Enterprise Security Architect (Financial Services)
My client, a Financial Services firm, based in London, is looking for an Enterprise Security Architect, to join their growing team. You would have to work two days per week in London.
Job purpose:
My client is seeking a highly skilled and strategic Enterprise Security Architect reporting to the Enterprise Security Architecture Manager, to lead the design, implementation, and continuous improvement of Security Architecture across the enterprise. In this role, you will collaborate with senior leadership, key stakeholders, and cross-functional teams to define and align security strategies with business objectives, ensuring security alignment to business objectives, evolving threat landscapes, and industry standards across the enterprise to mitigate risks and address emerging threats.
The Enterprise Security Architect will play a pivotal role in developing and enforcing the enterprise security architecture strategy and roadmap, developing patterns and conducting capability gap assessments whilst maintaining integration into the companys business and technology landscape. You will be responsible for maturing the security architecture practice, defining principles and input into policies and standards that span multiple business domains and technical environments, including cloud, infrastructure, and applications.
This position requires deep expertise in security architecture, a strong understanding of risk management, and the ability to influence and guide key decisions at the enterprise level.
Key responsibilities include:
* Lead the development and execution of the enterprise security architecture strategy and roadmaps, working closely with senior leadership, Enterprise Architecture, and technical teams to align security initiatives with broader business goals.
* Drive the integration of security across the enterprise.
* Champion security across multiple divisions, ensuring security is embedded into the design and implementation of products, services, and technology solutions.
* Provide thought leadership and guidance on security risks, policies, and controls to senior management and stakeholders, influencing key business decisions.
* Collaborate with internal and external stakeholders to ensure the security architecture supports business objectives, ensuring scalability, compliance, and future state.
* Develop and enforce security architecture frameworks, policies, and standards to guide the secure implementation of IT solutions across the enterprise, with particular emphasis on Cloud Security, SaaS, and IaaS models, ensuring alignment with industry best practices and evolving regulatory requirements.
* Familiarity with SABSA framework and its six layers, particularly in risk management and security strategy development.
* Lead efforts to assess and mature security practices across the enterprise.
* Stay abreast of industry trends, frameworks, and regulations (e.g., GDPR, ISO 27001/2, SANS Top 20 Critical Security Controls, NIST CSF, SP 800-53, PFMI, CPMI ISOCO and FFIEC handbook, SABSA) to ensure the organization is proactive in addressing emerging security threats and compliance challenges.
* Foster relationships with key functional teams such as IT, Compliance, Operations, Finance, HR, Internal Audit, and Enterprise Risk to support current and future initiatives.
* Keep informed of new and emerging security threats & assess effectiveness of current controls to identify opportunities for program improvement.
* Provide expert-level security architecture design, analysis, and consultation to enterprise-wide programs, ensuring security risks are appropriately mitigated during the planning and design stages.
* Work closely with technology teams, including Infrastructure, Cloud, Development, and Security, to embed security into solutions from the outset.
* Oversee and guide assessments of new technologies, vendors, and third-party services to ensure compliance with enterprise security standards and reduce potential risk exposure.
* Lead and guide project and program managers to ensure the integration of security architecture across various initiatives, with a focus on scalability, compliance, and risk management.
* Define, monitor, and enforce security architecture governance processes to ensure that security standards and controls are met across the enterprise.
Knowledge, skills and abilities:
* 8+ years of experience in information security, with a strong background in security architecture across large, complex enterprise environments.
* Proven ability to design, implement, and lead security initiatives across cloud, network, application, and infrastructure domains.
* Extensive experience working with senior leadership and stakeholders to drive strategic security initiatives, influencing decisions at the enterprise level.
* Strong understanding of security frameworks, including NIST CSF, SABSA etc, and the ability to apply them in diverse environments.
Qualifications and certifications:
* Degree in a technology discipline (Computer Science, Information Management, Computer Engineering, Cybersecurity or equivalent).
* Professional certifications such as CISSP, CISA, CISM, CRISC, SABSA, or equivalent.
* Deep expertise in risk management frameworks, including ISO 27001, NIST SP 800-53, and SANS Top 20 Critical Security Controls.
* Experience with cloud security solutions and services.
If this role is of interest please apply to this job advertisement or call me on 0207 509 8040.
About the job
Contract Type: FULL_TIME
Focus: Information Security
Workplace Type: Hybrid
Experience Level: Director
Location: London
Salary: £140,000 - £160,000 per annum
Job Reference: USK5DA-11D77E58
Date posted: 4 April 2025
Consultant: Darius Goodarzi
J-18808-Ljbffr