data into prioritised risk.
- Ability to translate complex technical findings into business risk terms, with experience presenting to senior technical and non‑technical stakeholders.
- Experience creating architecture strategies, roadmaps, and design patterns and presenting them to diverse audiences.
- Experience performing threat modelling and risk assessments to support new technology adoption or design pattern development.
- Strong understanding of cloud security across at least one major platform (AWS, Azure, or GCP), including how cybersecurity assessment capabilities apply in cloud‑native and hybrid environments.
- At least eight years of relevant technical experience, including experience working in a large corporate or regulated environment.
- University degree in a technical discipline, or equivalent experience.
- Relevant industry certifications (OSCP, CREST, CEH, CISSP, or equivalent).
- Familiarity with standard IT engineering and architecture frameworks (TOGAF, SABSA, or equivalent).
- Experience with Purple Team operations and the integration of offensive testing findings into defensive capability improvement.
- Familiarity with risk quantification frameworks (CVSS, EPSS, or proprietary models) and how they support prioritisation at scale.
- Experience working in a federated global organisation with distributed technology teams.
- Ability to work efficiently under pressure with tight timelines across globally distributed teams.
Key Stakeholders
- CISO
- Security Architect Lead
- Business Unit and Function Solution Architects and Engineering Leads
- Vulnerability Management and Remediation Teams
- Application Development and DevSecOps Teams
- Risk and Compliance Functions
Additional Information
The success of cybersecurity assessment architecture will be measured not only by what is delivered, but by how effectively those capabilities are adopted, integrated, and used to reduce real risk across the organisation. The ideal candidate is technically credible, comfortable working across organisational boundaries, and able to operate effectively in a federated environment where influence matters as much as authority.
The role requires:
- A collaborative, team‑oriented approach with a genuine willingness to share knowledge and develop others.
- Openness to constructive challenge and the ability to give clear, direct feedback in return.
- A self‑starting attitude with the drive to move work forward without waiting for direction.
- Intellectual curiosity and a commitment to staying current across a fast‑moving threat and tooling landscape.
Whilst DevNull Security is a remote‑first company, our consulting team may be required to travel to client sites up to 3 times per week, depending on project and customer needs.
Cyber Security Architect in Manchester employer: Dev/Null Security
At Dev/Null Security, we pride ourselves on being a leading cybersecurity consultancy that fosters a collaborative and innovative work culture. Our remote-first approach allows for flexibility while providing opportunities for professional growth through continuous learning and exposure to cutting-edge security technologies. With a commitment to employee development and a focus on meaningful contributions to client success, we offer an environment where your expertise can truly make a difference.
StudySmarter Expert Advice🤫
We think this is how you could land Cyber Security Architect in Manchester
✨Tip Number 1
Network like a pro! Attend cybersecurity meetups, webinars, and conferences to connect with industry experts. Don't be shy—introduce yourself and share your passion for security architecture!
✨Tip Number 2
Showcase your expertise! Create a portfolio or blog where you discuss your experiences and insights in cybersecurity. This not only highlights your skills but also demonstrates your commitment to the field.
✨Tip Number 3
Prepare for interviews by practising common questions related to cybersecurity architecture. Be ready to discuss your past projects and how you've tackled complex challenges—this is your chance to shine!
✨Tip Number 4
Apply through our website! We love seeing candidates who take the initiative. Tailor your application to highlight your relevant experience and how it aligns with our mission at Dev/Null Security.
We think you need these skills to ace Cyber Security Architect in Manchester
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Cyber Security Architect role. Highlight your experience in cybersecurity assessment capabilities and any relevant tools you've worked with. We want to see how your skills align with our needs!
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about cybersecurity and how your background makes you a perfect fit for Dev/Null Security. Keep it engaging and relevant to the job description.
Showcase Your Achievements:Don’t just list your responsibilities; showcase your achievements! Use specific examples of how you've improved security architectures or led successful projects. We love seeing quantifiable results that demonstrate your impact.
Apply Through Our Website:We encourage you to apply through our website for a smoother application process. It helps us keep track of your application and ensures you don’t miss out on any important updates from us!
How to prepare for a job interview at Dev/Null Security
✨Know Your Cybersecurity Architecture
Make sure you understand the key components of cybersecurity architecture, especially in relation to assessment capabilities. Brush up on your knowledge of Exposure Management, Offensive Security, and Code Assessment, as these are crucial for the role.
✨Communicate Clearly with Stakeholders
Practice translating complex technical jargon into business risk terms. You’ll need to present findings to both technical and non-technical audiences, so being able to communicate effectively is key. Consider doing mock presentations to refine your skills.
✨Showcase Your Experience
Be ready to discuss your past experiences in designing and implementing cybersecurity assessment capabilities. Highlight specific projects where you’ve successfully integrated security tools within SDLC processes or led offensive security programmes.
✨Demonstrate Collaborative Spirit
This role requires a team-oriented approach, so be prepared to share examples of how you've worked collaboratively in previous roles. Emphasise your willingness to mentor others and your openness to feedback, as this will resonate well with the interviewers.