A complete application in a minute — tailored resume and cover letter, ready to send.
Project Foundry Resourcing Services is seeking an experienced Cyber Security Architecture and Assurance Lead to provide independent technical leadership across the Cyber Recovery Technology Programme, defining the target architecture and assurance approach to deliver end-to-end recovery capabilities.
You will collaborate with technology teams, business stakeholders and suppliers to review designs, assess risks, dependencies and recovery testing approaches, and produce architecture assurance
We are seeking an experienced Cyber Security Architecture and Assurance Lead to provide independent technical leadership, architecture governance and assurance across its Cyber Recovery Technology Programme. Acting as a trusted technical adviser, you will define, govern and assure the target cyber recovery architecture, ensuring that the programme delivers a cohesive, end-to-end recovery capability rather than a set of disconnected technology solutions.
You will work closely with the technology teams, business stakeholders and third-party suppliers to ensure solutions are aligned with business, operational, security and recovery objectives. Throughout the programme lifecycle, you will provide constructive independent challenge, identifying risks, dependencies, integration challenges and recovery constraints while ensuring that designs reflect industry best practice and support agreed recovery outcomes.
This role has responsibility for architecture leadership and assurance across recovery infrastructure, immutable backup platforms, cyber recovery vaults, clean room environments, application recovery workstreams and related technology domains. You will bring the judgement to assess both strategic architecture direction and detailed technical designs, with a clear focus on resilience, recoverability and operational readiness.
KEY RESPONSIBILITIES
You will become the technical architecture lead for the Cyber Recovery Technology Programme, developing, maintaining and governing the Target Cyber Recovery Architecture. You will define the architecture principles, standards, reference architectures and design patterns required for cyber recovery and operational resilience, establishing a clear and consistent technical direction for all programme workstreams.
You will ensure that programme technologies, workstreams and suppliers integrate into a cohesive recovery capability. This will include reviewing and assuring technical designs produced by internal teams and third-party suppliers; challenging technical assumptions, architectural decisions and supplier proposals; and participating actively in Design Authority and technical governance forums.
You will identify and communicate architectural risks, technical debt, hidden dependencies and single points of failure. You will validate recovery strategies, recovery operating models and technology roadmaps, ensuring that programme solutions remain aligned with agreed Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).
You will support procurement activities, technology evaluations and supplier-selection exercises, providing independent technical input that supports informed decisions. You will also review recovery runbooks, recovery methodologies and recovery testing approaches, and will support cyber recovery testing, simulation exercises and recovery-readiness reviews.
You will produce architecture assurance reports, dependency assessments and clear technical recommendations for programme and senior stakeholders. You will remain informed about industry trends, emerging technologies and cyber recovery best practice, helping us to develop and sustain a best-in-class recovery capability.
MUST-HAVE SKILLS
Enterprise and Cyber Recovery Architecture
CORE
You have substantial experience in enterprise, solution, infrastructure or cyber recovery architecture. You can translate business, operational, security and recovery objectives into practical target architectures, principles, standards, reference architectures and design patterns. You are comfortable taking ownership of an architecture baseline and evolving it through a complex programme while retaining a clear end-to-end view of resilience and recoverability.
Cyber Recovery, Disaster Recovery and Operational Resilience
CRITICAL
You bring demonstrable experience designing and governing cyber recovery, disaster recovery or operational resilience programmes. You possess a strong understanding of recovery architectures, cyber-resilience principles and operational-resilience frameworks, and can validate recovery strategies, operating models and technology roadmaps against agreed RTOs and RPOs. You understand how recovery infrastructure, applications, data, processes and people must work together to deliver a credible recovery capability.
Architecture Governance and Technical Assurance
CRITICAL
You have experience leading Design Authority, architecture governance and technical assurance activity. You can review designs from internal teams and suppliers, challenge assumptions and decisions constructively, and provide defensible recommendations that balance security, resilience, operational needs and delivery constraints. You are able to establish effective governance forums and ensure that architecture decisions, exceptions and actions are recorded and followed through.
Recovery Infrastructure, Data and Platform Technologies
CORE
You have hands-on architectural knowledge of enterprise infrastructure, storage and virtualisation technologies, including VMware vSphere. You understand enterprise database recovery architectures, including Microsoft SQL Server and Oracle RAC, and can assess the recovery implications of platform design choices. You also have experience with immutable backup platforms, cyber recovery vaults, air-gapped recovery solutions and clean room environments, enabling you to assure the technical foundations of a secure recovery capability.
Identity and Access Recovery Architecture
REQUIRED
You have a strong understanding of identity and access management in a recovery context, including Active Directory, multi-factor authentication, privileged access management and recovery authentication models. You can assess how identity services and access controls support, constrain or introduce risk into a cyber recovery solution, and ensure these dependencies are appropriately addressed in architecture, runbooks and testing.
CORE
You have proven experience managing architecture across multi-supplier technology programmes. You can ensure that diverse technologies, suppliers and workstreams integrate into a cohesive solution, identifying interface risks, gaps in accountability, hidden dependencies and single points of failure. You will work effectively with internal technical teams, business stakeholders and third-party partners while maintaining independent assurance and technical challenge.
Risk, Dependency and Recovery-Readiness Assurance
REQUIRED
You bring strong risk-assessment, dependency-analysis and problem-solving capabilities. You can identify architectural risks, technical debt, recovery constraints and delivery dependencies early, and communicate their significance clearly to technical and non-technical stakeholders. You have experience supporting recovery testing, cyber exercises, validation activity and recovery-readiness assessments, including review of recovery runbooks, methodologies and test approaches.
Stakeholder Management and Technical Communication
REQUIRED
You are an effective stakeholder manager and communicator who can explain complex technical architecture, recovery risks and design trade-offs in clear, decision-ready language. You produce high-quality architecture assurance reports, dependency assessments and technical documentation, and can engage credibly with senior stakeholders, technical specialists, suppliers and governance forums.
GOOD TO HAVE - NOT A BLOCKER
WHY JOIN US?
This is an opportunity to play a pivotal technical leadership role in our client's Cyber Recovery Technology Programme. You will shape the target architecture and assurance approach for a strategically important recovery capability, influencing how technology, suppliers and recovery practices come together to protect critical business operations. The role offers significant scope to apply independent technical judgement, strengthen operational resilience and help establish a robust, best-practice foundation for cyber recovery.