At a Glance
- Tasks: Design and maintain robust security architectures to protect sensitive data and IT infrastructure.
- Company: Join the Medicines and Healthcare products Regulatory Agency, a leader in health regulation.
- Benefits: Enjoy a competitive salary, flexible working, and opportunities for professional growth.
- Other info: Be part of a dynamic team driving digital transformation in healthcare.
- Why this job: Make a real impact on public health by safeguarding vital IT systems.
- Qualifications: Extensive experience in security architecture and strong collaboration skills required.
The predicted salary is between 22802 - 22802 £ per year.
We are currently looking for a Lead Security Architect to join our Strategy & Architecture Function within the Digital & Technology group. This is a full-time opportunity, on a permanent basis. The role will be based in 7/8 Wellington Place, Leeds, LS1 4AP. Government departments and agencies are working towards implementing a minimum 60% attendance in office sites.
We are currently implementing a flexible, hybrid way of working, with a minimum of 8 days per month working on site to enable the collaboration and contact with partners and stakeholders needed to deliver MHRA business. Attendance on site is driven by business needs so depending on the nature of the role, this can flex up to 12 days a month, with the remainder of time worked either remotely or in the office. Some roles will need to be on site more regularly. Please discuss this with the recruiting manager before accepting an appointment.
In recognition of the need to attract and retain employees with specialist skills this role attracts a Market Pay Supplement of up to £22,802 per annum. This non-contractual supplement is reviewed at the end of the probation period and thereafter annually and is non-pensionable.
The Medicines and Healthcare products Regulatory Agency enhance and improve the health of millions of people every day through the effective regulation of medicines and medical devices, underpinned by science and research. The Digital and Technology Group (DTG) lies at the heart of the Agency and is responsible for delivering an optimised IT infrastructure and maximising the secure use of data to enable our scientists, inspectors, and the rest of the organisation to deliver world class services which can improve outcomes for patients and the general public.
The work we do matters! Its centre of excellence is also responsible for delivering a broad portfolio of change initiatives, both to transform the Agency’s legacy technologies and to deliver innovative new solutions, designed around our customers’ needs. DTG works in a holistic way to combine digital and technology change, data and information management, project delivery, business process, product management and cultural change to maximise our impact and ensure sustainability. We plan to be at the heart of one of the most digitally advanced medical regulators in the world and we need people who can help us deliver that ambition. DTG is a great place to build your career, and we are committed to enabling our people to do the best work of their lives.
As an IT Security Architect, you will play a critical role in safeguarding the department’s IT infrastructure and sensitive data, responsible for designing, building, and maintaining robust security architectures that protect the department's systems from threats and vulnerabilities. Your primary goal is to ensure that all IT services and solutions are secure by design and compliant with government security policies and standards. This role requires a strategic thinker with deep technical expertise knowledge, an understanding of emerging threats, and the ability to work collaboratively with various stakeholders to embed security principles throughout the IT landscape.
You will work closely with various stakeholders, including business leaders, IT teams, and external partners, to develop and implement security strategies that align with the department's objectives and regulatory requirements.
- Key responsibilities:
- Security Architecture Design
- Security Policy Development and Compliance
- Security Awareness and Training
- Stakeholder Engagement and Collaboration
- Innovation and Continuous Improvement
Our successful candidate will:
- Develop and maintain a comprehensive Security Architecture framework that aligns with the IT strategy, government policies, and best practices.
- Develop, implement, and maintain security policies, standards, and procedures in line with government regulations, industry standards, and departmental needs, ensuring that all IT systems and solutions comply with relevant legal, regulatory, and governmental standards, such as GDPR, Cyber Essentials, Secure By Design.
- Collaborate with cross-functional teams to ensure security is integrated into all aspects of the Agency’s digital transformation initiatives.
- Stay abreast of industry trends, emerging technologies, and best practices in Technical Architecture, bringing forward recommendations for improvement.
Person Specification:
- Method of assessment: A=Application, T=Test, I=Interview, P=Presentation
Behaviour Criteria:
- Leadership (I)
- Making Effective Decisions (I)
- Working Together (I)
- Communicating and Influencing (P)
Experience Criteria:
- Extensive experience designing, implementing, and managing the security architecture for large, complex organisations, with deep expertise in security architecture principles including defence in depth, zero trust, least privilege, and secure by design approaches (A, I, P)
- Strong risk and assurance capability, including conducting risk assessments and threat modelling, developing risk management strategies, and leading internal and external security audits, assessments, and penetration testing aligned to frameworks such as CAF and NIST (A, I)
- Proven track record in security governance and continuous improvement, including developing and maintaining security policies, standards, and procedures in line with industry best practice, and applying up to date knowledge of emerging threats, vulnerabilities, and trends to strengthen organisational security posture (A)
Technical Criteria:
- Experience in designing and implementing secure network architectures, including knowledge of network protocols, segmentation, firewalls, VPNs, and intrusion detection/prevention systems (IDS/IPS) in on-premise and cloud environments (A, P)
- Demonstrable experience with a range of security technologies and tools, including but not limited to: (A) Identity and Access Management (IAM), SIEM tools, endpoint protection, and cryptography and encryption solutions, Data Protection and Privacy Controls, Vulnerability Management, Security Orchestration, Automation, and Response (SOAR) Tools, Secure Mobile and Endpoint Computing and securing web applications, APIs, and microservices Degree level or significant professional experience (A)
Desirable:
- Familiarity with UK public sector regulations, standards, and frameworks, such as the Government Digital Service (GDS), Secure by Design, Cyber Essentials, NCSC guidelines, GDPR, and ISO/IEC 27001 (A)
- Security qualification e.g. CISSP, SABSA (A)
If you would like to find out more about this fantastic opportunity, please read our Job Description and Person Specification!
Please note: The job description may not open in some internet browsers. Please use Chrome or Microsoft Edge. If you have any issue viewing the job description, please contact careers@mhra.gov.uk
The selection process: We use the Civil Service Success Profiles to assess our candidates. Online application form, including questions based on the Behaviour, Experience and Technical Success Profiles. Please ensure all application questions are completed in full; your application may not be considered if any responses are left blank. Our applications are CV blind, and our Hiring Managers will not be able to access your CV when reviewing your application. Presentation, to be prepared as part of your interview, with further information being supplied when you reach this stage. Interview, which can include questions based on the Behaviour, Experience, Technical and Strengths Success Profiles.
In the instance that we receive a high number of applications, we will hold an initial sift based on the lead criteria of Extensive experience designing, implementing, and managing the security architecture for large, complex organisations, with deep expertise in security architecture principles including defence in depth, zero trust, least privilege, and secure by design approaches.
Applicants are assessed on whether they meet any mandatory requirements as well as the necessary skills and experience for the role. Applications are scored based on the competency-based answers provided- ensure you have read these thoroughly and allow sufficient time. You can view the competencies for this role in the job description.
Use of AI in Job Applications: Artificial Intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance for more information on appropriate and inappropriate use. If you require any disability related adjustments at any point during the process, please contact careers@mhra.gov.uk as soon as possible.
Closing date: 6th September 2026
Shortlisting date: from 11th September 2026
Interview date: from 28th September 2026
If you need assistance applying for this role or have any other questions, please contact careers@mhra.gov.uk
Candidates will be subject to UK immigration requirements as well as Civil Service nationality rules. Further information on whether you are able to apply is available here. Successful candidates must pass a disclosure and barring security check as well as animal rights and pro-life activism checks. People working with government assets must complete basic personnel security standard checks.
Certain roles within the MHRA will require post holders to have vaccinations, and in some circumstances, routine health surveillance. These roles include:
- Laboratory-based roles working directly with known pathogens
- Maintenance roles, particularly those required to work in laboratory settings
- Roles that involve visiting other establishments where vaccination is required
- Roles required to travel overseas where specific vaccination may be required.
Applicants who are successful at interview will be, as part of pre-employment screening subject to a check on the Internal Fraud Database (IFD). This check will provide information about employees who have been dismissed for fraud or dishonesty offences. This check also applies to employees who resign or otherwise leave before being dismissed for fraud or dishonesty had their employment continued. Any applicant’s details held on the IFD will be refused employment. A candidate is not eligible to apply for a role within the Civil Service if the application is made within a 5 year period following a dismissal for carrying out internal fraud against government. Any move to the MHRA from another employer will mean you can no longer access childcare vouchers. This includes moves between government departments. You may however be eligible for other government schemes, including Tax-Free Childcare. Determine your eligibility here.
Individuals appointed on level transfer will retain their existing salary and are responsible for ensuring they fully understand the financial implications of any potential move and the impact (if any) on their terms. If an individual is in any doubt, they should seek clarification before accepting a job offer. Staff joining on promotion will receive up to a 10% increase of their current basic salary, or the pay band minimum, whichever is the greater. The individual will not retain any allowances paid by the former department/Agency, unless there are special circumstances, such as a reserved right to those allowances on transfer.
Successful candidates may be subject to annual Occupational Health reviews dependent on role requirements. If you have any queries, please contact careers@mhra.gov.uk.
In accordance with the Civil Service Commissioners’ Recruitment Principles our recruitment and selection processes are underpinned by the requirement of selection for appointment on the basis of merit by a fair and open competition. If you feel your application has not been treated in accordance with the Recruitment Principles and you wish to make a complaint, in the first instance, you should contact the MHRA Recruitment Team at careers@mhra.gov.uk. If you are not satisfied with the response you receive, you can contact the Civil Service Commission at: civilservicecommission.independent.gov.uk info@csc.gov.uk Civil Service Commission Room G/8 1 Horse Guards Road London SW1A 2HQ
Lead Security Architect in Leeds employer: Medicines and Healthcare Products Regulatory Agency
The Medicines and Healthcare products Regulatory Agency (MHRA) is an exceptional employer, offering a dynamic work environment in the heart of Canary Wharf, London. With a strong commitment to employee growth, the agency provides opportunities for professional development and collaboration with leading experts in healthcare and research. The hybrid working model promotes a healthy work-life balance, while the agency's focus on innovation and public health ensures that employees contribute to meaningful projects that enhance the well-being of millions.
Contact Details:
Medicines and Healthcare Products Regulatory Agency Recruitment Team
StudySmarter Expert Advice🤫
We think this is how you could land Lead Security Architect in Leeds
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Medicines and Healthcare Products Regulatory Agency, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Medicines and Healthcare Products Regulatory Agency
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Medicines and Healthcare Products Regulatory Agency. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Lead Security Architect in Leeds
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Medicines and Healthcare Products Regulatory Agency insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Medicines and Healthcare Products Regulatory Agency that you’re committed to staying ahead in the game.
How to prepare for a job interview at Medicines and Healthcare Products Regulatory Agency
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Medicines and Healthcare Products Regulatory Agency to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Medicines and Healthcare Products Regulatory Agency.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.