Contract Security Architect (Platform security)
£555 p/d Inside IR35
Hybrid remote in Salisbury
**DV Clearance is essential** please only apply if you hold this level of clearance, this is due to the classification of the project.
We are seeking an experienced DV cleared Security Architect support the design, build and assurance of backend platform and endpoint security capabilities within secure, offline (air-gapped) environments.
This is a highly technical role suited to a security professional who can operate at both architectural and hands-on levels, with strong experience across endpoint protection, Antivirus/EDR, vulnerability management, platform security and secure environments. You will work closely with Infrastructure, Platform and Security teams, applying NIST Cybersecurity Framework principles and MOD security policies to deliver secure and compliant capabilities for a UK Government environment.
Key Responsibilities
- Lead the architecture, design and implementation of endpoint and platform security solutions.
- Design security controls aligned with MOD policies, NIST Cybersecurity Framework and NCSC guidance.
- Design and deliver vulnerability management capabilities, including scanning, risk prioritisation, remediation and reporting.
- Develop security solutions for offline and air-gapped environments, including controlled update, patch and signature distribution.
- Establish secure mechanisms for threat intelligence ingestion and data transfer within disconnected environments.
- Define and implement vulnerability scanning regimes and remediation processes.
- Advise on endpoint hardening, firewall rules, ports, protocols and system security controls.
- Produce penetration testing scopes covering backend platforms and endpoints.
- Produce and maintain formal technical documentation, including HLDs, LLDs, security architecture documentation and SOPs.
Essential Skills & Experience
- Proven experience operating as a Security Architect, Security Engineer or senior Security SME within secure, regulated or high-assurance environments.
- Designing and delivering: Platform security controls, Firewall, port and protocol security, Antivirus / Endpoint Protection / EDR solutions, Vulnerability Management platforms and Endpoint hardening and security controls
- Experience working within offline / air-gapped environments.
- Strong understanding of: Secure patching and update models, AV signature management, Threat intelligence management, Controlled data transfer mechanisms and Vulnerability assessment and remediation
- Experience producing formal technical documentation, including High-Level Designs (HLDs), Low-Level Designs (LLDs), Security Architecture documentation and Standard Operating Procedures (SOPs)
- Experience supporting security accreditation, assurance and compliance processes.