Lead Cloud Security Engineer

Lead Cloud Security Engineer

Full-Time 51600 - 58500 ÂŁ / year (est.) No home office possible
T

At a Glance

  • Tasks: Lead initiatives to secure cloud infrastructure and protect digital assets.
  • Company: Join The National Archives, a historic institution with a modern vision.
  • Benefits: Enjoy a generous benefits package, including pension and training opportunities.
  • Why this job: Make a real impact on national memory by safeguarding critical information.
  • Qualifications: Expertise in cloud security and hands-on engineering skills required.
  • Other info: Flexible working options available; dynamic environment with growth potential.

The predicted salary is between 51600 - 58500 ÂŁ per year.

As the living, growing home of our national story, The National Archives is already a special place to work. We’re an institution nearly 200 years old with a collection spanning 1,000 years of history. But it’s where we go next that makes things really interesting. In our strategic vision: Archives for Everyone, we set ourselves the challenge of becoming the 21st Century national archive – a different kind of cultural and heritage institution: Inclusive, Entrepreneurial, Disruptive. We won’t become this overnight. It will take time, focus, effort and daring. That’s where you come in. Because we can’t do this without you.

Our digital services support preservation and access at scale – and securing our systems means protecting history itself. We are seeking cyber professionals with hands‑on technical skills and a passion for protecting data and infrastructure that underpins national memory. Join us and be part of a unique, purposeful mission.

As the Lead Cloud Security Engineer, you will lead TNA wide initiatives to protect digital assets, data and cloud infrastructure from ever evolving threats. The role demands deep technical expertise, leadership in secure by design implementation and architecture governance, and the ability to influence decisions across departments and external suppliers. You will be accountable for the design, implementation and continuous improvement of multi‑cloud security frameworks (AWS, Azure and other environments), aligned with government standards and resilient to emerging risks. Your work protects critical information from malicious attacks, accidental loss and unauthorised access.

Reporting to the IT Security & Information Assurance Manager, you will own the “how” of secure cloud delivery across TNA – translating policy objectives into actionable technical standards, guardrails and patterns, and making the implementation decisions that ensure they are adopted effectively. You will chair a virtual Technical Design Authority (TDA) to embed secure by design practices across AWS, Azure and other cloud environments, define technical standards and roadmaps to reflect the desired cyber security posture and remain hands‑on engineering solutions, codifying controls and leading complex investigations. Through the TDA you hold decision rights to set guardrails and approve exceptions across directorates, combining technical authority, governance leadership and practical delivery to keep TNA’s systems secure, compliant and cost‑efficient.

As Lead Cloud Security Engineer, you will spearhead strategic decision‑making and shape the overall security posture of our cloud infrastructure. You’ll collaborate closely with cross‑functional teams across The National Archives to define security architecture, evaluate emerging technologies, and establish work practices and technologies that align with business objectives and regulatory requirements. Leveraging deep expertise in cloud platforms and threat landscapes, you’ll guide the selection and implementation of security controls, drive risk assessments, and lead incident response planning. Your leadership will ensure that security is embedded into every stage of cloud adoption and operations, fostering a culture of proactive defence and continuous improvement.

This is a full‑time post. However, requests for part‑time working, flexible working and job share will be considered, taking into account at all times the operational needs of the Department. A combination of onsite and home working is available and applicants should be able to regularly travel to our Kew site for a minimum of 60% of their work time.

Application Process

  • Interviews will be held on‑site at The National Archives in Kew.
  • We ask all applicants to submit work history details and a personal statement, not exceeding 1200 words.
  • Selection for interview will be based on the ‘essential’ requirements in the job description below so please ensure that your statement demonstrates in detail how you meet these requirements.

SC clearance/willingness to obtain SC clearance will be required for this role. This requires candidates to have been resident in the UK for at least the past three years. Please do not apply if you have been resident in the UK for less than three years as your application will be rejected.

Role and Responsibilities

  • Secure Design & Implementation: Define and enforce technical standards, roadmaps and guardrails, reference architectures and patterns for secure cloud delivery across AWS, Azure, on‑premises systems and SaaS platforms. Implement and maintain policy as code and IaC controls (e.g., Terraform); integrate security into CI/CD pipelines. Harden IAM, tune CSPM policies, develop Sentinel and Wiz queries, and lead complex incident response, automation and root cause remediation.
  • Governance & Influence: Chair the virtual TDA – approve guardrails and exceptions; standardise threat‑modeling and design review processes. Influence architectural decisions across directorates; advise senior stakeholders on risk and technical trade‑offs.
  • Cost Efficiency: Drive cost efficiencies across the security tooling portfolio (e.g., Wiz, Microsoft Defender/Sentinel, CI/CD security tools): optimise licensing, remove duplication, benchmark value and recommend investment/disinvestment options to the Head of IT Operations (budget holder).
  • Leadership & Development: Provide technical and thought leadership to both internal and external stakeholders and mentoring across teams; build security engineering communities of practice. Influence and negotiate with technical and business stakeholders and drive adoption of good security practices across the organisation and suppliers.

Person Specification

Essential criteria:
  • Significant expert knowledge of cloud security in either AWS or Azure, with proven experience leading cross‑organisation security initiatives.
  • Demonstrable experience in architecture governance (guardrails, patterns, exceptions) and standardising threat modelling.
  • Strong hands‑on engineering skills: IaC, CI/CD security, IAM hardening, CSPM tuning, incident response.
  • Ability to drive cost efficiencies and make evidence‑based recommendations.
  • Technical expertise in the following tech stack: AWS, Azure, Microsoft 365, GitHub, Kubernetes, Terraform, Linux, JAMF, Sentinel and Defender for Endpoint.
  • Experienced in excellent communication and able to influence up to senior leadership, delivering complex technical concepts and summarising complicated events to senior stakeholders up to and including board level.
Desirable criteria:
  • Relevant certifications (AWS/Azure Security, CISSP, CCSP).
  • Experience of external engagement in security communities.

Benefits

Generous benefits package, including pension, sports and social club facilities, onsite gym, discounted rates at our on‑site cafe and opportunities for training and development. Annual leave entitlement of 25 days per calendar year (rising to 26 days after 2 years’ service, and incrementally to 30 days after six years) and 10½ days public and privilege holidays per annum.

Selection process details

Reasonable adjustments: If a person with disabilities is put at a substantial disadvantage compared to a non‑disabled person, we have a duty to make reasonable changes to our processes. If you need a change to be made so that you can make your application, you should contact The National Archives via careers@nationalarchives.gov.uk as soon as possible before the closing date to discuss your needs.

Security: Successful candidates must pass a disclosure and barring security check. People working with government assets must complete basic personnel security standard checks.

Nationality requirements: This job is broadly open to the following groups: UK nationals, Nationals of Commonwealth countries who have the right to work in the UK, Nationals of the Republic of Ireland, Nationals from the EU, EEA or Switzerland with settled or pre‑settled status or who apply for either status by the deadline of the European Union Settlement Scheme (EUSS).

Working for the Civil Service: The Civil Service Code sets out the standards of behaviour expected of civil servants. We recruit by merit on the basis of fair and open competition, as outlined in the Civil Service Commission's recruitment principles. The Civil Service embraces diversity and promotes equal opportunities.

Contact point for applicants: Name: The National Archives Recruitment Team Email: careers@nationalarchives.gov.uk

Lead Cloud Security Engineer employer: The National Archives

The National Archives is an exceptional employer, offering a unique opportunity to contribute to the preservation of national history while working in a collaborative and inclusive environment. With a strong commitment to employee development, generous benefits including a comprehensive pension scheme, and flexible working arrangements, staff are empowered to thrive both personally and professionally. Located in Kew, employees enjoy access to beautiful surroundings and a vibrant community dedicated to cultural heritage and innovation.
T

Contact Detail:

The National Archives Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Lead Cloud Security Engineer

✨Tip Number 1

Network like a pro! Reach out to current employees at The National Archives on LinkedIn or other platforms. Ask them about their experiences and any tips they might have for the interview process. This insider info can give you a leg up!

✨Tip Number 2

Prepare for the interview by diving deep into the role of Lead Cloud Security Engineer. Brush up on your knowledge of AWS, Azure, and security frameworks. Be ready to discuss how you can contribute to making TNA a secure and innovative institution.

✨Tip Number 3

Showcase your hands-on skills! During the interview, share specific examples of past projects where you implemented cloud security measures. Highlight your problem-solving abilities and how you’ve tackled complex security challenges.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets the attention it deserves. Plus, it shows you’re serious about joining The National Archives and being part of their mission.

We think you need these skills to ace Lead Cloud Security Engineer

Cloud Security
AWS
Azure
Infrastructure as Code (IaC)
Continuous Integration/Continuous Deployment (CI/CD)
Identity and Access Management (IAM) Hardening
Cloud Security Posture Management (CSPM)
Incident Response
Threat Modelling
Technical Leadership
Governance and Compliance
Cost Efficiency Analysis
Communication Skills
Stakeholder Engagement
Mentoring

Some tips for your application 🫡

Show Your Passion: When writing your personal statement, let your enthusiasm for cloud security shine through! We want to see how your passion aligns with our mission at The National Archives. Make it clear why you’re excited about protecting digital assets and data.

Tailor Your Experience: Make sure to highlight your relevant experience in cloud security, especially with AWS or Azure. We’re looking for specific examples that demonstrate your hands-on skills and leadership in secure design implementation. Don’t just list your roles; tell us how you made an impact!

Be Clear and Concise: With a 1200-word limit, every word counts! Keep your statements focused and to the point. Use clear language to explain your technical expertise and how it relates to the role. We appreciate straightforward communication that gets right to the heart of your qualifications.

Apply Through Our Website: Don’t forget to submit your application through our website! It’s the best way to ensure we receive all your details correctly. Plus, it shows you’re keen on joining our team at The National Archives. We can’t wait to hear from you!

How to prepare for a job interview at The National Archives

✨Know Your Cloud Security Inside Out

Make sure you brush up on your knowledge of cloud security, especially in AWS and Azure. Be ready to discuss specific frameworks and standards you've worked with, as well as how you've implemented secure by design practices in previous roles.

✨Showcase Your Leadership Skills

As a Lead Cloud Security Engineer, you'll need to demonstrate your ability to lead cross-functional teams. Prepare examples of how you've influenced architectural decisions or chaired technical discussions, and be ready to explain how you foster collaboration and drive security initiatives.

✨Prepare for Technical Questions

Expect in-depth technical questions about incident response, IAM hardening, and CI/CD security. Brush up on your hands-on engineering skills and be prepared to discuss specific tools and technologies you've used, like Terraform or Kubernetes, and how they relate to the role.

✨Align with Their Vision

The National Archives is looking for someone who can help them become a 21st Century national archive. Familiarise yourself with their strategic vision, 'Archives for Everyone', and think about how your experience and ideas can contribute to this goal. Show them you're not just a fit for the role, but also for their mission.

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

T
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>