At a Glance
- Tasks: Lead security architecture strategy and ensure secure design across digital platforms.
- Company: Join the UK's largest water and wastewater company, making a real impact.
- Benefits: Competitive salary, generous leave, pension scheme, and private healthcare.
- Why this job: Shape the future of security in a critical infrastructure environment.
- Qualifications: Proven leadership in security architecture and deep knowledge of cyber security.
- Other info: Flexible working arrangements and meaningful career opportunities await you.
The predicted salary is between 84000 - 126000 £ per year.
We’re looking for a Head of Security Architecture to be the strategic authority for security-by-design across Digital. Reporting to the Chief Information Security Officer, this role leads the definition, development and execution of our security architecture strategy, ensuring that all platforms, technologies and services are designed, delivered and operated securely.
As a key member of the Digital Extended Leadership Team, you’ll provide influential leadership on security risk, architectural direction and the secure enablement of our digital ambitions — balancing innovation with resilience in a complex, critical-infrastructure environment.
What you’ll be doing as the Head of Security Architecture
- Security Architecture Leadership
- Own, define and continuously evolve the Security Architecture Strategy and its supporting frameworks.
- Embed secure-by-design principles across Digital, ensuring security requirements are incorporated through delivery and into operations.
- Lead the development, governance and optimisation of security controls across all programs, ensuring they are effective, measurable and aligned to recognised industry frameworks and regulatory expectations.
- Oversee the integration of threat modelling, risk assessment and secure design principles into Digital programmes, projects and service lifecycles.
- Strategic Influence & Cross Digital Collaboration
- Act as a senior strategic advisor within the Extended Leadership Team, advocating for security informed decision making and helping shape Digital’s technology direction.
- Build strong relationships with Enterprise Architecture, Enterprise Security Architecture, Engineering, Delivery, Operations and business leaders to ensure security architecture is understood, adopted and aligned to organisational objectives.
- Provide architectural steer and security assurance into major transformation initiatives, technology roadmaps, procurement activity and third-party engagements.
- Technology and Information Security and Standards
- Ensure technical standards align to and address Information Security and Cyber requirements, controls and strategy.
- Support and guide the development and maintenance of security architecture patterns, standards and reference models.
- Support and guide the evaluation and selection of security technologies, ensuring they integrate effectively into the wider architecture landscape.
- Ensure the organisation’s security architecture remains current with evolving threats, technologies and industry practices.
- Risk Management & Control Assurance
- Oversee and enhance processes for risk-based architecture decision making, ensuring transparency and accountability across Digital.
- Drive the assessment of control effectiveness and lead architectural strategies to address control gaps, vulnerabilities and emerging threats.
- Partner closely with Information Security Governance, Cyber Operations, Security Engineering and other teams to provide holistic risk visibility across Digital services.
- Leadership & Team Development
- Lead, mentor and inspire the security architecture team, cultivating technical excellence, critical thinking and a collaborative culture.
- Demonstrate visible personal leadership, modelling the behaviours expected across Digital and championing a mature, business aligned security culture.
- Build capability across Digital by promoting knowledge sharing, architectural consistency and secure design thinking.
Base location – Hybrid – Clear Water Court Reading
Working hours – 36 hours
Necessary requirements for the role – Security Clearance is required (must be completed prior to start date)
What you should bring to the role
- Proven leadership in security architecture within a complex enterprise environment
- Experience in critical infrastructure, utilities or the public sector
- Deep, holistic knowledge of cyber / information security
- Strong understanding of secure design, threat modelling, cloud and on-prem architectures, identity platforms
- Demonstrated ability to influence senior stakeholders and lead teams
Technical Skills
- Strong familiarity with frameworks such as NIST, ISO 27001, SABSA, TOGAF
- Broad experience across cyber security domains (e.g. IAM/IDAM)
Extra qualities that would be a great fit for our team:
- Experience working with vendors, procurement and contract management
- Experience supporting regulatory and compliance frameworks (e.g. SEMD, CAF)
- Relevant degree and certifications (CISSP, CISM, CCSP, SABSA, TOGAF)
What’s in it for you?
- Competitive salary of up to £105,000 per annum depending on experience
- Annual Leave - 26 days holiday per year increasing to 30 with the length of service (plus bank holidays)
- Car Allowance
- Performance-related pay plan directly linked to company performance measures and targets
- Generous Pension Scheme through AON
- Private Medical Health Care
- Access to lots of benefits to help you take care of you and your family’s health and wellbeing, and your finances – from annual health MOTs and access to physiotherapy and counselling, to Cycle to Work schemes, shopping vouchers and life assurance.
We’re the UK’s largest water and wastewater company, with more than 16 million customers relying on us every day to supply water for their taps and toilets. We want to build a better future for all, helping our customers, communities, people, and the planet to thrive.
We’re committed to being a great, diverse, and inclusive place to work. We welcome applications from everyone and want to ensure you feel supported throughout the recruitment process. If you need any adjustments, whether that’s extra time, accessible formats, or anything else just let us know, we’re here to help and support.
Head of Security Architecture - Reading, Berkshire employer: Thames Water
Contact Detail:
Thames Water Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Head of Security Architecture - Reading, Berkshire
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the industry. Attend meetups, webinars, or even local events. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Show off your expertise! When you get the chance to chat with potential employers, don’t hold back on sharing your knowledge about security architecture. Bring up relevant projects you've worked on and how you tackled challenges—this will make you stand out.
✨Tip Number 3
Prepare for interviews by researching the company’s current security practices. Tailor your answers to show how your experience aligns with their needs. This shows you’re not just interested in any job, but specifically in helping them achieve their security goals.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who are proactive about their job search. So, hit that apply button and let’s get you on board!
We think you need these skills to ace Head of Security Architecture - Reading, Berkshire
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter for the Head of Security Architecture role. Highlight your experience in security architecture and how it aligns with our strategic goals at StudySmarter.
Showcase Your Leadership Skills: We want to see your leadership style! Share examples of how you've led teams and influenced stakeholders in previous roles, especially in complex environments like critical infrastructure.
Be Clear and Concise: Keep your application straightforward and to the point. Use clear language to describe your achievements and experiences, making it easy for us to see why you’re a great fit for the role.
Apply Through Our Website: Don’t forget to submit your application through our website! It’s the best way for us to receive your details and ensures you’re considered for the position as soon as possible.
How to prepare for a job interview at Thames Water
✨Know Your Security Frameworks
Familiarise yourself with key frameworks like NIST, ISO 27001, and SABSA. Be ready to discuss how these frameworks can be applied in the role of Head of Security Architecture, especially in relation to critical infrastructure.
✨Showcase Your Leadership Skills
Prepare examples that demonstrate your leadership experience in security architecture. Highlight how you've influenced senior stakeholders and led teams in previous roles, as this will be crucial for the position.
✨Understand the Business Context
Research Thames Water's mission and values. Be prepared to explain how your security architecture strategies can align with their goals of providing safe water and supporting communities, showcasing your understanding of the broader impact of your work.
✨Prepare for Technical Questions
Expect technical questions related to secure design principles, threat modelling, and risk management. Brush up on your knowledge of cloud and on-prem architectures, and be ready to discuss how you would integrate security into digital programmes.