Senior Security Architect
Senior Security Architect

Senior Security Architect

Full-Time 80000 - 100000 ÂŁ / year (est.) No home office possible
Ohme

At a Glance

  • Tasks: Lead security architecture and embed secure practices across the organisation's tech landscape.
  • Company: Join a fast-paced scale-up with global ambitions and a passion for sustainability.
  • Benefits: Competitive salary, private health insurance, pension scheme, and flexible working options.
  • Other info: Diversity, equity, and inclusion are at the heart of our culture.
  • Why this job: Be the go-to security expert and shape the future of security in a growing tech company.
  • Qualifications: Proven experience in security architecture and deep AWS security expertise required.

The predicted salary is between 80000 - 100000 ÂŁ per year.

We are looking for an experienced Security Architect to join our technology leadership team as the organisation’s senior security authority. Reporting directly to the CIO, you will define and own the security architecture framework, work hands‑on alongside engineering teams, and provide governance and expert review of the way security is designed and implemented across the business. This is a senior individual contributor role – you will be the go‑to security expert in the organisation, combining deep technical capability with the ability to communicate clearly at all levels, from engineers to board. You will help establish a culture of security by design, embedding best practice into every layer of the technology estate.

Key Responsibilities

  • Security Architecture & Engineering
  • Define and maintain the organisation‑wide security architecture framework, covering cloud, application, network, and data security.
  • Work directly alongside engineering teams to embed secure‑by‑design principles into system design, infrastructure, and delivery pipelines (DevSecOps).
  • Lead security architecture reviews for new projects, platforms, and third‑party integrations.
  • Own the AWS security posture – including IAM/SCPs, Security Hub, GuardDuty, CloudTrail, and Config – ensuring controls are robust, scalable, and well‑governed.
  • Define and enforce standards for identity and access management, secrets management, encryption, and network segmentation.
  • Evaluate and recommend security tooling and services to strengthen the organisation’s security capabilities.
  • Governance & Compliance
    • Use ISO 27001 and related standards as the contextual framework for security governance, risk management, and policy development.
    • Develop and maintain security policies, standards, and guidelines that are practical, enforceable, and aligned to the business risk appetite.
    • Conduct regular risk assessments, threat modelling, and security reviews across the technology estate.
    • Support audit, compliance, and assurance activities, including engagement with external assessors where required.
    • Track and manage the security risk register, reporting on posture and remediation progress to the CIO and leadership team.
  • Communication & Stakeholder Engagement
    • Act as the primary security authority for internal stakeholders – translating complex security concepts for non‑technical audiences.
    • Build strong relationships with engineering, product, and operations teams to ensure security is seen as an enabler, not a blocker.
    • Contribute to board‑level and executive reporting on security posture, risk, and strategic initiatives.
    • Stay current with the evolving threat landscape and emerging security technologies, sharing relevant insight across the organisation.
  • AI Security & Governance
    • Define and maintain a pragmatic AI security governance framework covering the adoption of large language model (LLM) services from providers such as Anthropic and OpenAI, AI‑powered tooling, and agentic workflow platforms.
    • Identify, assess, and clearly communicate the security risks specific to AI systems – including prompt injection, tool misuse, data exfiltration via model inputs, insecure agentic behaviour, and supply chain risk from third‑party AI providers.
    • Establish and enforce security standards for integrating LLM‑based services into internal systems, covering API key management, data classification, model context boundaries, and output validation.
    • Define governance standards for Model Context Protocol (MCP) server deployments, ensuring that AI agents operating with tool access are subject to appropriate authentication, authorisation, and audit controls.
    • Champion a balanced approach to AI security – enabling engineering and product teams to adopt AI capabilities at pace while ensuring risk is understood, quantified, and appropriately managed.
    • Embed AI security review into delivery and procurement processes, ensuring new AI integrations receive proportionate threat modelling without creating unnecessary friction for teams.

    What We’re Looking For

    • Demonstrable experience as a Security Architect or senior security engineer, with a strong track record of hands‑on technical delivery.
    • Defining SIEM Platform configuration to provide a proactive orchestration, alerting and response approach to security across the organisation.
    • Deep expertise in AWS security services – IAM, SCPs, Security Hub, GuardDuty, CloudTrail, AWS Config, KMS, and related services.
    • A working knowledge of Azure Cloud services, including EntraID, Azure Portal, and ARM.
    • Experience embedding DevSecOps practices into CI/CD pipelines – SAST/DAST tooling, container security, secrets management, and infrastructure‑as‑code security.
    • Strong knowledge of ISO 27001 and the ability to apply governance frameworks pragmatically in a fast‑moving technology environment.
    • Experience conducting threat modelling, security architecture reviews, and risk assessments.
    • Excellent communication skills – able to present security concepts clearly to both technical and non‑technical audiences.
    • Comfortable operating as a senior individual contributor without direct reports.
    • A clear understanding of the specific security challenges presented by AI and LLM systems – including agentic architectures, prompt injection, third‑party model risk, and the data handling implications of AI pipelines – combined with the judgment to develop governance that enables innovation rather than blocking it.
    • AWS Certified Security – Specialty certification (or equivalent).
    • Experience with Microsoft Sentinel or an equivalent SIEM platform.
    • Experience with zero‑trust architecture and modern identity frameworks (OIDC, OAuth 2.0).
    • Familiarity with SOC 2, Cyber Essentials Plus, or NIST frameworks.
    • Experience working in a scale‑up or high‑growth technology environment.
    • Familiarity with AI provider security models and trust frameworks (e.g. Anthropic, OpenAI), and awareness of emerging AI governance standards including the OWASP LLM Top 10 and NIST AI RMF.
    • Hands‑on experience with Model Context Protocol (MCP), agentic AI orchestration, or AI automation platforms, with a practical understanding of the authentication, authorisation, and access control implications of these systems.

    You’ll get to work in a fast‑paced and rapidly growing scale‑up with global ambitions that is cutting edge, passionate about sustainability and seeks to make the world a better place.

    Our benefits

    • Competitive salary and bonus
    • London Office – 4 days a week in our London office and 1 day remote
    • Direct access and influence at CIO level from day one.
    • The opportunity to shape and own the security function in a growing technology organisation.
    • Private Health Insurance
    • Pension Scheme
    • Life Assurance Scheme with death in service benefit of 4x salary
    • Income Protection Scheme for long term illness
    • Ride to Work Scheme
    • Payroll Giving Scheme
    • Season Ticket Loan to spread cost of travel over 12 months
    • Eye Test every 2 years

    Ohme is an equal opportunity employer. Diversity, Equity and Inclusion are at the heart of what we do and we encourage a culture where everyone can be themselves at work. We actively seek out a diverse range of talent and our policies ensure that every job application and employee is treated fairly, with equal opportunity to succeed and to feel included.

    Senior Security Architect employer: Ohme

    At Ohme, we pride ourselves on being an exceptional employer, offering a dynamic work environment in the heart of London where innovation meets sustainability. As a Senior Security Architect, you will have direct access to the CIO and the opportunity to shape our security function, all while enjoying a competitive salary, comprehensive benefits, and a culture that champions diversity, equity, and inclusion. Join us in making a meaningful impact as we navigate the cutting-edge of technology and security together.
    Ohme

    Contact Detail:

    Ohme Recruiting Team

    StudySmarter Expert Advice 🤫

    We think this is how you could land Senior Security Architect

    ✨Tip Number 1

    Network like a pro! Reach out to your connections in the industry, attend meetups, and engage in online forums. The more people you know, the better your chances of landing that Senior Security Architect role.

    ✨Tip Number 2

    Show off your skills! Create a portfolio or a personal website showcasing your projects, especially those related to security architecture. This gives potential employers a taste of what you can bring to the table.

    ✨Tip Number 3

    Prepare for interviews by brushing up on your communication skills. You’ll need to explain complex security concepts clearly to both technical and non-technical audiences, so practice makes perfect!

    ✨Tip Number 4

    Don’t forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, we love seeing candidates who are proactive about their job search.

    We think you need these skills to ace Senior Security Architect

    Security Architecture
    AWS Security Services
    ISO 27001
    DevSecOps
    Risk Assessment
    Threat Modelling
    Communication Skills
    Governance Frameworks
    SIEM Platform Configuration
    Zero-Trust Architecture
    AI Security Governance
    Identity and Access Management
    Data Security
    Cloud Security
    Hands-on Technical Delivery

    Some tips for your application 🫡

    Tailor Your CV: Make sure your CV is tailored to the Senior Security Architect role. Highlight your experience with AWS security services and any hands-on technical delivery you've done. We want to see how your skills align with our needs!

    Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about security architecture and how you can contribute to our culture of security by design. Keep it engaging and relevant to the job description.

    Showcase Your Communication Skills: Since you'll be translating complex security concepts for non-technical audiences, make sure to demonstrate your communication skills in your application. Use clear language and examples that show you can bridge the gap between tech and business.

    Apply Through Our Website: We encourage you to apply through our website for the best chance of getting noticed. It helps us keep track of applications and ensures you’re considered for this exciting opportunity to shape our security function!

    How to prepare for a job interview at Ohme

    ✨Know Your Security Frameworks

    Make sure you’re well-versed in security frameworks like ISO 27001. Be ready to discuss how you’ve applied these standards in previous roles, especially in governance and risk management. This will show that you can align security practices with business objectives.

    ✨Demonstrate Hands-On Experience

    Prepare to share specific examples of your hands-on work with AWS security services and DevSecOps practices. Highlight your experience with IAM, Security Hub, and threat modelling. Real-world scenarios will help illustrate your technical capabilities and problem-solving skills.

    ✨Communicate Clearly

    Since you’ll be the go-to security expert, practice explaining complex security concepts in simple terms. Think about how you would present these ideas to non-technical stakeholders. Clear communication is key to building relationships across teams.

    ✨Stay Current with AI Security Trends

    Given the focus on AI security, brush up on the latest trends and challenges in this area. Be prepared to discuss how you would approach risks associated with AI systems, such as prompt injection and data handling. Showing that you’re proactive about emerging threats will set you apart.

    Senior Security Architect
    Ohme

    Land your dream job quicker with Premium

    You’re marked as a top applicant with our partner companies
    Individual CV and cover letter feedback including tailoring to specific job roles
    Be among the first applications for new jobs with our AI application
    1:1 support and career advice from our career coaches
    Go Premium

    Money-back if you don't land a job in 6-months

    >