At a Glance
- Tasks: Define and implement security architecture for cutting-edge systems and platforms.
- Company: Join Indra Group, a global leader in technology and consulting.
- Benefits: Enjoy competitive salary, flexible remote work, and professional growth opportunities.
- Other info: Dynamic team environment with a focus on innovation and sustainability.
- Why this job: Make a real impact on cybersecurity for London's transport network.
- Qualifications: Experience in security architecture and risk management is essential.
About Indra Group UK & Ireland
Indra is a leading global technology and consulting company, and a trusted technological partner for the core business operations of its clients worldwide. It stands at the forefront of key sectors including Transport, Defence, Air Traffic Management and Space, alongside advanced Information Technology services delivered through Minsait, and cutting-edge capabilities in Sovereign AI, Cybersecurity, and Cyberdefence via IndraMind.
The company’s business model is built around a comprehensive portfolio of proprietary products, combining strong innovation with a high-value focus for customers. With more than 2,500 projects implemented across 50 countries and over 100 cities, Indra is a global benchmark in innovative transportation and mobility solutions. It is recognised as one of the world’s top three companies in public transportation management systems. Indra’s technology supports the daily journeys of over 78 million people, helping to reduce more than 10 million tonnes of CO₂ emissions annually, and helping save nearly 3,000 lives through improved traffic management and road safety.
Indra Group is paving the way to a more secure and better-connected future through innovative solutions, trusted relationships and the very best talent. Sustainability sits at the heart of its strategy and culture, driving efforts to address current and future social and environmental challenges. In the 2024 financial year, Indra achieved revenues of €5.5 billion, over 60,000 professionals, maintained a local presence in 46 countries, and operated across more than 140 countries worldwide.
As the technological partner for its customers’ key operations, Indra is at the core of their business, and Indra’s four values guide everything we do:
- Innovation - Our capacity for innovation, cutting‑edge solutions, and specialised team of professionals enables us to drive a safer, more connected future through technology.
- Trust - We work with strength, commitment, and reliability, delivering quality solutions to build trust with customers, employees, partners, investors, and society.
- Connection - We harness the power of collaboration, connect ideas and solutions, and adapt to our customers’ needs, supporting them on the path to a better future.
- Foresight - We anticipate future needs to make the world safer and more connected, transforming our experience and knowledge into solutions for a better tomorrow.
About the Project
Transport for London (TfL) has awarded Indra a long‑term contract to operate, develop, enhance and expand ticketing and access control systems across London’s transport network through to 2034, with extension options to 2039. This programme covers the maintenance, operation and evolution of a large-scale, complex ecosystem, including turnstiles, validators, ticket machines, sales terminals, back‑office systems, payment gateways, IT infrastructure and cybersecurity that supports over 8.6 million daily journeys.
Therefore, Indra will become TfL’s strategic technology partner to guarantee the operation and evolution of the world’s largest and most sophisticated ticketing system. Following a transition period of approximately two years, Indra will serve as the sole provider across the network that includes more than 8,500 buses, nearly 400 Underground stations, around 300 rail stations (Overground, DLR, Elizabeth Line and suburban services), 4,000 Oyster Card outlets, seven customer service centres, and 24 river boat boarding points.
Drawing on over 30 years of experience in urban public transport solutions, Indra will manage and evolve all aspects of the system. The project also envisages, in partnership with TfL, the implementation of new technologies to develop the system, make it more efficient and automate key processes; in short, to jointly create the next generation of the ticketing system for London.
Role Overview
The Security Architect is responsible for defining, guiding, and assuring the implementation of security architecture and cyber resilience control across a range of systems, platforms, and services. This role provides strategic and technical security expertise to support the design, development, and delivery solutions, working closely with engineering teams, project stakeholders, and business units.
Key Responsibilities
- Support the definition and integration of security requirements within projects, ensuring alignment with business needs and industry best practices.
- Provide security architecture guidance for the design and evolution of cloud services, applications, back‑office systems, and infrastructure solutions.
- Contribute to the assessment and management of security risks, supporting activities such as risk analysis, impact assessments, and audits when required.
- Collaborate with multidisciplinary teams (e.g. DevOps, system engineering, development, and project management) to promote secure‑by‑design principles across all phases of delivery.
- Advise on the implementation of appropriate security controls (technical, procedural, and organisational) to ensure the protection of systems and data.
- Support governance activities, including participation in design reviews, project checkpoints, and change management processes from a security perspective.
- Promote best practices and continuous improvement in information security, contributing to the adoption of standards, frameworks, and emerging technologies.
- Ensure that security considerations are appropriately documented and communicated to relevant stakeholders.
- Support the definition of processes that enable secure system operation, maintenance, and service transition.
- Ensure compliance with organisational policies, standards, and applicable regulatory requirements.
Working model
First 3 months: 2 days onsite per week. Thereafter: fully remote with a maximum of 0-1 day onsite (as required).
Security Architect employer: Doist
Brink's is an exceptional employer that fosters a collaborative and innovative work culture, empowering employees to drive global commercial strategies in the ATM lifecycle solutions sector. With a strong focus on professional development and growth opportunities, employees are encouraged to expand their skills while contributing to sustainable growth and operational excellence. Located in a dynamic environment, Brink's offers unique advantages such as a diverse team and the chance to build long-term partnerships with global customers, making it a rewarding place to advance your career.
StudySmarter Expert Advice🤫
We think this is how you could land Security Architect
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Doist, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Doist
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Doist. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Security Architect
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Doist insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Doist that you’re committed to staying ahead in the game.
How to prepare for a job interview at Doist
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Doist to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Doist.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.