Cyber Security Architect
Location: Ipswich, GB
Reference Number - 79372
This Cyber Security Architect will report to the Cyber Security Architecture Manager and will work within the Information Systems directorate based in either our Fore Hamlet, Ipswich or Crawley or London office. You will be a permanent employee.
You will attract a salary of £57,600.00 and a bonus of 7.5%. This role can also offer blended working after probationary period (6 months) - 3 days in the office and 2 remote
Close Date: 07/08/2024
We also provide the following additional benefits
-
25 Days Annual Leave plus bank holidays
-
Personal Pension Plan - Personal contribution rates of 4% or 5% (UK Power Networks will make a corresponding contribution of 8% or 10%)
-
Tenancy Loan Deposit scheme
-
Tax efficient benefits: cycle to work scheme
-
Season ticket loan
-
Occupational Health support
JOB PURPOSE:
You will develop the security systems and policies within the organisation and will ensure that UK Power Networks data, network, and systems are protected from cyber threats and will comply with the relevant standards and regulations.
DIMENSIONS:
UK Power Networks is expanding its presence in Microsoft Azure and enhancing its on-prem OT Mission Critical Systems. It is necessary that a secure environment is developed for the hosting and management of our critical information assets. We ask that you have a blend of skillsets across cyber security including solution design, configuration, implementation, operation, governance, change management, communications, and the understanding of protecting data in employing the use of relevant encryption standards.
-
People - work collaboratively in a team of circa 8 permanent and temporary cyber security architecture resources.
-
Communication - communicate technical cyber security concepts to all kinds of colleagues across different levels of seniority to facilitate and ensure common understanding of decisions taken across the business.
PRINCIPAL ACCOUNTABILITIES:
-
Implement the cyber security plans, technology roadmaps based on sound enterprise architecture practices to help implement UK Power Networks Cyber Security Strategy ensuring agreement to the company vision, values, and strategic goals.
-
Develop the security architecture framework including policies, standards, blueprints and procedures that enables the enterprise to develop and implement security solutions and capabilities in projects and operations that are aligned with business, technology, and threat drivers.
-
Participate in the Architecture Review Board (ARB) as the design authority for all cyber security for all cyber security matters through the review and approval of all solution proposals.
-
Create target and transition architectures which conform to best practice, and UKPN's Information Security policies and underpinning standards.
-
Translate our requirements into technical solutions, and communicate with product teams on your design.
-
Develop cloud security measurement tooling to manage cloud performance, resources, and cost to ensure budgetary compliance and make recommendations for improvement.
Qualifications:
-
Experience acquiring an understanding of cyber security technologies and principles within an operational technology (OT) environment or enterprise environments and utilising the security features of Azure Cloud, Microsoft 365, and other Cyber related Solutions.
-
Experience working as a Cyber Security Architect, OT Cyber Security Architect, Cloud Security Architect (DevSecOps) or relevant Cyber Engineering Role with Architecture responsibilities.
-
A degree in Computer Science, Computer Engineering, Information Technology, or relevant field with cognate experience designing, implementing, and supporting Cyber Security solutions.
-
Relevant security certifications such as Microsoft Azure Security Technologies (AZ-500), Azure Solutions Architect Expert or Further security certifications include CISSP, CISSP-ISSAP, CCSP, CCSK, or CompTIA are desirable.
-
Containerisation experience with Azure Kubernetes Service (AKS) and Docker, including the use of tools such as Vagrant and LXC
-
Experience with Infrastructure as Code (IaC) Automation tools, such as Terraform and deploying "secure by design" IaC approach with the DevOps team.
-
Working knowledge of Cyber Essentials, ISO27001:2022, CSA Cloud Controls Matrix, NCSC CAF and GDPR, is important to ensure that data is being managed in a compliant manner.
-
Quality review solution providers high- and low-level solution designs ensuring they align to the data architecture and policies.
-
Proven experience of developing a credible and practical target architecture for the Security domain, which supports the Business and IT strategy.Experience working within a regulated environment, preferably Energy sector Critical National Infrastructure (CNI)