Enterprise Security Architect/DevSecOps

SoCode Limited

Cambridge

On-site

GBP 90,000 - 130,000

Full time

5 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

SoCode Limited is hiring an Enterprise Security Architect to sit between architecture and engineering on a major on‑prem Private Cloud build. You will shape security foundations of a brand‑new private cloud, built with open‑source stacks and modern platform engineering practices, embedding security across the stack.

You’ll threat‑model the platform, define secure designs, validate controls, and implement DevSecOps with automated tests, hardened configurations and auditable evidence, working

Qualifications

  • Proven experience building private cloud infrastructure, not just public cloud.
  • Strong background with open‑source infrastructure stacks, containers, and platform technologies.
  • Hands‑on security architecture and engineering across large‑scale datacentre or hybrid environments.
  • Expertise in threat modelling and attack‑path analysis.

Responsibilities

  • Own and evolve threat modelling across the platform, infra, workloads and onboarding pathways.
  • Translate threat stories into engineering requirements, acceptance criteria and delivery priorities.
  • Drive secure‑by‑design through IaC, CI/CD, policy‑as‑code and hardened image pipelines.
  • Define reusable standards for identity, privileged access, secrets, PKI, segmentation, logging and recovery.
  • Translate NIST/STIG frameworks into pragmatic, testable controls.
  • Automate posture, evidence and continuous validation across the platform.
  • Act as the security conduit across engineering, programme leadership and enterprise security.

Skills

Threat modelling
Open‑source stacks
Platform technologies
Security architecture
DevSecOps
IaC
CI/CD
PKI
Secrets management
Vulnerability management

Job description

We’re hiring an Enterprise Security Architect to sit right between architecture and engineering on a major on‑prem Private Cloud build. This isn’t a public‑cloud security role — you’ll be shaping the security foundations of a brand‑new private cloud infrastructure, built using open‑source software stacks and modern platform‑engineering practices.

The RoleEmbedded full‑time within an engineering‑led programme, you’ll be the dedicated security partner — threat‑modelling the platform, defining secure designs, validating controls, and embedding DevSecOps across the stack. You’ll work directly with architects and engineers to turn threats into real mitigations, automated tests, hardened configurations and auditable evidence.

Key Responsibilities
  • Own and evolve threat modelling across the platform, infra, workloads and onboarding pathways.
  • Translate threat stories into engineering requirements, acceptance criteria and delivery priorities.
  • Drive secure‑by‑design through IaC, CI/CD, policy‑as‑code and hardened image pipelines.
  • Define reusable standards for identity, privileged access, secrets, PKI, segmentation, logging and recovery.
  • Translate NIST/STIG frameworks into pragmatic, testable controls.
  • Automate posture, evidence and continuous validation across the platform.
  • Act as the security conduit across engineering, programme leadership and enterprise security.
What You’ll Bring
  • Proven experience building private cloud infrastructure — not just consuming public cloud.
  • Strong background with open‑source infrastructure stacks, containerisation and platform technologies.
  • Deep hands‑on security architecture + engineering experience across large‑scale datacentre or hybrid environments.
  • Strong threat‑modelling and attack‑path analysis skills.
  • Practical knowledge of compute, virtualisation, containers, orchestration, storage, networking and platform management.
  • Experience with IaC, CI/CD, policy‑as‑code and hardened image pipelines.
  • Expertise in PKI, secrets, privileged access, segmentation, workload isolation and infra hardening.
  • Ability to define reusable patterns, measurable criteria and security standards.Experience with automated testing, attack simulation and vulnerability management.
  • Credibility to influence multidisciplinary engineering teams and balance risk vs delivery
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Private Cloud Security Architect & DevSecOps
Private Cloud Security Architect & DevSecOps

SoCode Limited • Cambridge

On-site
GBP 90,000 - 130,000
Senior Security Architect
Senior Security Architect

Anson McCade • Greater London

On-site
GBP 90,000 - 130,000
Senior Security Engineer
Senior Security Engineer

Sanderson • Greater London

On-site
GBP 70,000 - 90,000
Enterprise Security Architect
Enterprise Security Architect

HOK Consulting - Technical Recruitment Consultancy • Sheffield

On-site
GBP 70,000 - 90,000
Cloud Security Engineer
Cloud Security Engineer

La Fosse • Greater London

On-site
GBP 70,000 - 90,000
Cloud Security Architect
Cloud Security Architect

Pioneertechlabs • Greater London, Slough

On-site
GBP 70,000 - 90,000
Lead Security Engineer: Own Cloud & Incident Response
Lead Security Engineer: Own Cloud & Incident Response

Understanding Recruitment • Greater London

Hybrid
GBP 110,000 - 150,000
Hybrid working
London office access
Autonomy and ownership
+2
Cloud Security Architect
Cloud Security Architect

Queen Square Recruitment • Reading

On-site
GBP 80,000 - 110,000
Security Architect (Entra ID/Microsoft Azure)
Security Architect (Entra ID/Microsoft Azure)

Methods • Greater London

On-site
GBP 90,000 - 120,000
Autonomy to grow skills
LinkedIn Learning access
Pension salary exchange
+2
Cloud Architect
Cloud Architect

SR2 | Socially Responsible Recruitment | Certified B Corporation • Bradford

On-site
GBP 101,000 - 111,000