- Company Name
- i-confidential
- Job Title
- Security Architect
- Job Description
-
Job title: Security Architect
Role Summary
Design, author and govern end‑to‑end network and infrastructure security architectures for a financial services client, ensuring alignment with functional and non‑functional business requirements, industry standards and regulatory controls. Provide technical leadership, high‑level design artefacts, and governance oversight throughout the architecture lifecycle.
Expactations
- Deliver complete high‑level design documentation, architecture patterns, decision records, and risk logs (securely, on time).
- Publish new architecture patterns, technical risks, issues, and deviations when required.
- Maintain, extend, and re‑platform an Azure‑hosted web application that manages firewall rule recertification for CheckPoint, Illumio and Fortinet, supporting WAF, network segmentation, and proxy capabilities.
- Influence technical design authorities and business stakeholders to secure solutions.
- Lead investigations of control gaps, remediation plans and residual risk assessments for local and national programmes.
Key Responsibilities
- Create and publish high‑level network and infrastructure security designs (firewalls, WAF, SDN segmentation, IDS/IPS, proxies, NAC).
- Architect features for web application upgrades, including WAF, network segmentation, proxy capabilities and infrastructure migration.
- Provide technical expertise during large‑scale IT transformation programmes.
- Coordinate design authority presentations, peer reviews and governance approvals.
- Ensure solutions meet security bases, config baselines, HA, DR, and compliance requirements.
- Identify and mitigate technical and project risks, mapping design decisions to risk outcomes.
- Act as liaison between cybersecurity services and technical design authorities, translating business and security needs.
- Maintain artefacts in Confluence, manage Jira for tasks, and model in BizzDesign, Archi or UML as required.
Required Skills
- Deep technical knowledge of network security controls: firewalls (CheckPoint, Illumio, Fortinet), WAF, software‑defined segmentation, IDS/IPS, proxies, NAC.
- Experience with secure protocols (TLS/SSL, IPsec, SSH) and secure baselining.
- Proficiency in traffic analysis, anomaly detection, and network policy management.
- Expertise in disaster recovery, redundancy, high‑availability design.
- Strong architecture and design skills: BizzDesign, Archi, UML, Confluence and Jira.
- Ability to manage separation of control, design authority, and governance.
- Effective communication with non‑security SMEs, business leaders, and technical teams.
- Proven record in operational and transformation cybersecurity roles within large programmes.
Required Education & Certifications
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent professional experience).
- Relevant certifications such as CISSP, CISM, CCSP, or vendor‑specific (CheckPoint, Illumint, Fortinet) preferred.
Manchester, United kingdom
Hybrid
24-12-2025