Job Details

Cyber Security – Senior Enterprise Security Architect

Cyber Security – Senior Enterprise Security Architect

📍 London
Not Specified
Industry: Retail/Purchasing
Applications: <10
Posted: 06-10-2026
Company: DCV Technologies
Type: Contract
Reference: 225693477

Job Description:

Position: Cyber Security – Senior Enterprise Security Architect
Location: London, UK (Hybrid-4 days from office)
6 months contract position

Role overview:

We are seeking a seasoned, strategic, and hands-on Senior Enterprise Security Architect to lead the foundational implementation of the Centre for Internet Security (CIS) Critical Security Controls (CSC) across our entire enterprise. You will be the primary architect responsible for transitioning our security posture from current state to a robust, CIS-aligned framework, ensuring that security is deeply integrated into our infrastructure, cloud environments, and business operations.

Your responsibilities:  

Your Profile

Experience: 10+ years in Cybersecurity, with at least 5 years in a senior architecture or lead security role.

Framework Expertise: Deep, hands-on experience implementing CIS Critical Security Controls in large-scale enterprise environments.

Cloud Fluency: Demonstrated architectural design experience in secure cloud migrations and cloud-native security practices.

Automation: Strong belief in and experience with "Security as Code" principles; proficiency in scripting (Python, PowerShell) or Infrastructure as Code (Terraform, Ansible) to automate hardening.

Hardening Standards: Expert-level knowledge of CIS Benchmarks for operating systems (Linux/Windows), cloud platforms, and network devices.

Communication: Proven ability to bridge the gap between technical teams and business stakeholders, articulating security risks in plain language.

Senior Stakeholder Management – Proficient and experience in communication at executive levels within the organisation, reports, PowerPoint and presentation

Preferred Technical Proficiency Requirements

Professional Certifications

A successful candidate will ideally hold a mix of architectural-level and domain-specific certifications.

Category

Recommended Certifications

Architectural

CISSP-ISSAP (Information Systems Security Architecture Professional), TOGAF (The Open Group Architecture Framework)

Cloud-Specific

AWS Certified Security – Specialty, Microsoft Certified: Cybersecurity Architect Expert, Google Professional Cloud Security Engineer

General Security

CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager)

Familiarity with integrating CIS controls alongside other regulatory frameworks (NIST CSF, ISO 27001, SOC2, or HIPAA).

Technical/Auditor

GSEC (GIAC Security Essentials), GCIH (GIAC Certified Incident Handler), CISA (Certified Information Systems Auditor)

Program Management

Experience leading large-scale cross-functional security transformation programs

Strategic Impact: The Implementation Mindset

The ideal candidate will move beyond simple checklist compliance. They must understand how to:

  1. Prioritize via CIS Implementation Groups (IGs): Pragmatically apply IG1 (Essential Cyber Hygiene), IG2 (Advanced), and IG3 (Expert) based on the organization's specific risk profile.
  2. Measure Efficacy: Define KPIs for each control (e.g., "Percentage of endpoints with auto-patching enabled") to report progress to the Board.
  3. Automation First: Ensure that every security control, where possible, is deployed via automated pipelines rather than manual "click-ops," ensuring consistency across thousands of assets.
Apply Now