Security Architect
Job description
Original text imported from Reed
Description
Security Architect
Location: Huntingdon
UNLEASH YOUR POTENTIAL
At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers’ success. We empower our teams in the UK to address some of the most complex problems in defence, government, safety and security, and transportation. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community.
We are seeking an experienced Cyber Security Architect to be based at our customer site in Huntingdon, Cambridgeshire, with occasional travel to other UK locations. You will work alongside engineering and delivery teams to design, assure, and maintain a strong and resilient cyber security posture across the customer estate.
You will be responsible for ensuring that solution security designs meet all functional and non-functional security requirements, delivering the required level of assurance to the client.
This will be achieved through the application of Secure by Design (SbD) principles, aligned to HMG standards (including MOD-specific JSPs) and frameworks such as NIST CSF and RMF. You will also take ownership of design feasibility, support secure delivery, and lead service acceptance reviews and approvals, ensuring all security artefacts meet the required standard
Are you ready for your next career challenge?
You will work closely with security design partners across the programme, including customer and supplier representatives, as well as internal engineering and service teams. You will ensure the establishment and ongoing maintenance of an effective and efficient security architecture, capable of adapting to evolving customer requirements, legislation, and Secure by Design (SbD) principles across the programme lifecycle. Within the programme, you will report to the Cyber Security Team Lead, taking responsibility for developing and delivering the relevant security architecture components while maintaining an understanding of the wider solution. You will support activities spanning new system implementation and the transformation of existing services.
You will have a strong understanding of cyber risk and proportionate risk treatment approaches, with the ability to clearly articulate risk and its management to a range of stakeholders. You will be experienced in securing highly sensitive systems and applying appropriate controls within government environments.
You will be responsible for developing both high-level and low-level security architecture designs for solutions operating in secure and sensitive environments, ensuring controls are informed by detailed risk analysis
The Leidos client base includes several national government departments and arms-length bodies, local authorities and providers of critical national infrastructure. We take our security obligations very seriously and will ensure there is a strong security component to all our proposals and will be able to demonstrate a sound security operation is enabled by the solution we design for our clients. You must hold, or be eligible to obtain, Developed Vetting (DV) clearance in line with UK National Security Vetting requirements
You will primarily be based at a customer site in Huntingdon, Cambridgeshire (typically 3–4 days per week), with the remaining time spent working from home. Occasional work at other customer or secure locations may also be required
Your Role and Responsibilities;
-
Experience of applying a defence-in-depth, multi-layered approach to security architecture design.
-
Proven ability to apply proportionate preventative and detective controls to reduce risk to an acceptable level.
-
Sound understanding of systems engineering lifecycle controls, with experience across key areas such as requirements and configuration management.
-
Familiarity with a range of delivery methodologies, including waterfall, incremental, SAFe Agile, and DevOps.
-
Experience of providing security review and assurance of High Level Design (HLD) and Low Level Design (LLD) artefacts as part of engineering lifecycle governance.
-
Ability to perform design trade-offs in collaboration with architects and engineers to deliver integrated and coherent solutions.
-
Understanding of service operations and security operational management planning.
-
Experience supporting delivery activities within secure or sensitive environments.
-
Familiarity with Defence Digital environments and approaches, including delivery within MOD-aligned programmes
Technology skills
-
Strong understanding of Confidentiality, Integrity and Availability (CIA), with practical experience applying these principles to security architecture and design.
-
Experience defining derived security requirements and maintaining traceability across system designs and supporting artefacts.
-
Experience of delivering security assurance for secure and sensitive systems across the lifecycle, aligned to Secure by Design (SbD) principles.
-
Experience producing and reviewing security documentation sets, such as SyOPs, RMADs, Security Management Plans, and DART submissions.
-
Working knowledge of SIEM technologies, including their implementation, operation, and ongoing management within secure environments.
-
Understanding of network and boundary protection technologies, including firewalls, mail gateways, load balancers, and endpoint protection solutions.
-
Understanding of authentication and authorisation mechanisms, such as SAML, LDAP, and PKI.
-
Professional certifications such as CISM or CISSP are desirable, alongside experience with SABSA or similar enterprise security architecture frameworks.
Communication and Soft Skills
Excellent verbal and written communication skills, with the ability to work effectively within multidisciplinary team environments.
Strong organisational skills, with the ability to prioritise and manage own workload, including associated administrative tasks, to meet delivery timelines and programme demands.
Ability to develop and communicate a clear security vision in support of system requirements and overall solution outcomes.
Capable of communicating complex technical concepts clearly and effectively across a wide range of stakeholders, both technical and non-technical.
Good commercial awareness, supporting effective delivery within programme constraints and considerations.
Experience of linKey skills
AI-extracted from the job advert
Application advice
5 AI-generated recommendations to maximise your chances.
⭐ Lead your CV personal statement with explicit mention of Secure by Design (SbD) and NIST RMF/CSF, as these are named frameworks central to the role's daily responsibilities.
📊 Quantify your security architecture experience: e.g. "Designed HLD and LLD security controls for 3 government programmes covering 12 interconnected systems, achieving full JSP compliance."
🎯 Explicitly reference MOD or HMG project experience in your work history — the advert targets defence/government environments and screeners will look for this context.
🌐 Highlight experience working across multi-stakeholder programmes (customer, supplier, internal engineering) as the role requires coordinating security design across all three groups.
🤝 Include a bullet in each relevant role demonstrating how you articulated cyber risk to non-technical stakeholders, as the advert specifically calls out this communication skill.
Suggested CV bullets
3 bullets our AI drafted for this specific advert, mirroring its ATS keywords.
Add these 3 bullets under your most recent experience:
- •Developed HLD and LLD security architectures for 4 MOD-connected systems, ensuring full alignment to JSP 440 and Secure by Design principles, achieving accreditation sign-off within a 6-month programme window.
- •Led service acceptance reviews for 3 new government system deployments, producing and assuring all security artefacts against NIST RMF requirements and reducing post-deployment findings by 45%.
- •Conducted proportionate cyber risk assessments across a Critical National Infrastructure estate of 8 interconnected services, identifying 12 high-severity control gaps and delivering a prioritised treatment plan adopted by the client CISO.
Free to copy — tailoring requires a 30-sec CV upload.
Your cover letter is ready
We've drafted a cover letter for Appcast Enterprise. Preview the opening, then unlock the full personalised version.
Letter preview — tailored to Appcast Enterprise
Dear Hiring Manager,
Leidos' work securing national government and Critical National Infrastructure programmes is precisely where I want to apply my cyber security architecture expertise — which is why the Security Architect position in Huntingdon immediately stood out. With hands-on experience delivering Secure by Design architectures aligned to NIST RMF and HMG standards, including MOD JSP frameworks, I am well placed to strengthen the security posture of your customer estate from day one.
My background in government cyber security includes developing both high-level and low-level security designs for sensitive environments, conducting proportionate risk assessments, and producing security artefacts that satisfy formal assurance and service acceptance processes. I have worked across multi-stakeholder programmes — coordinating with customer representatives, suppliers, and internal engineering teams — and I am comfortable articulating cyber risk clearly to both technical and non-technical audiences at senior levels.
Free signup, no card needed. Export to PDF/Word requires a £1.99 trial (14 days).
Interview questions
10 questions generated from this advert.
Technical
- ›How have you applied Secure by Design principles across a government or defence programme lifecycle?
- ›Walk us through how you would develop a low-level security architecture design for a system operating in a MOD-classified environment.
- ›How do you align security controls to NIST RMF stages when onboarding a new system into an existing government estate?
- ›What is your approach to conducting a proportionate cyber risk assessment, and how do you select appropriate risk treatment options?
- ›How have you used JSPs (e.g. JSP 440 or JSP 604) to inform security architecture decisions on a defence programme?
Behavioural
- ›Describe a time when you had to articulate a complex cyber risk to a non-technical senior stakeholder and gain their buy-in for a security control.
- ›Tell me about a situation where evolving customer requirements forced you to adapt an existing security architecture mid-programme.
- ›Give an example of leading a service acceptance review — what challenges arose and how did you resolve them?
- ›Describe a time you identified a significant security gap in a solution design proposed by an engineering team. How did you handle it?
- ›Tell me about a programme where you had to balance security assurance requirements against delivery timelines. What was the outcome?
STAR answer examples
Model answers using the Situation-Task-Action-Result framework. Adapt to your own experience.
Describe a time when you had to articulate a complex cyber risk to a non-technical senior stakeholder and gain their buy-in for a security control.
Tell me about a programme where you had to balance security assurance requirements against delivery timelines. What was the outcome?