Quick Overview
Job Description
About the Role
We are seeking an experienced Cyber Security Solution Architect to design, implement, and oversee enterprise-wide security architecture. The ideal candidate will have deep expertise across Identity and Access Management (IAM), firewalls, network security, cloud security, endpoint security, and broader cybersecurity domains , acting as the technical authority bridging business requirements with secure, scalable technical solutions.
Role requires 3 days working from office in Coventry.
Key Responsibilities
- Design and architect end-to-end security solutions covering IAM, network security, cloud security, endpoint protection, and perimeter defense across on-prem and multi-cloud environments.
- Lead the architecture, deployment, and optimization of firewalls, IDS/IPS, VPNs, proxies, and network segmentation strategies.
- Design and implement IAM frameworks including SSO, MFA, PAM, RBAC/ABAC, identity federation, and lifecycle management.
- Architect cloud security controls across AWS/Azure/GCP — including IAM policies, network security groups, encryption, key management, workload protection (CWPP), and cloud security posture management (CSPM).
- Design secure landing zones and cloud architecture patterns aligned with the shared responsibility model.
- Define endpoint security architecture including EDR/XDR, device hardening, patch management, mobile device management (MDM), and endpoint compliance policies.
- Develop security reference architectures, standards, and blueprints aligned with industry frameworks (NIST, ISO 27001, CIS, Zero Trust).
- Conduct security architecture reviews for new projects, applications, cloud migrations, and infrastructure changes.
- Perform risk assessments, threat modeling, and security gap analyses; recommend remediation strategies.
- Collaborate with network, cloud, application, DevOps, and endpoint teams to embed security by design.
- Evaluate, select, and integrate security tools/technologies (SIEM, SOAR, EDR/XDR, DLP, CASB, WAF, CSPM, CNAPP).
- Define and enforce security policies, standards, and best practices across the organization.
- Provide technical leadership during incident response and post-incident architecture hardening.
- Create and maintain documentation: HLDs, LLDs, network diagrams, cloud architecture diagrams, data flow diagrams, and security runbooks.
- Support audits, compliance assessments, and regulatory requirements (GDPR, PCI-DSS, HIPAA, SOX, etc.).
- Mentor security engineers and junior architects on best practices and emerging threats.
- Stay current with emerging threats, vulnerabilities, and technologies; recommend proactive improvements.
Required Skills & Experience
Core Domains:
- Good experience in cybersecurity and in a solution/security architect role
- Strong hands-on and architectural experience in:
- IAM: Okta, Azure AD/Entra ID, Ping Identity, SailPoint, CyberArk (PAM), ForgeRock
- Firewalls & Network Security: Palo Alto, Fortinet, Cisco ASA/Firepower, Check Point, Juniper
- Network Security: VPNs, VLANs, segmentation, NAC, SD-WAN, DNS security, secure routing/switching
- Cloud Security: AWS (IAM, Security Hub, GuardDuty, KMS), Azure (Defender for Cloud, Sentinel, Entra ID), GCP Security Command Center; CSPM/CNAPP tools (Wiz, Prisma Cloud, Orca)
- Endpoint Security: CrowdStrike, Microsoft Defender for Endpoint, SentinelOne, Symantec; MDM/UEM (Intune, Jamf)
- Cybersecurity fundamentals: vulnerability management, threat intelligence, encryption/PKI, data protection
Architecture & Frameworks:
- Experience designing Zero Trust Architecture (ZTA)
- Strong understanding of cloud-native security architecture and shared responsibility models
- Knowledge of security frameworks: NIST CSF, ISO 27001, CIS Controls, MITRE ATT&CK
Other Technical Skills:
- SIEM/SOAR platforms (Splunk, QRadar, Sentinel)
- Scripting/automation (Python, PowerShell, Terraform) is a plus
- Understanding of DevSecOps and CI/CD security integration
- Container and Kubernetes security exposure (a plus)
Certifications (preferred, not mandatory):
- CISSP, CISM, or CCSP
- Cloud: AWS Certified Security – Specialty, Azure Security Engineer, Google Professional Cloud Security Engineer
- Vendor-specific: Palo Alto PCNSE, Fortinet NSE, Cisco CCNP Security
- IAM: CyberArk CDE, Okta Certified Professional
- TOGAF or other architecture certification (a plus)
Similar jobs
- EU
Solutions Architect
NewExperis UK
new malden🇬🇧Hybrid2 hours agoAgileTechnology - EC
Solutions Architect
Newea Change
United Kingdom🇬🇧Remote2 hours agoAWSAgileAzure+1Technology - PT
Technical Solutions Architect
NewPeaple Talent
bristol🇬🇧£85k/yrHybrid2 hours agoPower BIZero TrustTechnology - DC
Business Central Solution Architect
NewDynamics Consultants
southampton🇬🇧Hybrid2 hours agoTechnology - PC
Cloud Solution Architect - Exchange/SharePoint
NewPenta Consulting
United Kingdom🇬🇧Remote2 hours agoShellPowerShellTechnology - NC
Senior Solution Architect
NewN Consulting Global
guildford🇬🇧Hybrid2 hours agoMicroservicesAWSScrum+10Technology