About The Role
We are looking for a skilled Security Architect to join our Technology Architecture team. In this role, you will lead IT Security planning, design, governance, and assurance initiatives, ensuring alignment with the Security Reference Architecture. You will develop security product and application roadmaps, define long-term strategies, and design and govern Security Architecture for key programmes with a high strategic impact. As a Security Architect, you will collaborate with stakeholders across the organisation, attend Architecture and Technical Review boards, and provide expert guidance to ensure robust security solutions are in place.
Responsibilities
Planning and Design Activities
Define and maintain security architecture processes aligned with business, technology, and threat drivers.
Develop security strategy plans, roadmaps, and architecture artefacts, including models, templates, and standards.
Establish baseline security standards for operating systems, network segmentation, and identity and access management.
Contribute to standards for data encryption and tokenization based on data classification criteria.
Draft security procedures and standards for executive review and approval.
Establish a taxonomy of indicators of compromise (IOCs) and share insights with security teams.
Continuously monitor developments in digital business and threat environments to refine security strategies and artefacts.
Assurance
Validate IT infrastructure and reference architectures for security best practices and recommend improvements.
Ensure proper security configurations for infrastructure tools such as firewalls, IPSs, WAFs, and endpoint protection systems.
Facilitate threat modelling for services and applications tied to organisational risks.
Maintain accurate inventories of systems and applications logged in the SIEM.
Collaborate with DevOps to ensure secure coding practices and escalate risks as necessary.
Document sensitive data flows and recommend security controls, including encryption and tokenization.
Review network segmentation and ensure least privilege for network access (Zero Trust).
Support testing and validation of internal security controls and assess emerging security technologies.
Collaboration
Partner with vendor management to conduct security assessments of vendors, including SaaS, IaaS, MSPs, and payroll providers, ensuring adequate protections in contracts and SOWs.
Coordinate with operational and facility management teams to assess the security of operational technology (OT) and IoT systems.
Liaise with architects and practitioners to share best practices and insights.
Work with the business continuity management (BCM) team to validate security practices during failover operations.
Participate in application and infrastructure projects to provide security-planning guidance.
Collaborate with the internal audit team to evaluate the design and effectiveness of security-related controls.
About You
1. Educated to degree level or equivalent
2. Five to ten years experience in IT Security roles
3. Experience of working in similar enterprises to Morrisons with large technological footprints
4. Proven experience working and defining Security Reference Architectures and within large programmes
5. Experience driving Security Strategies and Initiatives in large enterprise
6. Experience working with cloud vendors (AWS, GCP, Azure) and driving security policies and guide rails
7. Experience working within a structured governance framework
8. IT Security Qualification such as CISA/CISSP or BCS and PCI/ISA qualification
Industry and Regulatory Experience
The security architect is expected to have documented experience with the following:
9. Payment Card Industry Data Security Standard (PCI-DSS)
10. General Data Protection Regulation (GDPR) and Privacy Practices
11. ISO 27001/2
12. Knowledge of OWASP 10
13. NIST Cybersecurity Framework (CSF)
14. CIS and Benchmarking
About The Team