- Company Name
- Spire Healthcare Group plc
- Job Title
- Senior Technical Architect - Security (Engineering)
- Job Description
-
**Job Title:**
Senior Technical Architect – Security (Engineering)
**Role Summary:**
Lead security architect responsible for designing, implementing, and maintaining enterprise‑wide security solutions across Microsoft 365, Azure, endpoints, and network environments. Provides technical leadership, drives security improvements, ensures regulatory compliance, and mentors IT staff while supporting both BAU and project initiatives within a large healthcare organization.
**Expectations:**
- Define and execute secure architecture aligned with corporate security principles.
- Collaborate with IT architecture teams to embed security into all solutions.
- Maintain deep knowledge of the organization’s security product portfolio and promote best‑fit solutions.
- Deliver consultancy, mentoring, and guidance to raise security competency across IT.
- Ensure controls meet ISO 27001, Cyber Essentials Plus, and other regulatory frameworks.
- Act as a key member of the Incident Response team alongside an external SOC.
**Key Responsibilities:**
- Architect and lead implementation of security improvement initiatives.
- Design secure solutions in partnership with other IT architecture groups.
- Administer and enforce security policies for Microsoft 365 (SharePoint, Exchange, Intune) and endpoint protection (Microsoft Defender, EDR, Purview).
- Develop and maintain security controls, including SIEM, DLP, firewalls, IDAM/PAM, and vulnerability management.
- Provide soft‑consultancy, mentoring, and training to IT teams on security best practices.
- Participate in incident response, threat hunting, and coordination with the managed SOC.
- Continuously evaluate and enhance knowledge of security products, technologies, and industry trends.
**Required Skills:**
- Enterprise security architecture and implementation experience.
- Strong knowledge of SIEM, antivirus, DLP, firewalls, cloud security (Azure), IDAM/PAM, EDR, vulnerability scanning tools.
- Proficiency with Microsoft 365 security (SharePoint, Exchange, Intune) and endpoint security suites.
- Windows Server administration and networking fundamentals.
- Incident response planning and execution.
- Ability to design secure networks and enforce security policies.
- Excellent communication, stakeholder management, and mentorship abilities.
- Experience in multi‑supplier, multi‑platform environments.
**Required Education & Certifications:**
- ITIL qualification (mandatory).
- Relevant degree in IT, Computer Science, or Information Security – desirable but not essential.
- Preferred security certifications: CISSP, CISM, CCSP, CISA, SSCP, ISO 27001 Lead Auditor, Cisco security certifications, SANS certifications.