skip navigation
skip mega-menu

Security Architect - NS&I - G7

Government Digital & Data -

Full-time (Permanent)
National minimum £57,500 London minimum £66,000
Published on
24 April 2025
Deadline
21 May 2025

The Security Architect is a key role in the Enterprise Architecture (EA) team, defining and assessing the organisation's security architecture strategy, high level architectures, and practices. The Security Architect will be required to effectively translate business objectives and risk management strategies into secure designs and services.  They are also key to ensuring that solutions proposed are aligned with NS&I ‘cloud-native’ and ‘secure by design’ principles, and for identifying opportunities for exploiting emerging technologies and supporting their safe use aligned to NS&I’s risk appetite while supporting NS&Is “fast follower” ambition.

 The Security Architect evaluates services, suppliers, applications and security tools, from a technical and security architecture perspective, and translates the risk characteristics of these activities and functions into enterprise risk terms.

Job description

Plan and design security architectures to support the delivery of NS&I’s Business goals:

  • Design and develop NS&I’s security architecture, enabling NS&I and service providers to implement solutions and capabilities in accordance with NS&I security policy.
  • Develop security architecture strategies and roadmaps.
  • Develop and maintain security architecture artefacts (e.g. principles, models, templates and standards) to be used to leverage security capabilities in projects and operations.
  • Support the review and approval of designs at appropriate design authorities from a security perspective.
  • Review technologies, tools and services, and make recommendations to the design authority for their implementation, based on security and operational metrics.
  • Liaise with other security practitioners to share best practices and insights.
  • Contribute to Enterprise Architecture development and implementation.
  • Track developments and changes in the business and external environments to ensure that they are addressed in security architecture artefacts.
  • Validate IT infrastructure and other reference architectures against security best practices and recommend changes, where applicable.

Engage with subject matter experts across NS&I and its delivery partners to deliver secure systems and operations:

  • Liaise with delivery partner architects to ensure the most appropriate, lowest impact security solution designs are selected (e.g. in terms of cost, complexity or feasibility).
  • Evaluate supplier designs to ensure they align with NS&I’s design standards and target architecture from a security perspective.
  • Work with and the internal Security team and wider Risk Directorate to ensure that security risks identified in designs are within the organisational risk appetite, and that the NS&I Corporate Risk Management Framework is followed.

Assure conformance with appropriate standards, principles and governance:

  • Validate that the design of solutions allows for appropriate security controls to be included, can meet the risk appetite of the organisation, and are aligned to best practise.
  • Coordinate with the Data Architect to document sensitive data flows in the organisation (e.g. PII (Personally Identifiable Information) ) and recommend controls to ensure that this data is appropriately protected (e.g. encryption and tokenization).
  • Support project deliveries in making sure that any changes to the security architecture are understood holistically, and the changes being implemented follow the architectural principles and align with the business strategies.
  • Assess solutions against NS&I Security Architecture Principles.
  • Support Design Change Governance and Assessment of Change Materiality.
  • Identify, define and manage relevant architectural waivers and risks.
  • Contribute to the definition of risk mitigation plans, where appropriate.

Relationships

Listed below are the jobs and areas with which the post interacts.

Internal

Information Technology

EA and Change Delivery

SIAM

Business Delivery Directorate & Operations

Risk Directorate

Supplier Management

SOC Manager and SOC staff

External

3rd Party delivery teams and service providers

Person specification

Essential experience:

  • (Lead Criteria) Experience of working in complex outsourced environments using a wide range of technology, combined with public sector constraints around solution options and governance requirements
  • Significant experience of defining security architecture and governance principles in an organisation, and the assurance processes to monitor compliance.
  • Considerable experience of IT system delivery projects (following both agile and waterfall methodologies) and implementing security within those deliveries.

Essential technical knowledge and skills:

  • Significant experience of supporting the implementation of a secure, public cloud and SaaS solutions in large, complex organisations.
  • Strong working knowledge of implementing security infrastructure
  • Strong working knowledge of vulnerability management tools

Desirable qualifications, experience and technical knowledge / skills:

  • Degree in computer science, information systems, cybersecurity or a related field.
  • Experience in using architecture methodologies such as TOGAF and preferably TOGAF certified.

Knowledge of:

  • IST Cybersecurity Framework (CSF);
  • NCSC guidance and best practice;
  • General Data Protection Regulation (GDPR) and the Data Protection Act (DPA);


Technical skills

We'll assess you against these technical skills during the selection process:

  • Successful candidates at sift will be assessed on their knowledge of the data processes outlined within the essential criteria.
  • Presentation

More jobs at Government Digital & Data

Lead Business Analyst-Department for Transport
£51,997
Full-time (Permanent)
Technical Architect Vehicle Certification Agency-SEO
£57,400
Full-time (Permanent)
Software Engineer - ONS - HEO
£32,452
Full-time (Permanent)
IT Support Engineer - Met Office - EO
£26,954 - £29,531
Full-time (Permanent)
DDaT Senior BI Design & Integration Manager - MoD - SEO
£43,080
Full-time (Permanent)
Lead Applied AI Engineer (i.AI) - CO - G6
£67,126 - £103,924
Full-time (Permanent)
DDAT Lead Technical Architect - MoD - G7
£57,670 - This post is eligible for a Digital Skills Allowance of up to £15,300 per annum
Full-time (Permanent)
Interaction Design Industrial Placement 2025 - Met Office - AO
£25,606
Full-time (Permanent)
Lead DevOps Engineer - DWP - G6
£72,664 - £89,995
Full-time (Permanent)
Software Development Engineer In Test (Automation Test Engineer
Full-time (Permanent)
Software Developer in Test - HM Courts and Tribunals Service - SEO
£41,463 - £52,040 location dependant. Offers above will be an additional GDD allowance based on experience.
Full-time (Permanent)
Software Developer in Test - HM Courts and Tribunals Service - SEO
£41,463 - £52,040 location dependant. Offers above will be an additional GDD allowance based on experience.
Full-time (Permanent)
Software Developer - HM Courts and Tribunals Service - SEO
The national salary range is £41,463 - £45,276, London salary range is £47,657 - £52,040.
Full-time (Permanent)
Defence Business Services (DBS) Senior Technical Architect - MoD - SEO
The base salary for this grade is £44,590, Offers above this will be made up of DSA , Digital Skill allowance of up to £11,400
Full-time (Permanent)
Interaction Designer - Planning Inspectorate - SEO
£45,219 - £49,462
Full-time (Permanent)
Systems Solution Lead - NS&I - G7
National minimum £53,000 London minimum £57,800
Full-time (Permanent)
Senior Test Engineer - Companies House - HEO
Base salary is £40,398 with an additional DDaT allowance of £4,350 - £11,000 available.
Full-time (Permanent)
Junior Software Developer Cross Cutting - HM Courts and Tribunals Service - HEO
The national salary range is £34,140 - £37,105. London salary range is £38,661- £42,019.
Full-time (Permanent)
Technical Architect Home Office Biometrics - HO - SEO
£48,720 - £52,130. You may be eligible for an additional non-pensionable allowance, pending a Capability and Skills assessment, with a value of up to £8,680.
Full-time (Permanent)
Principal Data Architect, Police and Public Protection Technology - HO - G6
£73,900 - £85,690. You may be eligible for an additional non-pensionable allowance, pending a Capability and Skills assessment, with a value of up to £21,700.
Full-time (Permanent)
DDAT Army Design Authority Assistant Head Information Architect - MoD - G7
£59,690 DDAT Allowance (Digital Skills Allowance) of up to £15,300 per annum
Full-time (Permanent)
Test Engineer - Social Security Scotland - HEO
£36,944 - £42,244
Full-time (Permanent)
Lead Performance Test Engineer - Companies House - SEO
Base salary is £41,571 - £45,784 with an additional DDaT allowance of £4,350 - £11,000 available.
Full-time (Permanent)
Defence Business Services (DBS) Junior Test Engineer - MoD - EO
£29,580
Full-time (Permanent)
Consultation UX/Interaction Designer - HSE - HEO
£36,235 - £39,611
Full-time (Permanent)
Associate Interaction Designer Industrial Placement - HMRC - EO
£29,475 - £31,536
Full-time (Permanent)
Content Designer - Welsh Revenue Authority - HEO
£35,787 - £43,758
Full-time (Permanent)
Software Developer - Companies House - EO
£40,398
Full-time (Permanent)
Technical Architect (UKSV) - CO - G7
£55,403 - £61,939 Allowance values range up to £23,691 with the highest reserved for candidates whose capability is above the expected level for all of the skills.
Full-time (Permanent)
Technical Architect - CO - G7
£55,403 - £61,939
Full-time (Permanent)
Senior DevOps Engineer - HSE - SEO
£45,954 - £53,265
Full-time (Permanent)
Data Architect - HSE - G7
£60,760 - £65,776
Full-time (Permanent)
Test Engineer - DVSA - HEO
£34,233
Full-time (Permanent)
Test Engineer - College of Policing - SEO
Nation £35,074 London £40,112
Full-time (Permanent)
Test Engineer - HM Courts and Tribunals Service - HEO
The national salary range is £34,140 - £37,105, London salary range is £38,661 - £42,019.
Full-time (Permanent)
Head of Test (QA Lead) - MoJ - G6
National salary range is £68,967 - £78,842, London salary range is £73,115- £83,585, additional allowance may apply
Full-time (Permanent)
Junior Software Developer Industrial Placement - HMRC - EO
£29,475
Full-time (Permanent)
Senior Technical Architect - DfE - G7
£56,353 London: £60,373 This post is eligible for a Digital, Data and Technology (DDT) capability based pay (CBP) allowance.
Full-time (Permanent)
Defence Business Services (DBS) AG Lead Technical Architect
£59,690. Offers above this will be made up of DSA , Digital Skill allowance of up to £15,300
Full-time (Permanent)

Subscribe to our newsletter

Sign up here