At a Glance
- Tasks: Design and implement security architecture for cutting-edge IT systems.
- Company: Global tech leader transforming the world with innovative solutions.
- Benefits: Flexible work options, tailored benefits, and continuous learning opportunities.
- Why this job: Join a diverse team making a real impact in cybersecurity.
- Qualifications: 5+ years in IT security, risk management, and cloud platforms.
- Other info: Inclusive culture with various support networks for all employees.
The predicted salary is between 43200 - 72000 £ per year.
The Security Architect will be responsible for the design, implementation and ongoing development of the security architecture of the client's IT systems. The Security Architect will draw upon Enterprise Security Architecture or Security Solutions Architecture to:
- Identify business objectives, user needs, risk appetite and cyber security obligations
- Identify vulnerabilities, perform threat modelling, undertake risk assessment, evaluate the effectiveness of security controls
- Verify and evidence alignment to 'Secure by Design' principles, corporate security policy/standards as well as industry recognised frameworks and best practice
What you'll be doing:
- Develop, deliver and continually enhance a coherent approach to the design of secure client end-to-end solutions
- Develop secure conceptual, logical and high level designs by identifying appropriate security controls to be embedded in solutions that meet business requirements whilst evidencing alignment to the target risk appetite.
- Own the design and be able to articulate and justify design recommendations at security architecture assurance gates
- Draft design documentation, options papers, risk assessments, stakeholder presentations and be able to effectively communicate these to both senior technical and non-technical stakeholders
- Contribute to a reference architecture of established patterns, principles and guidelines
- Research emerging technologies, new products and be able to position these in a coherent manner against the developing threat landscape and client risk appetite
- Ability to distil complex information and concepts into key discussion points that identifies a path to resolution rather than only the identification of challenges
- Contribute to the development of the Security Practice skills and capabilities to ensure consistent high quality of service delivery and expertise. Active coaching and mentoring of junior members of the team
- Leading in the development of collateral to support Security Consulting ‘go to market’ propositions and service offerings.
- Leading in the development and presentation of compelling client proposals collaborating with teams across our business.
- Strong stakeholder management and relationship building skills at senior levels that will enable consensus building in the shaping of secure client solutions
- Shaping, leading and delivering value through security advisory consultancy and through guiding secure transformational delivery engagements.
- Providing security expertise across security standards and accreditations, measure and control the effectiveness of the security controls framework and maintain the Information Security Management System.
- Deriving and delivering documented Information Security Management Plans which incorporate Regulatory, Legal and Compliance in relation to applicable security policies, standards and guidelines
- Assisting with the identification of identified risks and emerging cyber security vulnerabilities and threats. The subsequent analysis to quantify and lead risk mitigation plans
- Work with Service Management to ensure that partners and suppliers adhere to agreed standards, policies and verify/evidence appropriate compliance and security KPIs
- Work closely with 1st, 2nd and 3rd lines of defence on all matters relating to cyber security, information assurance, cyber risk, data privacy including regulatory and compliance considerations
- Lead the development and enhancement of governance, risk and compliance aligned to policy, standards and industry good practice
- Ensure that continuous assessment, identification, analysis and reporting of useful metrics to enable informed risk based decisions to be taken
- Constructively challenge established processes and controls to identify, recommend and facilitate continuous improvement, ensuring that all personnel (including senior stakeholders) understand their responsibilities in relation to security risk mitigation and remediation
- Review and verify that documentation relating to process and technical security controls are maintained
What experience you'll bring:
- Minimum of 5 years’ experience in a multi-tiered IT enterprise environment / Governance, Risk and Compliance role
- Minimum of 5 years’ experience in a Governance, Risk and Compliance role
- A track record of delivering security solutions for large-scale infrastructure, transformation or integration programmes
- Practical knowledge and understanding of industry security frameworks and guidance such as NIST CSF, NIST 800-53, NCSC CAF and other NCSC guidelines
- Good knowledge of networking (switching, routing, firewalls)
- Experience with the design concepts associated with adoption of Cloud platforms (AWS and/or Microsoft Azure)
- An understanding of the native security capabilities and good practice within Cloud platforms (AWS and/or Microsoft Azure)
- In-depth knowledge of modern security concepts, common attack vectors, malware, security analytics and threat intelligence.
- A good understanding of security testing and vulnerability management is important (including pen testing/ITHC, CVSS/CVE)
- Experience working with security standards such as ISO 27001, 27002, 27017, 27108 etc
DESIRABLE SKILLS AND EXPERIENCE
- CISSP, CISM, CCSP, CRISC or equivalent experience
- Good knowledge covering several of the following examples (this list is not exhaustive): AD, Cryptography, End User Computing, IAM, PKI, Server hardening, SIEM, SOAR, virtualisation (VMware)
- Participate in pre-sales tasks and perform ongoing support of delivery collateral.
- Familiarity with MITRE ATT&CK
- Familiarity with ITIL
We’re a business with a global reach that empowers local teams, and we undertake hugely exciting work that is genuinely changing the world. Our advanced portfolio of consulting, applications, business process, cloud, and infrastructure services will allow you to achieve great things by working with brilliant colleagues, and clients, on exciting projects. Our inclusive work environment prioritises mutual respect, accountability, and continuous learning for all our people. This approach fosters collaboration, well-being, growth, and agility, leading to a more diverse, innovative, and competitive organisation.
We offer a range of tailored benefits that support your physical, emotional, and financial wellbeing. Our Learning and Development team ensure that there are continuous growth and development opportunities for our people. We also offer the opportunity to have flexible work options.
We are an equal opportunities employer. We believe in the fair treatment of all our employees and commit to promoting equity and diversity in our employment practices. We are also a Disability Confident Committed Employer - we want to see every candidate performing at their best throughout the job application and interview process, if you require any reasonable adjustments during the recruitment process, please let us know and we look forward to hearing from you.
Security Architect in London employer: NTT DATA
Contact Detail:
NTT DATA Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Security Architect in London
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect with potential colleagues on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Prepare for interviews by researching the company and its security practices. Be ready to discuss how your experience aligns with their needs, especially around risk assessment and security architecture. Show them you’re not just a fit, but the perfect fit!
✨Tip Number 3
Practice your pitch! You’ll want to clearly articulate your design recommendations and how they align with business objectives. Mock interviews with friends or mentors can help you refine your delivery and boost your confidence.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining our team and contributing to our exciting projects.
We think you need these skills to ace Security Architect in London
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience in security architecture. Use keywords from the job description to show that you understand what we're looking for.
Showcase Your Skills: Don’t just list your qualifications; demonstrate how your skills align with our needs. For instance, if you have experience with NIST frameworks or cloud security, make it clear how you've applied this knowledge in past roles.
Be Clear and Concise: When drafting your application, keep it straightforward. Use bullet points for easy reading and ensure your key achievements stand out. We want to see your impact without wading through too much text!
Apply Through Our Website: We encourage you to submit your application directly through our website. This way, you’ll ensure it reaches us promptly and you can easily track your application status. Plus, it’s super easy!
How to prepare for a job interview at NTT DATA
✨Know Your Security Frameworks
Make sure you brush up on your knowledge of industry security frameworks like NIST CSF and ISO 27001. Be ready to discuss how you've applied these in past roles, as this will show your understanding of best practices and your ability to align with corporate security policies.
✨Articulate Your Design Process
Prepare to explain your approach to designing secure systems. Think about how you identify vulnerabilities and perform threat modelling. Being able to articulate your design recommendations clearly will demonstrate your expertise and confidence in security architecture.
✨Engage with Stakeholders
Since strong stakeholder management is key, practice how you'll communicate complex security concepts to both technical and non-technical audiences. Use examples from your experience where you've successfully built consensus or influenced decision-making.
✨Showcase Continuous Improvement Mindset
Be ready to discuss how you've challenged established processes for better security outcomes. Highlight any initiatives you've led that resulted in improved security measures or compliance, as this shows your proactive approach to risk management.