Permanent hybrid variable Birmingham or London
What You’ll Be Doing
As a Security Architect, you will play a key role in designing and delivering secure, scalable, and compliant architectures for our clients, with a particular focus on Google Cloud Platform (GCP) and emerging Agentic AI systems. Leveraging your strong cloud security and governance expertise, you will:
Security Architecture
- Translate business, data protection and security requirements into practical architectural designs leveraging industry frameworks (NIST, ISO 27001, CIS).
- Design and maintain cloud‑native security architectures, with deep expertise in GCP architecture, security services, and secure workload design.
- Establish secure architectural patterns and standards across cloud platforms, with specific focus on GCP IAM, VPC Service Controls, Cloud Armor, Confidential Computing, and secure workload segmentation.
- Develop security design documentation, diagrams, and rationale aligned with business and compliance requirements.
- Apply risk‑based and threat‑based approaches to recommend secure and proportionate solutions.
Agentic AI & LLM Security Architecture
You will be responsible for shaping security controls around emerging AI ecosystems, including:
- Designing security architectures for agent‑based AI systems, including orchestration frameworks, tool‑use agents, and multi‑agent workflows.
- Implementing AI/LLM security controls across:
- API & orchestration security, including secure agent tool use
- Data security for vector stores, embeddings, and retrieval services
- Performing AI‑specific threat modelling, including:
- Sensitive data leakage
- Toxic output & jailbreak attempts
- Advising on secure integration of AI with cloud environments, focusing on compliant, privacy‑aware design.
- Conduct comprehensive risk assessments and threat modelling for cloud and AI systems.
- Support incident response, including issues involving AI‑driven systems and automated agents.
- Provide actionable mitigation strategies for cloud and AI threats.
Stakeholder Engagement & Technical Leadership
- Provide expert guidance to clients, presenting complex cloud and AI security concepts to technical and non‑technical partners.
- Mentor teams on secure cloud design, AI security, and modern architecture practices.
- Participate in pre‑sales and contribute to delivery collateral.
Security Policy, Standards & Governance
- Develop and implement cloud and AI security policies and standards.
- Support compliance assessments and audits, including cloud‑specific controls and emerging AI regulatory frameworks.
- Ensure alignment to governance standards such as ISO 27001, NIST 800‑53/CSF, NIS2, DORA, and industry cloud security benchmarks.
Technology Evaluation & Continuous Improvement
- Conduct cloud and AI security architecture reviews, including:
- GCP security posture assessments
- Evaluate and recommend security technologies for cloud, AI, identity, and data protection.
- Stay up to date with new threats, especially in LLM, agentic AI, and GCP contexts.
What Experience You’ll Bring
Required Core Profile
- Security‑first mindset — this role is primarily for a Security Architect, not a general cloud architect.
- 5+ year’s experience in information security, cloud security and architecture roles.
- Strong knowledge of security governance, risk and compliance frameworks (ISO 27001, NIST CSF/800‑53, NIS2, DORA).
- Strong communication skills and ability to work with senior stakeholders.
- Experience mentoring teams or influencing security decisions.
Required Technical Skills
- Deep hands‑on experience with GCP security services and GCP security best practices.
- Experience architecting secure multi‑project setups and identity boundaries.
Agentic AI Security
- Experience designing security for agent‑based AI systems and LLM‑integrated applications.
- Hands‑on experience with AI/LLM security controls (prompt security, model governance, secure APIs, orchestration security).
- AI‑specific threat modelling expertise.
Cloud & Security Architecture
- Strong cloud security background across AWS/Azure/GCP.
- Experience in secure design of:
- IAM
- Data protection and encryption
- Application and API security
- Knowledge of SIEM, IAM, CASB, container/Kubernetes security.
- Experience in Vibe coding, as well as technologies experience similar to Openclaw and Ollama
Certifications
- One or more of: CISA, CRISC, CISM, CISSP (required).
#J-18808-Ljbffr
Security Architect Consultant in Birmingham employer: NTT DATA, Inc.
NTT DATA is an exceptional employer that values innovation and collaboration, offering a dynamic work culture where employees can thrive. With a strong focus on professional development, you will have access to numerous growth opportunities while working remotely in the UK/Europe, allowing for a healthy work-life balance. Join us to be part of a supportive team that prioritises your success and well-being.