We are looking for a skilled Security Architect to join our Technology Architecture team. In this role, you will lead IT Security planning, design, governance, and assurance initiatives, ensuring alignment with the Security Reference Architecture. You will develop security product and application roadmaps, define long-term strategies, and design and govern Security Architecture for key programmes with a high strategic impact. As a Security Architect, you will collaborate with stakeholders across the organisation, attend Architecture and Technical Review boards, and provide expert guidance to ensure robust security solutions are in place.
Responsibilities
Planning and Design Activities
• Define and maintain security architecture processes aligned with business, technology, and threat drivers.
• Develop security strategy plans, roadmaps, and architecture artefacts, including models, templates, and standards.
• Establish baseline security standards for operating systems, network segmentation, and identity and access management.
• Contribute to standards for data encryption and tokenization based on data classification criteria.
• Draft security procedures and standards for executive review and approval.
• Establish a taxonomy of indicators of compromise (IOCs) and share insights with security teams.
• Continuously monitor developments in digital business and threat environments to refine security strategies and artefacts.
Assurance
• Validate IT infrastructure and reference architectures for security best practices and recommend improvements.
• Ensure proper security configurations for infrastructure tools such as firewalls, IPSs, WAFs, and endpoint protection systems.
• Facilitate threat modelling for services and applications tied to organisational risks.
• Maintain accurate inventories of systems and applications logged in the SIEM.
• Collaborate with DevOps to ensure secure coding practices and escalate risks as necessary.
• Document sensitive data flows and recommend security controls, including encryption and tokenization.
• Review network segmentation and ensure least privilege for network access (Zero Trust).
• Support testing and validation of internal security controls and assess emerging security technologies.
Collaboration
• Partner with vendor management to conduct security assessments of vendors, including SaaS, IaaS, MSPs, and payroll providers, ensuring adequate protections in contracts and SOWs.
• Coordinate with operational and facility management teams to assess the security of operational technology (OT) and IoT systems.
• Liaise with architects and practitioners to share best practices and insights.
• Work with the business continuity management (BCM) team to validate security practices during failover operations.
• Participate in application and infrastructure projects to provide security-planning guidance.
• Collaborate with the internal audit team to evaluate the design and effectiveness of security-related controls.
Role-specific knowledge, skills & experience:
* Educated to degree level or equivalent
* Five to ten years experience in IT Security roles
* Experience of working in similar enterprises to Morrisons with large technological footprints
* Proven experience working and defining Security Reference Architectures and within large programmes
* Experience driving Security Strategies and Initiatives in large enterprise
* Experience working with cloud vendors (AWS, GCP, Azure) and driving security policies and guide rails
* Experience working within a structured governance framework
* IT Security Qualification such as CISA/CISSP or BCS and PCI/ISA qualification
Industry and Regulatory Experience
The security architect is expected to have documented experience with the following:
Regulations, Standards and Frameworks
* Payment Card Industry Data Security Standard (PCI-DSS)
* General Data Protection Regulation (GDPR) and Privacy Practices
* ISO 27001/2
* Knowledge of OWASP 10
* NIST Cybersecurity Framework (CSF)
* CIS and Benchmarking
By joining Morrisons, you not only become an essential asset to our success but also open doors to a future where your professional journey aligns with the scale and diversity of our thriving business. It's not just a job; it's a pathway to a fulfilling and progressive career within one of the UK's leading retailers.
We want all colleagues to be able to bring their best selves to work, you can expect to enjoy (Just to name a few):
* 4 and half day work week
* Flexible remote working options
* 15% colleague discount in stores and online, plus an additional 10% card for a friend or family member
* Annual bonus scheme
* Generous holiday entitlement
* Company pension contributions
* Private healthcare
* Perks with over 850 retailers
* Free onsite parking
If you're interested, please apply with your CV or alternatively contact me directly on jessica.2.kaur@morrisonsplc.o.uk