- Company Name
- HM Revenue & Customs
- Job Title
- Cyber Security Architect
- Job Description
-
Job title: Cyber Security Architect
Role Summary: Leads the design and delivery of cyber security services across the UK government, embedding the Government Cyber Security Strategy (GCSS) within 400 organisations. Coordinates with senior stakeholders, sets security standards, and ensures compliance with HMG and industry frameworks.
Expactations: Must hold SC Clearance. 3–5 years as a Cyber Security Professional or Security Architect, proven senior stakeholder management, strong communication to both technical and non‑technical audiences, and a solid grasp of risk, privacy, and secure design principles.
Key Responsibilities:
- Own end‑to‑end delivery of service lines supporting GCSS objectives.
- Develop, implement, and continuously improve Cyber GSeC advice, guidance, and policies for 400+ organisations.
- Select and apply security techniques, tools, and test strategies to verify compliance; recommend remediation.
- Lead creation of Security Principles, Policies, and Technical Standards aligned to business context and risk appetite.
- Conduct risk assessments, identify vulnerabilities, and drive resolution in complex technical environments.
- Communicate security posture and recommendations to stakeholders such as the Government Security Group, NCSC, and CDDO.
- Research, validate, and champion adoption of emerging technologies and methodologies.
- Support balanced risk‑management decisions, balancing security with business needs.
Required Skills:
- Security architecture design and secure code review.
- Risk assessment and incident response planning.
- Policy drafting, governance, and compliance alignment.
- Expertise in NIST, ISO 27001/27002, CIS Controls, Cyber Essentials.
- Technical testing: vulnerability scanning, penetration testing, red/blue team exercises.
- Strong stakeholder engagement, negotiation and influence.
- Knowledge of secure development life cycle and Secure by Design principles.
- Ability to distill complex technical concepts for diverse audiences.
Required Education & Certifications:
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- Professional certifications: CISSP, CISM, ISO 27001 Lead Implementer, CISA, or equivalent.