At a Glance
- Tasks: Lead cyber security design for national-scale programmes and ensure compliance with security standards.
- Company: Join the National Physical Laboratory, a leader in measurement science and technology.
- Benefits: Enjoy flexible working, social activities, and a range of employee benefits.
- Other info: Diverse and inclusive workplace with excellent career growth opportunities.
- Why this job: Make a real impact on national security while working with cutting-edge technologies.
- Qualifications: Expertise in cyber security architecture and relevant certifications like CISSP or CISM required.
The predicted salary is between 43200 - 72000 ÂŁ per year.
The National Physical Laboratory (NPL) is seeking a Principal Enterprise Security Architect to lead cyber security design and assurance for nationalâscale Position, Navigation and Timing (PNT) programmes. The role requires expertise in enterprise security architecture frameworks, cloud and IT technologies, risk mitigation and relevant certifications such as CISSP or CISM, while collaborating with senior stakeholders and ensuring alignment with NPL's security strategy and compliance with government and industry standards.
This role will be responsible for the overall cyber security design, development and delivery across strategic PNT programmes. It will deliver assurance relating to activities of high complexity and risk, making decisions that enable NPL to achieve its goals within its risk appetite.
The Principal Enterprise Security Architect will lead the Cyber Security pillar within the PNT Technical Design Authority, overseeing the implementation of solutions to ensure technology and digital solutions align with the enterprise security roadmap. This specialist position reports to the head of NPL's Cyber Security Team, part of the NPL CIO function, helping to provide dayâtoâday information risk consultancy, advice and guidance for all of NPL. It also supports prioritisation of risk mitigation activities, tracking of risk tolerance and reporting while supporting the design and implementation of the assurance framework.
Key Responsibilities
- Lead the cyber security architecture and design function across NPL's PNT programmes to deliver at National Scale
- Oversee the design, delivery and operation of Cyber Operational capability dedicated to NPL's PNT programmes
- Develop an enterprise architecture and guiding principles for the PNT programmes that align with NPL's security strategy
- Communicate with senior stakeholders (across NPL and UK Government) and define the vision, principles and strategy for security architecture
- Work alongside the Enterprise Architecture team to provide a consolidated and aligned architectural position to guide NPL in the safe use of IT technologies and systems
- Lead the technical cyber security design of systems and services across multiple PNT programmes and projects / technologies, up to an organisational or interâorganisational level
- Make and influence important business and architectural decisions
- Research, identify, validate and adopt new security technologies and methodologies that help NPL achieve its business objectives
- Research and apply innovative security architecture solutions to new or existing problems, and justify and communicate design decisions
- Lead the engagement with NPL's customers within both the UK Government and the private sector on security risk and architectural decisions
- Understand the impact of decisions, balancing requirements and deciding between approaches based on the business requirements and risk appetite of NPL
- Identify and communicate current and emerging threats, whilst designing security architecture elements to provide mitigation against those threats
- Maintain an understanding of the emerging threat profile, work with the wider team to contextualise this threat in terms of NPL's own business and delivered programmes, and ultimately develop a prioritised mitigation strategy; develop a security posture that delivers this mitigation through technical implementation, operating procedures and business processes
About You
Essential
- Referenceable, inâdepth knowledge and experience in Cyber Security and IT; including business process design
- Ability to work with Enterprise Security Architecture frameworks (SABSA / TOGAF)
- Designing and constructing business processes, functions and organisational structures using appropriate tools/models
- Significant knowledge of cloud architecture and integration technologies
- Understanding of IT, networking and virtualisation technologies
- Proven ability to define architecture roadmaps, associated strategies, including design analysis
- Inâdepth assessment of IT systems, cloud offerings (IaaS, PaaS and SaaS), services and IT Security controls to provide an independent view of their compliance and effectiveness with Security Policy, IT Security standards and external regulatory requirements
- Assessing architectural designs to determine whether the relevant IT Security controls have been identified in line with business objectives and risk mitigation
- Experience of crossâsecurity domain approaches and solutions
- A working knowledge of IT Security risk assessment processes and ability to identify a proportionate set of IT Security controls, aligned with business objectives
- Excellent communicator, verbal and written, with the ability to explain complex issues to a variety of stakeholders; technical and nonâtechnical
Desirable
- Secure delivery of scale national infrastructure and subsequent managed service; including the ability to design and build practical security infrastructure within this environment, based on a contextualised understanding of risk
- Experience of operating in Critical National Infrastructure (CNI) and the requirements around cyber security and operational resilience
- Understanding of threats in a government, mission and critical national infrastructure environments
- Analysis, creation and compilation of relevant documentation determining the compliance level of systems and services, technical security controls with applicable certification, accreditation and internal policy requirements
- Stakeholder engagement; promoting a mindâset of developing secure systems, transferring knowledge of security standards / processes and acting as a subjectâmatter expert (SME)
- Experience of leading and mentoring colleagues
- Ability to work in small teams, across highlyâspecialised technology areas with diverse projects
Essential Cyber Security Certifications
- Certified Information Security Systems Professional (CISSP)
- SABSA Chartered Security Architect (SCF)
- Certified Information Security Manager (CISM)
Preferred Certifications (Two or more of the following)
- CompTIA Security+
- Certified Cloud Security Professional (CCSP)
- Systems Security Certified Practitioner (SSCP)
- GIAC Security Essentials Certification (GSEC)
- Certified Ethical Hacker (CEH)
- Certified in Risk and Information Systems Control (CRISC)
- ISO 27001 Lead Auditor
- ISO 27001 Lead Implementer
- Certified Information Systems Auditor (CISA)
We actively recruit citizens of all backgrounds, but the nature of our work in specific departments means that nationality, residency and security requirements can be more tightly defined than others. You will be asked about this throughout the recruitment process. To work at NPL, you will need to obtain BPSS security clearance. However, to work in this role in the Time & Frequency department, you will need to have an SC clearance with no restrictions, or you must have the ability to obtain an SC clearance.
Please note: Applications will be reviewed, and interviews conducted throughout the duration of this advert; we may at any time bring the closing date forward. We encourage all interested applicants to apply as soon as practical.
About Us
The National Physical Laboratory (NPL) is a worldâleading centre of excellence that provides cuttingâedge measurement science, engineering and technology to underpin prosperity and quality of life in the UK.
NPL and DSIT have strong commitments to diversity and equality of opportunity, and welcome applications from candidates irrespective of their background, gender, race, sexual orientation, religion, or age, providing they meet the required criteria. Applications from women, disabled and black, Asian and minority ethnic candidates in particular are encouraged. All disabled candidates (as defined by the Equality Act 2010) who satisfy the minimum criteria for the role will be guaranteed an interview under the Disability Confident Scheme.
At NPL, we believe our success is a result of the diversity and talent of our people. We strive to nurture and respect individuals to ensure everyone feels valued by treating everyone on the basis of their own individual merits and abilities regardless of their own or perceived identity, as part of our commitment to diversity & inclusion, we hold memberships and accreditations to ensure we're creating an environment where all our colleagues feel supported and welcome.
We are committed to the health and wellâbeing of our employees. Flexible working and social activities are embedded in our culture to create a positive workâlife balance, along with a broad range of benefits. Our values are at the heart of what we do, and they shape the way we interact, develop our people and celebrate success.
To ensure everyone has an equal chance, we're always willing to make reasonable adjustments to the recruitment process. If you would like to discuss, please contact us.
Principal Enterprise Security Architect in London employer: NPL Careers
Contact Detail:
NPL Careers Recruiting Team
StudySmarter Expert Advice đ¤Ť
We think this is how you could land Principal Enterprise Security Architect in London
â¨Tip Number 1
Network like a pro! Reach out to folks in your industry, especially those already at NPL or similar organisations. A friendly chat can open doors and give you insider info on the role.
â¨Tip Number 2
Prepare for the interview by brushing up on your knowledge of enterprise security architecture frameworks. Be ready to discuss how your experience aligns with NPL's security strategy and compliance needs.
â¨Tip Number 3
Showcase your problem-solving skills! Be prepared to share examples of how you've tackled complex security challenges in the past. This will demonstrate your ability to handle the high-risk decisions expected in this role.
â¨Tip Number 4
Donât forget to apply through our website! Itâs the best way to ensure your application gets the attention it deserves. Plus, we love seeing candidates who are proactive about their job search!
We think you need these skills to ace Principal Enterprise Security Architect in London
Some tips for your application đŤĄ
Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience with enterprise security architecture frameworks and cloud technologies. We want to see how your skills align with the specific requirements of the Principal Enterprise Security Architect role.
Showcase Your Certifications: Donât forget to mention your relevant certifications like CISSP or CISM. These are key for us, so make them stand out in your application to show youâre the right fit for the job!
Communicate Clearly: Since this role involves working with senior stakeholders, itâs crucial to demonstrate your communication skills. Use clear and concise language in your written application to convey complex ideas effectively.
Apply Through Our Website: We encourage you to apply directly through our website. Itâs the best way for us to receive your application and ensures you donât miss any important updates during the recruitment process.
How to prepare for a job interview at NPL Careers
â¨Know Your Cyber Security Frameworks
Make sure you brush up on enterprise security architecture frameworks like SABSA and TOGAF. Be ready to discuss how you've applied these frameworks in your previous roles, especially in relation to risk mitigation and compliance with industry standards.
â¨Showcase Your Technical Expertise
Prepare to dive deep into your knowledge of cloud architecture and IT technologies. Be specific about the tools and methodologies you've used, and how they align with the security strategies of the organisations you've worked for.
â¨Communicate Effectively with Stakeholders
Practice explaining complex cyber security concepts in simple terms. Youâll need to demonstrate your ability to engage with both technical and non-technical stakeholders, so think of examples where you've successfully communicated your vision and strategy.
â¨Stay Updated on Emerging Threats
Research current and emerging threats in the cyber security landscape. Be prepared to discuss how you would identify and mitigate these threats within the context of NPL's PNT programmes, showcasing your proactive approach to security architecture.