HomeJobsHuntingdonSecurity Architect
Back to all jobs
⚡ Source: ReedRef: 57040656

Security Architect

Appcast Enterprise·Huntingdon·Posted yesterday
Tailor my CV for this job — Free

Job description

Original text imported from Reed

Description

Security Architect

Location: Huntingdon

UNLEASH YOUR POTENTIAL 

At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers’ success. We empower our teams in the UK to address some of the most complex problems in defence, government, safety and security, and transportation. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community.

We are seeking an experienced Cyber Security Architect to be based at our customer site in Huntingdon, Cambridgeshire, with occasional travel to other UK locations. You will work alongside engineering and delivery teams to design, assure, and maintain a strong and resilient cyber security posture across the customer estate.

You will be responsible for ensuring that solution security designs meet all functional and non-functional security requirements, delivering the required level of assurance to the client.

This will be achieved through the application of Secure by Design (SbD) principles, aligned to HMG standards (including MOD-specific JSPs) and frameworks such as NIST CSF and RMF. You will also take ownership of design feasibility, support secure delivery, and lead service acceptance reviews and approvals, ensuring all security artefacts meet the required standard

 Are you ready for your next career challenge?

You will work closely with security design partners across the programme, including customer and supplier representatives, as well as internal engineering and service teams. You will ensure the establishment and ongoing maintenance of an effective and efficient security architecture, capable of adapting to evolving customer requirements, legislation, and Secure by Design (SbD) principles across the programme lifecycle. Within the programme, you will report to the Cyber Security Team Lead, taking responsibility for developing and delivering the relevant security architecture components while maintaining an understanding of the wider solution. You will support activities spanning new system implementation and the transformation of existing services.

You will have a strong understanding of cyber risk and proportionate risk treatment approaches, with the ability to clearly articulate risk and its management to a range of stakeholders. You will be experienced in securing highly sensitive systems and applying appropriate controls within government environments.

You will be responsible for developing both high-level and low-level security architecture designs for solutions operating in secure and sensitive environments, ensuring controls are informed by detailed risk analysis

The Leidos client base includes several national government departments and arms-length bodies, local authorities and providers of critical national infrastructure.  We take our security obligations very seriously and will ensure there is a strong security component to all our proposals and will be able to demonstrate a sound security operation is enabled by the solution we design for our clients.  You must hold, or be eligible to obtain, Developed Vetting (DV) clearance in line with UK National Security Vetting requirements

You will primarily be based at a customer site in Huntingdon, Cambridgeshire (typically 3–4 days per week), with the remaining time spent working from home. Occasional work at other customer or secure locations may also be required

 Your Role and Responsibilities;

  • Experience of applying a defence-in-depth, multi-layered approach to security architecture design.

  • Proven ability to apply proportionate preventative and detective controls to reduce risk to an acceptable level.

  • Sound understanding of systems engineering lifecycle controls, with experience across key areas such as requirements and configuration management.

  • Familiarity with a range of delivery methodologies, including waterfall, incremental, SAFe Agile, and DevOps.

  • Experience of providing security review and assurance of High Level Design (HLD) and Low Level Design (LLD) artefacts as part of engineering lifecycle governance.

  • Ability to perform design trade-offs in collaboration with architects and engineers to deliver integrated and coherent solutions.

  • Understanding of service operations and security operational management planning.

  • Experience supporting delivery activities within secure or sensitive environments.

  • Familiarity with Defence Digital environments and approaches, including delivery within MOD-aligned programmes

Technology skills

  • Strong understanding of Confidentiality, Integrity and Availability (CIA), with practical experience applying these principles to security architecture and design.

  • Experience defining derived security requirements and maintaining traceability across system designs and supporting artefacts.

  • Experience of delivering security assurance for secure and sensitive systems across the lifecycle, aligned to Secure by Design (SbD) principles.

  • Experience producing and reviewing security documentation sets, such as SyOPs, RMADs, Security Management Plans, and DART submissions.

  • Working knowledge of SIEM technologies, including their implementation, operation, and ongoing management within secure environments.

  • Understanding of network and boundary protection technologies, including firewalls, mail gateways, load balancers, and endpoint protection solutions.

  • Understanding of authentication and authorisation mechanisms, such as SAML, LDAP, and PKI.

  • Professional certifications such as CISM or CISSP are desirable, alongside experience with SABSA or similar enterprise security architecture frameworks.

Communication and Soft Skills

  • Excellent verbal and written communication skills, with the ability to work effectively within multidisciplinary team environments.

  • Strong organisational skills, with the ability to prioritise and manage own workload, including associated administrative tasks, to meet delivery timelines and programme demands.

  • Ability to develop and communicate a clear security vision in support of system requirements and overall solution outcomes.

  • Capable of communicating complex technical concepts clearly and effectively across a wide range of stakeholders, both technical and non-technical.

  • Good commercial awareness, supporting effective delivery within programme constraints and considerations.

    Experience of lin
  • SpeedCV AI

    Key skills

    AI-extracted from the job advert

    Must-have skills
    Secure by Design (SbD)NIST CSF / RMFMOD JSP complianceHMG security standardsCyber risk assessment and treatmentHigh-level and low-level security architecture designGovernment / defence security environment experience
    Nice-to-have
    Critical National Infrastructure securityService acceptance review leadershipMulti-supplier programme security coordination
    Soft skills
    Stakeholder communicationRisk articulationAutonomyAdaptabilityCollaboration
    SpeedCV AI

    Application advice

    5 AI-generated recommendations to maximise your chances.

    1

    ⭐ Lead your CV personal statement with explicit mention of Secure by Design (SbD) and NIST RMF/CSF, as these are named frameworks central to the role's daily responsibilities.

    2

    📊 Quantify your security architecture experience: e.g. "Designed HLD and LLD security controls for 3 government programmes covering 12 interconnected systems, achieving full JSP compliance."

    3

    🎯 Explicitly reference MOD or HMG project experience in your work history — the advert targets defence/government environments and screeners will look for this context.

    4

    🌐 Highlight experience working across multi-stakeholder programmes (customer, supplier, internal engineering) as the role requires coordinating security design across all three groups.

    5

    🤝 Include a bullet in each relevant role demonstrating how you articulated cyber risk to non-technical stakeholders, as the advert specifically calls out this communication skill.

    NEW
    AI SpeedCV

    Suggested CV bullets

    3 bullets our AI drafted for this specific advert, mirroring its ATS keywords.

    How to tailor your CV

    Add these 3 bullets under your most recent experience:

    • Developed HLD and LLD security architectures for 4 MOD-connected systems, ensuring full alignment to JSP 440 and Secure by Design principles, achieving accreditation sign-off within a 6-month programme window.
    • Led service acceptance reviews for 3 new government system deployments, producing and assuring all security artefacts against NIST RMF requirements and reducing post-deployment findings by 45%.
    • Conducted proportionate cyber risk assessments across a Critical National Infrastructure estate of 8 interconnected services, identifying 12 high-severity control gaps and delivering a prioritised treatment plan adopted by the client CISO.

    Free to copy — tailoring requires a 30-sec CV upload.

    NEW
    AI cover letter

    Your cover letter is ready

    We've drafted a cover letter for Appcast Enterprise. Preview the opening, then unlock the full personalised version.

    Letter preview — tailored to Appcast Enterprise

    Dear Hiring Manager,

    Leidos' work securing national government and Critical National Infrastructure programmes is precisely where I want to apply my cyber security architecture expertise — which is why the Security Architect position in Huntingdon immediately stood out. With hands-on experience delivering Secure by Design architectures aligned to NIST RMF and HMG standards, including MOD JSP frameworks, I am well placed to strengthen the security posture of your customer estate from day one.

    My background in government cyber security includes developing both high-level and low-level security designs for sensitive environments, conducting proportionate risk assessments, and producing security artefacts that satisfy formal assurance and service acceptance processes. I have worked across multi-stakeholder programmes — coordinating with customer representatives, suppliers, and internal engineering teams — and I am comfortable articulating cyber risk clearly to both technical and non-technical audiences at senior levels.

    Get my personalised letter — free

    Free signup, no card needed. Export to PDF/Word requires a £1.99 trial (14 days).

    SpeedCV exclusive
    SpeedCV AI

    Interview questions

    10 questions generated from this advert.

    Technical

    • How have you applied Secure by Design principles across a government or defence programme lifecycle?
    • Walk us through how you would develop a low-level security architecture design for a system operating in a MOD-classified environment.
    • How do you align security controls to NIST RMF stages when onboarding a new system into an existing government estate?
    • What is your approach to conducting a proportionate cyber risk assessment, and how do you select appropriate risk treatment options?
    • How have you used JSPs (e.g. JSP 440 or JSP 604) to inform security architecture decisions on a defence programme?

    Behavioural

    • Describe a time when you had to articulate a complex cyber risk to a non-technical senior stakeholder and gain their buy-in for a security control.
    • Tell me about a situation where evolving customer requirements forced you to adapt an existing security architecture mid-programme.
    • Give an example of leading a service acceptance review — what challenges arose and how did you resolve them?
    • Describe a time you identified a significant security gap in a solution design proposed by an engineering team. How did you handle it?
    • Tell me about a programme where you had to balance security assurance requirements against delivery timelines. What was the outcome?
    SpeedCV AINEW

    STAR answer examples

    Model answers using the Situation-Task-Action-Result framework. Adapt to your own experience.

    1Question

    Describe a time when you had to articulate a complex cyber risk to a non-technical senior stakeholder and gain their buy-in for a security control.

    Situation: During a government data-sharing programme, a proposed API integration introduced a high-severity data exfiltration risk that the programme director, a non-technical SCS2, was inclined to accept to avoid a 6-week delay. Task: I needed to communicate the risk clearly and secure approval for a compensating control without derailing the delivery schedule. Action: I prepared a one-page risk brief using business-impact language — estimating a potential £2.4M remediation cost and reputational exposure — and proposed a lightweight mutual TLS control that added only 3 days to the timeline. Result: The director approved the control immediately, the programme delivered on time, and the approach was adopted as a template for two subsequent integrations.
    2Question

    Tell me about a programme where you had to balance security assurance requirements against delivery timelines. What was the outcome?

    Situation: On a 9-month MOD infrastructure modernisation programme, the engineering team submitted a system design 4 weeks before go-live that had not been through formal security assurance, creating a conflict between the delivery milestone and JSP 604 accreditation requirements. Task: I had to complete a full assurance review without pushing the go-live date. Action: I triaged the 47 security controls into three tiers, fast-tracked the 12 critical controls through an accelerated review with the customer's accreditor, and agreed a risk-accepted remediation schedule for the remaining 35. Result: The system achieved interim accreditation on the original go-live date, with full accreditation confirmed 5 weeks later — the first programme in the portfolio to hit both milestones without a formal deviation.

    Similar jobs

    View all