We are seeking an experienced and commercially minded Principal Security Architect to join an established a rapidly growing IT Service Provider. This is a senior client-facing role responsible for leading the design, assurance and delivery of complex security solutions across enterprise and public sector customers.
The successful candidate will act as a trusted advisor to C-level stakeholders, security leaders, and technical teams, helping clients develop and implement security strategies, architectures and operational capabilities that reduce risk and support business objectives.
A key focus of the role will be security monitoring and detection capabilities, with demonstrable expertise in Microsoft Sentinel, SIEM/SOAR design, security operations transformation and cloud-native security architectures.
Working closely with sales, delivery and technical teams, you will provide thought leadership, contribute to solution development, support pre-sales engagements and lead security architecture initiatives across a diverse customer base.
Key Responsibilities
Client Advisory & Leadership
- Act as the lead Security Architect across assigned Managed Services clients.
- Act as a trusted security advisor to client stakeholders, including CIOs, CISOs and security leadership teams.
- Lead security architecture engagements from discovery through design and implementation.
- Define security strategies, roadmaps, target architectures, and governance standards.
- Produce and assure HLDs, LLDs, and reference architectures aligned to Zero Trust and Secure by Design principles.
- Lead architecture for Microsoft Entra ID, Active Directory, Identity Governance, PIM, Conditional Access, SSO, Federation, and B2B/B2C identity.
- Provide architectural ownership across the Microsoft security stack, including Defender, Sentinel, Purview, Intune, Security Copilot, Azure Security, and Microsoft 365 Security & Compliance.
- Translate business requirements into secure, scalable and practical security solutions.
- Present architectural recommendations and security strategies to executive audiences.
- Lead security workshops, assessments and roadmap development activities.
Security Architecture
- Define and maintain enterprise security architectures aligned with business objectives.
- Design security controls across cloud, hybrid and on-premise environments.
- Develop security reference architectures, standards and patterns.
- Ensure solutions align with recognised frameworks including:
- NCSC Cyber Assessment Framework
- NIST Cyber Security Framework
- ISO 27001
- CIS Controls
- Zero Trust principles
Microsoft Security & Sentinel
- Lead the architecture, deployment and optimisation of Microsoft Sentinel environments.
- Design SIEM and SOAR solutions to enhance threat detection, incident response and operational efficiency.
- Create and optimise analytics rules, detection use cases, automation playbooks and dashboards.
- Drive security monitoring maturity programmes and SOC transformation initiatives.
- Integrate Sentinel with Microsoft Defender technologies and third-party security platforms.
- Advise clients on security operations processes, reporting and threat management.
Cloud Security
- Design secure cloud-native architectures across Microsoft Azure environments.
- Support cloud migration and transformation programmes.
- Define security controls covering:
- Identity and Access Management
- Privileged Access
- Data Protection
- Network Security
- Security Monitoring
- Threat Detection and Response
Pre-Sales & Business Development
- Support sales and account teams in developing cyber security opportunities.
- Lead technical discussions during bids, tenders and client presentations.
- Contribute to proposals, statements of work and solution documentation.
- Assist with service innovation and development of new cyber security offerings.
- Represent the organisation at client events, conferences and industry forums.
Governance & Assurance
- Perform architecture reviews and security assurance activities.
- Assess risk and provide pragmatic remediation recommendations.
- Produce high-quality architecture documentation and design artefacts.
- Provide technical leadership and mentoring to architects, consultants and engineers.
Essential Skills & Experience
Security Architecture
- Proven experience operating as a Lead, Principal or Enterprise Security Architect.
- Strong understanding of enterprise security architecture methodologies.
- Experience designing security solutions within large and complex organisations.
- Deep knowledge of security frameworks and regulatory requirements.
Microsoft Security Expertise
- Extensive experience with:
- Microsoft Sentinel
- Microsoft Defender XDR
- Microsoft Defender for Cloud
- Microsoft Entra ID
- Azure Security Services
- Microsoft Purview
Security Operations
- Strong understanding of:
- SIEM
- SOAR
- SOC Operations
- Threat Detection Engineering
- Incident Response
- Threat Intelligence
- Security Monitoring
Cloud & Infrastructure
- Strong Azure security architecture experience.
- Knowledge of hybrid cloud environments.
- Experience securing:
- Identity platforms
- Networks
- Endpoints
- Applications
- Data services
Consulting & Stakeholder Management
- Excellent client-facing and communication skills.
- Ability to engage effectively at Board, Executive and Technical levels.
- Strong workshop facilitation and presentation skills.
- Commercial awareness and experience supporting sales engagements.
Desirable Experience
- Managed Security Services (MSSP) environments.
- Security Operations Centre transformation programmes.
- DevSecOps and secure software development practices.
- OT/ICS security experience.
- Public sector, financial services or regulated industry experience.
- Experience working within a UK IT Services, Consulting or Systems Integrator organisation.
Certifications
Highly desirable certifications include:
- Microsoft Certified: Cybersecurity Architect Expert (SC-100)
- Microsoft Security Operations Analyst (SC-200)
- CISSP
- CCSP
- SABSA
- TOGAF
- Azure Solutions Architect Expert
- Certified Cloud Security Professional (CCSP)
- GIAC Security Certifications