Principal Enterprise Security Architect
Principal Enterprise Security Architect

Principal Enterprise Security Architect

Full-Time 43200 - 72000 ÂŁ / year (est.) No home office possible
N

At a Glance

  • Tasks: Lead cyber security design for national-scale PNT programmes and ensure compliance with security strategies.
  • Company: Join the National Physical Laboratory, a leader in scientific research and innovation.
  • Benefits: Enjoy competitive pay, professional development opportunities, and a collaborative work environment.
  • Why this job: Make a real impact on national security while working with cutting-edge technologies and expert teams.
  • Qualifications: Must have relevant certifications like CISSP or CISM and experience in enterprise security architecture.
  • Other info: This role requires SC clearance; applications are reviewed on a rolling basis.

The predicted salary is between 43200 - 72000 ÂŁ per year.

The National Physical Laboratory (NPL) is seeking a Principal Enterprise Security Architect to lead cyber security design and assurance for national‑scale Position, Navigation, and Timing (PNT) programmes; requiring expertise in enterprise security architecture frameworks, cloud and IT technologies, risk mitigation, and relevant certifications such as CISSP or CISM, while collaborating with senior stakeholders and ensuring alignment with NPL’s security strategy and compliance with government and industry standards.

This role will be responsible for the overall cyber security design, development and delivery across strategic PNT programmes. The role will be responsible for delivering assurance relating to activities of high complexity and risk, making decisions that will enable NPL to achieve its goals within its risk appetite.

The Principal Enterprise Security Architect will lead the Cyber Security pillar within the PNT Technical Design Authority, overseeing the implementation of solutions to ensure technology and digital solutions align with the enterprise security roadmap.

This specialist position will report into the head of NPL’s Cyber Security Team, part of the NPL CIO function helping to provide all of NPL with day‑to‑day information risk consultancy, advice, and guidance. It will also support with prioritisation of risk mitigation activities, tracking of risk tolerance and reporting while supporting the design and implementation of the assurance framework.

Key Responsibilities

  • Lead the cyber security architecture and design function across NPL’s PNT programmes to deliver at National Scale
  • To oversee the design, delivery, and running of Cyber Operational capability that is dedicated for NPL\’s PNT programmes
  • Develop an enterprise architecture and guiding principles for the PNT programmes which aligns with the NPL’s security strategy
  • Communicate with senior stakeholders (across NPL and UK Government) and be responsible for defining the vision, principles and strategy for security architecture.
  • Work alongside the Enterprise Architecture team to provide a consolidated and aligned architectural position to guide NPL in the safe use of IT technologies and systems
  • Lead the technical cyber security design of systems and services across multiple PNT programmes and projects / technologies, up to an organisational or inter‑organisational level
  • Make and influence important business and architectural decisions
  • Research, identify, validate and adopt new security technologies and methodologies that help NPL achieve its business objectives
  • Research and apply innovative security architecture solutions to new or existing problems, and be able to justify and communicate design decisions
  • Lead the engagement with NPL’s customers within both the UK Government and the private sector on security risk and architectural decisions
  • Understand the impact of decisions, balancing requirements and deciding between approaches based on the business requirements and risk appetite of NPL
  • Identify and communicate current and emerging threats, whilst designing security architecture elements to provide mitigation against those threats
  • Maintain an understanding of the emerging threat profile, work with the wider team to contextualise this threat in terms of NPL’s own business/delivered programmes and ultimately develop a prioritised mitigation strategy. Develop a security posture which delivers this mitigation through both technical implementation, operating procedures and business processes

Qualifications

Essential: Referenceable, in‑depth knowledge and experience in Cyber Security and IT; including business process design. Ability to work with Enterprise Security Architecture frameworks (SABSA / TOGAF). Designing and constructing business processes, functions and organisational structures using appropriate tools/modelling languages. Significant knowledge of cloud architecture and integration technologies. Understanding of IT, networking and virtualisation technologies. Proven ability to define architecture roadmaps, associated strategies, including design analysis. In‑depth assessment of IT systems, cloud offerings (IaaS, PaaS and SaaS), services and IT Security controls to provide an independent view of their compliance and effectiveness with Security Policy, IT Security standards and external regulatory requirements. Assessing architectural designs to determine whether the relevant IT Security controls have been identified in line with business objectives and risk mitigation. Experience of cross‑security domain approaches and solutions. A working knowledge of IT Security risk assessment processes and ability to identify a proportionate set of IT Security controls, aligned with business objectives. Excellent communicator, verbal and written, with the ability to explain complex issues to a variety of stakeholders; technical and non‑technical.

Desirable: Secure delivery of scale national infrastructure and subsequent managed service; including the ability to design and build practical security infrastructure within this environment, based on a contextualised understanding of risk. Experience of operating in Critical National Infrastructure (CNI) and the requirements around cyber security and operational resilience. Understanding of threats in a government, mission and critical national infrastructure environments. Analysis, creation and compilation of relevant documentation determining the compliance level of systems and services, technical security controls with applicable certification, accreditation, and internal policy requirements. Stakeholder engagement; promoting a mind‑set of developing secure systems, transferring knowledge of security standards / processes and acting as a subject‑matter expert (SME). Experience of leading and mentoring colleagues. Ability to work in small teams, across highly‑specialised technology areas with diverse projects.

Essential Cyber Security Certifications: One of the following:
– Certified Information Security Systems Professional (CISSP)
– SABSA Chartered Security Architect (SCF)
– Certified Information Security Manager (CISM)

Two or more of the following certifications (or equivalent):
– CompTIA Security+
– Certified Cloud Security Professional (CCSP)
– Systems Security Certified Practitioner (SSCP)
– GIAC Security Essentials Certification (GSEC)
– Certified Ethical Hacker (CEH)
– Certified in Risk and Information Systems Control (CRISC)
– ISO 27001 Lead Auditor
– ISO 27001 Lead Implementer
– Certified Information Systems Auditor (CISA)

We actively recruit citizens of all backgrounds, but the nature of our work in specific departments means that nationality, residency and security requirements can be more tightly defined than others. You will be asked about this throughout the recruitment process. To work at NPL, you will need to obtain BPSS security clearance. However, to work in this role in the Time & Frequency department, you will need to have an SC clearance with no restrictions, or you must have the ability to obtain an SC clearance. Please note: Applications will be reviewed, and interviews conducted throughout the duration of this advert therefore we may at any time bring the closing date forward. We encourage all interested applicants to apply as soon as practical.

#J-18808-Ljbffr

Principal Enterprise Security Architect employer: National Physical Laboratory

The National Physical Laboratory (NPL) is an exceptional employer, offering a dynamic work environment that fosters innovation and collaboration in the field of cyber security. With a strong commitment to employee development, NPL provides opportunities for professional growth through mentorship and access to cutting-edge technologies, all while contributing to national-scale programmes that have a meaningful impact. Located in Teddington, NPL boasts a supportive culture that values diversity and encourages employees to thrive in their careers, making it an ideal place for those seeking rewarding and impactful employment.
N

Contact Detail:

National Physical Laboratory Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Principal Enterprise Security Architect

✨Tip Number 1

Familiarise yourself with the specific enterprise security architecture frameworks mentioned in the job description, such as SABSA and TOGAF. Understanding these frameworks will not only help you in interviews but also demonstrate your commitment to aligning with NPL's security strategy.

✨Tip Number 2

Network with professionals in the cyber security field, especially those who have experience in national-scale programmes or government projects. Engaging with industry peers can provide insights into the role and may even lead to referrals.

✨Tip Number 3

Stay updated on the latest trends and emerging threats in cyber security. Being knowledgeable about current issues will allow you to speak confidently about how you can contribute to NPL’s objectives during interviews.

✨Tip Number 4

Prepare to discuss your experience in leading teams and mentoring colleagues, as this is a key aspect of the role. Think of specific examples where you've successfully guided others in applying architectural expertise in cyber security.

We think you need these skills to ace Principal Enterprise Security Architect

Enterprise Security Architecture Frameworks (SABSA, TOGAF)
Cloud Architecture and Integration Technologies
Cyber Security Design and Assurance
Risk Mitigation Strategies
Stakeholder Engagement and Communication
Technical Cyber Security Design
IT Security Risk Assessment Processes
Knowledge of NCSC's Cyber Assurance Framework (CAF)
Experience with NIST Cyber Security Framework (CSF) and ISO 27001
Proven Track Record in Secure Delivery of National Infrastructure
Ability to Define Architecture Roadmaps
Mentoring and Leading Colleagues
Understanding of Critical National Infrastructure (CNI) Requirements
Assessment of IT Systems and Cloud Offerings
Excellent Documentation and Knowledge Sharing Skills
Emerging Threat Identification and Mitigation

Some tips for your application 🫡

Tailor Your CV: Make sure your CV highlights relevant experience in enterprise security architecture, cloud technologies, and risk mitigation. Use specific examples that demonstrate your expertise in frameworks like SABSA or TOGAF.

Craft a Compelling Cover Letter: In your cover letter, express your passion for cyber security and how your skills align with NPL's mission. Mention your certifications such as CISSP or CISM and how they relate to the role.

Highlight Stakeholder Engagement Skills: Since the role involves communicating with senior stakeholders, emphasise your experience in stakeholder engagement. Provide examples of how you've successfully communicated complex security issues to both technical and non-technical audiences.

Showcase Continuous Learning: Mention any recent training or certifications you have pursued to stay updated on emerging cyber security trends and technologies. This demonstrates your commitment to professional development in a rapidly evolving field.

How to prepare for a job interview at National Physical Laboratory

✨Showcase Your Technical Expertise

As a Principal Enterprise Security Architect, you'll need to demonstrate a deep understanding of security and IT technologies. Be prepared to discuss your experience with enterprise security architecture frameworks like SABSA or TOGAF, and how you've applied them in previous roles.

✨Communicate Effectively with Stakeholders

This role involves engaging with senior stakeholders, so practice articulating complex security concepts in a way that is accessible to both technical and non-technical audiences. Highlight any past experiences where you successfully communicated security strategies or architectural decisions.

✨Prepare for Scenario-Based Questions

Expect questions that assess your problem-solving skills in real-world scenarios. Think about past projects where you had to make critical decisions regarding risk mitigation or security design, and be ready to explain your thought process and the outcomes.

✨Stay Updated on Cyber Security Trends

The cyber security landscape is constantly evolving. Make sure you're familiar with the latest trends, threats, and technologies. Being able to discuss recent developments or emerging threats will show your commitment to staying current in the field.

Principal Enterprise Security Architect
National Physical Laboratory

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

N
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>