Security Architect (Entra ID/Microsoft Azure)

Methods

Greater London

Hybrid

GBP 90,000 - 120,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Autonomy to grow skills
LinkedIn Learning access
Pension salary exchange
Private medical insurance
Travel insurance

Job summary

Methods is seeking an experienced Security Architect to lead security architecture across a major technology transformation programme in London. You will define security principles, patterns and controls, and assure designs across identity, endpoints, Microsoft 365, apps, infrastructure and networks.

You will work at the intersection of security, architecture and delivery, challenging designs when necessary while enabling pragmatic delivery.

Qualifications

  • Strong background in security architecture across large enterprise environments.
  • Experience translating security risk into business impact and options.
  • Proven ability to embed security design across identity, endpoints, data and networks.

Responsibilities

  • Provide security architecture leadership across the transformation lifecycle.
  • Define and assure security patterns, controls, and risk-based design decisions.
  • Assess threats, risks, and control gaps across current and target states.
  • Review migration approaches from a security perspective and ensure containment of risks.
  • Maintain security architecture documentation including threat models and architecture decision records.
  • Engage with senior stakeholders and deliver pragmatic security recommendations.

Skills

Security architecture
Zero Trust
Identity protection
Threat modelling
Microsoft cloud
Azure
Risk assessment
Security governance

Tools

Microsoft Entra ID
Microsoft 365
Identity & access security
Security logging/Monitoring

Job description

  • We are looking for an experienced Security Architect to join a major technology transformation programme and provide security architecture leadership across the full transformation lifecycle
  • This is a key role responsible for defining and assuring the security architecture across identity, endpoints, Microsoft 365, applications, infrastructure, networks and migration activities
  • You will work at the intersection of security, architecture and delivery, ensuring that appropriate security controls are embedded into both coexistence and target-state designs without creating unnecessary barriers to practical delivery
  • The programme will involve significant technology change and will need to operate across existing environments while progressively introducing new services and capabilities. You will therefore play a critical role in ensuring that security is considered from the outset, rather than being treated as a final-stage assurance activity
  • You will establish the security principles, patterns and control requirements that underpin the programme, assess threats and risks across current and future states, and provide independent assurance over technical designs and migration approaches
  • The successful candidate will bring strong technical security expertise together with sound risk judgement. You will be comfortable challenging designs where necessary, but equally capable of finding pragmatic solutions that allow the programme to move forward while maintaining an appropriate level of security
  • As the Security Architect, you will provide security architecture leadership and assurance across the transformation programme
  • Establish and maintain the programme’s security architecture principles, patterns, standards and control requirements
  • Define clear security design-assurance criteria and ensure that technical designs are assessed consistently against agreed requirements
  • Assess threats, risks, vulnerabilities and control gaps across the current, coexistence, transition and target states
  • Develop proportionate security controls that support secure coexistence between existing environments and new target services
  • Define and assure Zero Trust principles across identity, devices, applications, data and network access
  • Establish security patterns for identity protection, privileged access, least privilege, Conditional Access and administrative boundaries
  • Work closely with the identity and directory architecture function to ensure that authentication, access and administrative controls are appropriately designed and secured
  • Define security requirements for endpoint, email, Microsoft 365, data, application and network architectures
  • Establish appropriate requirements for security logging, monitoring, alerting, threat detection and incident response
  • Review technical architecture and solution designs, identifying security weaknesses, control gaps, dependencies and areas requiring further assurance
  • Assess migration strategies and cutover approaches from a security perspective, ensuring that risks associated with transition between environments are understood and controlled
  • Review proposed security exceptions and deviations from established standards, documenting the rationale, residual risk, compensating controls and required treatments
  • Maintain visibility of significant security risks and ensure that appropriate owners and mitigation plans are established
  • Work with technical teams to develop practical remediation and risk-treatment approaches rather than simply identifying problems
  • Ensure security requirements are incorporated into programme plans, technical designs, migration patterns, testing strategies and operational handover
  • Support security testing and assurance activities, including validation of security controls before major migrations or go-live decisions
  • Provide security input into operational readiness, ensuring that monitoring, alerting, incident response and support arrangements are in place before services transition into production
  • Align programme designs with organisational security policies, information-security standards, data-protection obligations and relevant regulatory or assurance requirements
  • Maintain appropriate security architecture documentation, including HLDs, security principles, control matrices, threat models, risk assessments, exception records and architecture decision records
  • Provide clear security recommendations and risk-based advice to programme leadership and senior stakeholders
  • Support continuous improvement of security controls as the transformation progresses and new risks, technologies and requirements emerge
  • This is a transformation programme where security needs to be built into the architecture while delivery continues at pace
  • The programme will need to coexist with existing technology environments while introducing new identity, endpoint, productivity, application, infrastructure and network services. This creates a range of security challenges around trust boundaries, authentication, privileged access, data protection, legacy dependencies, migration paths and operational control
  • You will therefore need to take a risk-based and pragmatic approach to security architecture
  • The role is not about preventing change or applying controls without considering their operational impact. Instead, you will help the programme understand the risks it is taking, identify appropriate controls and determine where residual risk can reasonably be accepted, mitigated or transferred
  • You will be expected to challenge weak security decisions while also helping delivery teams find workable alternatives
  • A key part of the role will be ensuring that security controls remain effective throughout the transition. A design that is secure in the target state may not be appropriate during coexistence, and migration activities can introduce temporary risks that need to be explicitly understood and controlled
  • Your role will be to make those risks visible and ensure that the programme has a clear path to managing them
Benefits
  • Autonomy to develop and grow your skills and experience
  • Be part of exciting project work that is making a difference in society
  • Strong, inspiring and thought-provoking leadership
  • A supportive and collaborative environment
  • Development access to LinkedIn Learning, a management development programme and training
  • Wellness 24/7 Confidential employee assistance programme
  • Social - Breakfast Tuesdays, Pizza Thursday monthly, weekly social in the office and commitment to charitable causes
  • Time off 25 days a year
  • Pension Salary Exchange Scheme with 4% employer contribution and 5% employee contribution
  • Discretionary Company Bonus based on company and individual performance
  • Life Assurance of 4 times base salary
  • Private Medical Insurance which is non-contributory (spouse and dependants included)
  • Worldwide Travel Insurance which is non-contributory (spouse and dependants included)
  • Benefits Platform offering various retail and leisure discounts

We are looking for an experienced Security Architect with a strong background in Microsoft cloud and hybrid enterprise environmentsExperience working within formal architecture and security-governance frameworksStrong technical writing skills, with experience producing security architecture documentation, risk assessments, threat models, control matrices and design-assurance outputsAbility to translate technical security risks into clear business impacts, choices and recommendationsExperience designing security controls across endpoints, email, data, applications, infrastructure and networksDemonstrable experience in threat modelling, security risk assessment, control mapping and architecture assuranceExtensive experience working as a Security Architect across complex enterprise technology environmentsStrong knowledge of identity and access security, including authentication, Conditional Access, identity protection and administrative controlsStrong understanding of security logging, monitoring, threat detection and incident-response requirementsStrong technical knowledge of Microsoft Entra ID, Microsoft 365, Azure, endpoint security, networks and application securityExperience assessing security risks associated with migration, coexistence, cutover and transition activitiesExperience reviewing security exceptions and developing pragmatic risk-treatment or compensating-control strategiesStrong understanding of hybrid and cloud security architectures and the challenges associated with transitioning from legacy environmentsUnderstanding of data protection, information governance and relevant regulatory or assurance requirementsProven experience applying Zero Trust, least privilege, privileged access and defence-in-depth principlesLocation : the role will be onsite in London initially and then 50/50 hybridYou will also be able to distinguish between genuine security risks and theoretical concerns that do not warrant disproportionate controlsYou will be comfortable engaging with senior stakeholders and explaining complex security matters in straightforward language. When a risk needs to be escalated, you will be able to clearly articulate the issue, potential impact, available options and your recommended approachMost importantly, you will be able to embed security by design while maintaining the momentum of a major transformation programmeYou will have the technical depth to challenge architects and engineers, but also the judgement to understand delivery constraints and work collaboratively towards solutionsYou will be confident operating in an environment where information is incomplete and decisions need to be made based on a combination of evidence, risk and professional judgementYou will be a pragmatic security professional who understands that effective security is about managing risk, not eliminating change

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Architect - Entra ID/MS/Azure
Security Architect - Entra ID/MS/Azure

Methods Business and Digital Technology • Greater London

On-site
GBP 90,000 - 120,000
Development
Wellness program
Flexible working
+2
Security Architect - Entra ID/MS/Azure
Security Architect - Entra ID/MS/Azure

Methods • Greater London

On-site
GBP 90,000 - 120,000
Development
Wellness
Flexible Working
+6
Security Architect - Entra ID/MS/Azure
Security Architect - Entra ID/MS/Azure

Methods Business and Digital Technology • City Of London

On-site
GBP 85,000 - 110,000
Development programs
Wellness program
Flexible working
+5
Lead Security Architect - Microsoft Security specialist
Lead Security Architect - Microsoft Security specialist

Anson McCade • United Kingdom

Hybrid
GBP 110,000 - 170,000
Performance bonus
Career progression
Security Architect – Entra ID, MS, Azure
Security Architect – Entra ID, MS, Azure

Jobtailor • Greater London

Hybrid
GBP 90,000 - 130,000
Security Architect
Security Architect

GCS Recruitment • Warrington

On-site
GBP 70,000 - 110,000
Lead Security Architect
Lead Security Architect

UK Home Office • Sheffield

On-site
GBP 70,000 - 90,000
Security Architect - DV cleared
Security Architect - DV cleared

CBSbutler Ltd. • Greater London

Hybrid
GBP 120,000 - 138,000
Cyber Security Architect & Engineering Lead
Cyber Security Architect & Engineering Lead

Moore Kingston Smith LLP • Greater London

Hybrid
GBP 70,000 - 85,000
Cyber Security Architect & Engineering Lead
Cyber Security Architect & Engineering Lead

Moore Kingston Smith • Greater London

On-site
GBP 70,000 - 90,000