Software Security Architect in Cambridge

Software Security Architect in Cambridge

Cambridge Full-Time On-site
S

07th October, 2026You will provide the technical leadership that turns security objectives into practical architecture, engineering standards and secure products. Working throughout the product lifecycle, you will collaborate with engineering teams to ensure security is considered from initial concept and design through development, verification, release and ongoing maintenance. If you have a strong background in secure device architecture and enjoy combining strategic ownership with hands-on technical influence, this is an opportunity to make a significant impact within an innovative technology company based in Waterbeach, Cambridge.

Due to the nature of our UK customer base, the successful candidate may be expected to complete UK Security Clearance (SC) vetting.

Role: Take ownership for the definition, delivery and continuous improvement of software security across the full product line. The Security Architect turns security objectives into practical architecture, engineering controls and evidence, ensuring that product teams build, verify, release and maintain secure software throughout the product lifecycle.

Key accountabilities: Own product-line software securityCreate and maintain the software security strategy, target state and prioritized roadmap for the product line.

Be accountable for security architecture decisions and for the consistent application of security requirements across products, platforms and shared components.

Maintain a product-line view of software security risk, technical debt, dependencies and remediation commitments, escalating material gaps with clear options and recommendations.

Define what good looks like through measurable controls, assurance evidence and acceptance criteria.

Embed security into deliveryIntegrate security requirements and threat modelling into product planning, architecture, design and backlog refinement.

Establish proportionate security gates across implementation, code review, build, test, release and maintenance activities.

Partner with engineering teams to ensure vulnerabilities are triaged, owned and resolved according to risk, with exceptions explicitly documented and approved.

Ensure security is planned and delivered as part of normal product development rather than treated as a separate compliance activity.

Lead secure architecture and engineering practiceProvide authoritative guidance on secure design, trust boundaries, identity, authentication, authorization, cryptography, data protection, secure communications and platform hardening.

Define reusable patterns, reference architectures, coding standards and engineering guardrails that enable teams to deliver securely and efficiently.

Review significant designs and changes, challenging assumptions and driving decisions to resolution.

Guide the selection and effective use of security tooling within development and CI/CD workflows.

Assure releases and the product lifecycleDefine the security evidence required to support release decisions and product assurance.

Coordinate security testing, vulnerability assessment and remediation across products and releases.

Ensure software security considerations are addressed through deployment, update, support, incident response and end-of-life activities.

Provide a clear security position for major releases, including residual risks, approved exceptions and recommended actions.

Ensure product security architecture, engineering controls and lifecycle processes support compliance with the EU Cyber Resilience Act (CRA).Influence, govern and improveAct as the software security authority for product and engineering stakeholders, translating risk into clear delivery decisions.

Build security capability across engineering through coaching, design reviews, practical guidance and communities of practice.

Work with product, systems, quality, compliance and operational stakeholders to align software security with wider product obligations.

Use lessons from vulnerabilities, incidents, testing and assurance activity to improve standards, controls and engineering practice.

What you need to succeed: QualificationsA relevant technical degree.

Experience and SkillsDemonstrable experience owning software or product security across multiple teams, products or platforms.

Strong software architecture and engineering background, with practical experience delivering security controls in complex products.

Deep understanding of secure development lifecycle practices, threat modelling, secure design, vulnerability management and security testing.

Experience embedding automated security controls and evidence into build, test and CI/CD workflows.

Ability to assess technical risk, make proportionate decisions and communicate trade-offs to engineering and business stakeholders.

Credibility to influence senior technical leaders while remaining hands-on enough to guide teams through difficult design and delivery decisions.

Clear written and verbal communication, with a pragmatic approach that enables delivery while protecting the organisation and its customers.

Nice to haveExperience with embedded, connected, mobile or mission-critical products.

Knowledge of relevant product security standards, regulatory expectations or assurance frameworks.

Experience of incident response coordinated vulnerability disclosure and security maintenance across supported product versions.

Relevant security or architecture certification, supported by substantial practical experience.

Experience of Android and/or Embedded Linux system architecture.

Software Security Architect in Cambridge employer: Sepura

At Sepura Ltd., we pride ourselves on being an exceptional employer, offering a dynamic work culture that fosters innovation and collaboration. Located in the vibrant area of Waterbeach, Cambridge, our team enjoys access to cutting-edge technology and opportunities for professional growth, all while contributing to mission-critical communications that make a real difference globally. Join us to be part of a supportive environment where your expertise in hardware engineering will be valued and your career can thrive.

S

Contact Details:

Sepura Recruitment Team