Overview
Security Architect role at Intellectual Property Office UK . The role collaborates with the Chief Security Officer, Head of Cyber, Lead Security Architect and the wider security team to develop IPO’s security vision and evolve the security strategy and roadmaps. It is part of the IPO Secure team and focuses on ensuring continued compliance with key security standards such as PCI, ISO27001, secure by design, GovAssure, and related frameworks. The role champions security by design and shapes security solutions and controls across on-premises, cloud and hybrid environments.
The role ensures common tools and patterns are used effectively to deliver secure systems while implementing proportionate controls to safeguard IPO data, essential services and supporting infrastructure. It coordinates assurance against the National Cyber Security Centre’s Cyber Assessment Framework and the Government’s GovAssure framework.
Working style
This role operates under IPO hybrid working arrangements, with staff expected to spend at least 20% of time onsite in one of our offices. This role is based in the Newport Office. Attendance expectations can vary by role; discuss working arrangements with the recruiting manager to agree a reasonable balance between home and office working.
Main duties
- Ensure security architecture aligns with Gov security policies and frameworks, legal frameworks, industry regulations and best practice (e.g., ISO 27001, NCSC Standards, GDPR, PCI DSS, GovAssure, Secure by Design).
- Support the secure by design champion in building awareness and understanding of the secure by design framework across DDaT.
- Manage the security architecture compliance roadmap, coordinating with relevant teams to align with the IPO Secure Team’s strategic direction and audit recommendations.
- Stay up to date with changing compliance legislation and initiatives to educate colleagues on relevant security standards.
- Recommend security controls and identify security solutions that support business objectives.
- Provide expert security guidance during the design, implementation and use phases of systems, applications and infrastructure.
- Offer specialist advice on approaches and technologies across teams, assessing risks of proposed changes.
- Inspire and influence others to apply security principles and communicate with stakeholders at all levels.
- Support GovAssure by coordinating evidence collection and GovAssure returns to Cabinet Office.
- Assist with incident response processes to identify architectural issues and solutions.
- Engage with internal and external partners to develop knowledge and inform decisions.
- Carry out any other duties reasonably required in line with main duties.
- Broad technical knowledge, especially around cloud and hybrid technologies.
- Solid understanding of Governance, Compliance and Risk, and the CIA triad (Confidentiality, Availability, Integrity).
- Solid understanding of security protocols, networking, identity management, authentication, authorization and cryptography.
- Excellent communication and interpersonal skills to articulate security controls, solutions and advice to stakeholders; able to switch between technical and non-technical language.
- Ability to evaluate options and make decisions quickly and effectively.
- Team player with enthusiasm for contributing to the team’s success and collaborating with stakeholders at all levels.
- Sense of urgency and proactive handling of situations, incidents or tasks.
- Continual learning to stay informed about emerging security technologies, threats and trends.
Qualifications and benefits
Salary : £46,262 , with £13,402 contributed towards the Civil Service Defined Benefit Pension scheme. Benefits include :
Unlimited Pluralsight video learning accessAccess to Microsoft’s ESI training suiteHybrid working with no core hoursSupport for career progression25 days annual leave, increasing to 30 days in annual increments, plus 8 public leave and 1 privilege daySecurity and vetting
Successful candidates must pass a disclosure and barring security check and, if successful, must hold or be willing to obtain higher Security Clearance . Candidates must have consistently lived in the UK for a minimum of 5 years to meet security clearance requirements.
Seniority and employment details
Seniority level : Mid-Senior levelEmployment type : Full-timeJob function : Information TechnologyIndustries : Government Administration#J-18808-Ljbffr