At a Glance
- Tasks: Lead security architecture for renewable energy projects, ensuring secure designs and compliance.
- Company: NextEnergy Group focuses on developing and operating large-scale solar and battery storage projects across Europe.
- Benefits: Enjoy flexible working options, a collaborative culture, and opportunities for professional growth.
- Why this job: Join us to make a real impact in the clean energy sector while innovating in security practices.
- Qualifications: 5+ years in security architecture, with experience in renewable energy and strong knowledge of Azure security.
- Other info: Ideal for those passionate about sustainability and eager to tackle new challenges.
The predicted salary is between 54000 - 84000 £ per year.
NextEnergy Group develops, builds, and operates large-scale solar Photovoltaic (PV) assets and battery storage projects across Europe. As our Security & Information Security Architect, you will set the security vision and implement secure-by-design principles across all organizational layers—from field-level Operational Technology networks and real-time trading engines to corporate business systems.
A key aspect of this role involves close collaboration with:
- Data Protection Officer (DPO): embedding privacy-by-design, supporting DPIAs, and audits
- Network & Security Engineering team: translating architecture patterns into robust, monitored, and recoverable production configurations
- External security advisors & key technology suppliers: aligning architectural controls with best practices, managed service deliverables, and secure software supply chain requirements
This is a strategic yet hands-on role that balances secure-by-design principles with practical delivery across cloud, on-premises, and SaaS environments.
KEY RESPONSIBILITIES
- Develop and evolve enterprise security architecture (reference models, standards, patterns) for IT, OT, and hybrid-cloud environments handling renewable-generation data.
- Integrate security and privacy requirements into solution designs, CI/CD pipelines, and infrastructure as code, collaborating closely with product teams and the DPO.
- Conduct threat modeling, risk assessments, and analyses (STRIDE/PASTA) for new solar plant constructions, grid integration projects, and SaaS platforms.
- Lead architecture on secure network topologies (IT/OT segmentation, zero-trust, IEC 62443 zones) with Network & Security Engineers.
- Establish standards for IAM, encryption (at rest/in transit), secrets management, and key management aligned with ISO 27001/27019 and NIS2.
- Review and select third-party security solutions; lead due diligence with EPC, O&M, and SCADA vendors.
- Serve as SME for compliance frameworks such as ISO 27001, NIST CSF, GDPR, IEC 62443, CIS Controls.
- Collaborate with the DPO on data flow mapping, DPIA, breach response readiness, and audits.
- Monitor emerging threats in the energy sector and update architecture roadmaps accordingly.
SKILLS & COMPETENCIES
- Time management & prioritization skills: ability to manage workload effectively in a dynamic environment.
- Excellent communication skills: articulate in English (and other European languages), capable of clear written and verbal communication.
- Flexibility: adaptable and open to new challenges beyond your formal role.
- Intellectual curiosity: genuine interest in the profession, with a desire to delve deep and innovate.
- Delivery focus: proactive work ethic with a focus on quality and timely delivery.
- Critical thinking and problem-solving skills.
- Passion for our mission: to generate a sustainable future through clean energy.
- Alignment with our values: leadership, trust, responsibility, innovation, and bringing your best.
EXPERIENCE & QUALIFICATIONS
- 5+ years in security architecture/cyber engineering, with 3+ years in renewable energy, utilities, or critical infrastructure.
- Deep knowledge of Azure security, hybrid networking, container/serverless security, and DevSecOps tools.
- Experience in securing corporate platforms (ERP, CRM, HR, finance, M365, identity providers, SaaS).
- Familiarity with offensive security techniques; ability to interpret red-team reports and translate findings into controls.
- Understanding of OT protocols (Modbus/TCP, IEC 61850, DNP3) and SCADA/RTU architectures.
- Strong stakeholder engagement skills; proven record working with DPO, Risk, Compliance, and Security Operations teams.
- Certifications such as CISSP, CISM, SABSA, TOGAF, or Azure Security Specialty are desirable.
- Additional desirable certifications include ISA/IEC 62443 Cybersecurity Specialist or GIAC GICSP.
- Experience with ISO 27001/27019, NIS2 compliance, or TSO cybersecurity standards is advantageous.
- Legal right to work in the UK.
Security & Information Security Architect employer: NextEnergy Group
Contact Detail:
NextEnergy Group Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Security & Information Security Architect
✨Tip Number 1
Familiarise yourself with the latest trends and technologies in security architecture, especially those related to renewable energy. This will not only help you understand the role better but also allow you to engage in meaningful conversations during interviews.
✨Tip Number 2
Network with professionals in the renewable energy sector, particularly those involved in security roles. Attend industry conferences or webinars to build connections and gain insights that could give you an edge in your application.
✨Tip Number 3
Showcase your hands-on experience with Azure security and DevSecOps tools through practical examples. Be prepared to discuss specific projects where you've implemented secure-by-design principles, as this will demonstrate your capability for the role.
✨Tip Number 4
Research NextEnergy Group's current projects and initiatives in solar PV and battery storage. Understanding their mission and values will help you align your responses during interviews and show your genuine interest in contributing to their goals.
We think you need these skills to ace Security & Information Security Architect
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in security architecture and renewable energy. Emphasise your skills in Azure security, hybrid networking, and any certifications you hold that are pertinent to the role.
Craft a Compelling Cover Letter: In your cover letter, express your passion for clean energy and how your background aligns with NextEnergy Group's mission. Mention specific projects or experiences that demonstrate your ability to implement secure-by-design principles.
Showcase Relevant Skills: Clearly outline your time management, communication, and problem-solving skills in your application. Provide examples of how you've successfully managed workloads in dynamic environments and collaborated with cross-functional teams.
Highlight Compliance Knowledge: Since compliance is crucial for this role, make sure to mention your familiarity with frameworks like ISO 27001, NIST CSF, and GDPR. Discuss any direct experience you have with these standards in your previous roles.
How to prepare for a job interview at NextEnergy Group
✨Understand the Role and Responsibilities
Make sure you thoroughly understand the key responsibilities of the Security & Information Security Architect role. Familiarise yourself with concepts like secure-by-design principles, threat modelling, and compliance frameworks such as ISO 27001 and NIST CSF. This will help you articulate how your experience aligns with their needs.
✨Showcase Your Technical Expertise
Be prepared to discuss your technical skills in areas like Azure security, hybrid networking, and DevSecOps tools. Highlight specific projects where you've implemented security measures or led architecture discussions, especially in renewable energy or critical infrastructure settings.
✨Demonstrate Communication Skills
Since this role involves collaboration with various teams, it's crucial to showcase your communication skills. Practice explaining complex security concepts in simple terms, and be ready to discuss how you've effectively engaged with stakeholders in previous roles.
✨Express Your Passion for Clean Energy
Convey your enthusiasm for the mission of generating a sustainable future through clean energy. Share any relevant experiences or projects that reflect your commitment to this cause, as cultural fit is just as important as technical skills.