Auf einen Blick
- Aufgaben: Leite die Sicherheitsarchitektur in einem spannenden Transformationsprogramm und forme die Zukunft der Technologie.
- Unternehmen: Innovatives IT-Beratungsunternehmen mit Fokus auf den öffentlichen Sektor.
- Vorteile: Flexible Arbeitszeiten, 25 Tage Urlaub, Weiterbildungsmöglichkeiten und ein unterstützendes Team.
- Weitere Informationen: Dynamisches Umfeld mit Spaß bei der Arbeit und Möglichkeiten zur persönlichen Entwicklung.
- Warum dieser Job: Gestalte Sicherheit von Anfang an und mache einen echten Unterschied in der Technologiebranche.
- Qualifikationen: Erfahrung in Sicherheitsarchitektur und fundierte Kenntnisse in Microsoft-Cloud-Technologien.
Das prognostizierte Gehalt liegt zwischen 63000 - 77000 € pro Jahr.
We are looking for an experienced Security Architect to join a major technology transformation programme and provide security architecture leadership across the full transformation lifecycle.
This is a key role responsible for defining and assuring the security architecture across identity, endpoints, Microsoft 365, applications, infrastructure, networks and migration activities.
You will work at the intersection of security, architecture and delivery, ensuring that appropriate security controls are embedded into both coexistence and target‑state designs without creating unnecessary barriers to practical delivery.
The programme will involve significant technology change and will need to operate across existing environments while progressively introducing new services and capabilities.
You will therefore play a critical role in ensuring that security is considered from the outset, rather than being treated as a final‑stage assurance activity.
You will establish the security principles, patterns and control requirements that underpin the programme, assess threats and risks across current and future states, and provide independent assurance over technical designs and migration approaches.
The successful candidate will bring strong technical security expertise together with sound risk judgement.
You will be comfortable challenging designs where necessary, but equally capable of finding pragmatic solutions that allow the programme to move forward while maintaining an appropriate level of security.
What you will do
- Establish and maintain the programme's security architecture principles, patterns, standards and control requirements.
- Define clear security design‑assurance criteria and ensure that technical designs are assessed consistently against agreed requirements.
- Assess threats, risks, vulnerabilities and control gaps across the current, coexistence, transition and target states.
- Develop proportionate security controls that support secure coexistence between existing environments and new target services.
- Define and assure Zero Trust principles across identity, devices, applications, data and network access.
- Establish security patterns for identity protection, privileged access, least privilege, Conditional Access and administrative boundaries.
- Work closely with the identity and directory architecture function to ensure that authentication, access and administrative controls are appropriately designed and secured.
- Define security requirements for endpoint, email, Microsoft 365, data, application and network architectures.
- Establish appropriate requirements for security logging, monitoring, alerting, threat detection and incident response.
- Review technical architecture and solution designs, identifying security weaknesses, control gaps, dependencies and areas requiring further assurance.
- Assess migration strategies and cutover approaches from a security perspective, ensuring that risks associated with transition between environments are understood and controlled.
- Review proposed security exceptions and deviations from established standards, documenting the rationale, residual risk, compensating controls and required treatments.
- Maintain visibility of significant security risks and ensure that appropriate owners and mitigation plans are established.
- Work with technical teams to develop practical remediation and risk‑treatment approaches rather than simply identifying problems.
- Ensure security requirements are incorporated into programme plans, technical designs, migration patterns, testing strategies and operational handover.
- Support security testing and assurance activities, including validation of security controls before major migrations or go‑live decisions.
- Provide security input into operational readiness, ensuring that monitoring, alerting, incident response and support arrangements are in place before services transition into production.
- Align programme designs with organisational security policies, information‑security standards, data‑protection obligations and relevant regulatory or assurance requirements.
- Maintain appropriate security architecture documentation, including HLDs, security principles, control matrices, threat models, risk assessments, exception records and architecture decision records.
- Provide clear security recommendations and risk‑based advice to programme leadership and senior stakeholders.
- Support continuous improvement of security controls as the transformation progresses and new risks, technologies and requirements emerge.
- The security challenge
This is a transformation programme where security needs to be built into the architecture while delivery continues at pace.
The programme will need to coexist with existing technology environments while introducing new identity, endpoint, productivity, application, infrastructure and network services.
This creates a range of security challenges around trust boundaries, authentication, privileged access, data protection, legacy dependencies, migration paths and operational control.
You will therefore need to take a risk‑based and pragmatic approach to security architecture.
The role is not about preventing change or applying controls without considering their operational impact.
Instead, you will help the programme understand the risks it is taking, identify appropriate controls and determine where residual risk can reasonably be accepted, mitigated or transferred.
You will be expected to challenge weak security decisions while also helping delivery teams find workable alternatives.
A key part of the role will be ensuring that security controls remain effective throughout the transition.
A design that is secure in the target state may not be appropriate during coexistence, and migration activities can introduce temporary risks that need to be explicitly understood and controlled.
Your role will be to make those risks visible and ensure that the programme has a clear path to managing them.
Requirements
We are looking for an experienced Security Architect with a strong background in Microsoft cloud and hybrid enterprise environments.
- Extensive experience working as a Security Architect across complex enterprise technology environments.
- Strong technical knowledge of Microsoft Entra ID, Microsoft 365, Azure, endpoint security, networks and application security.
- Strong understanding of hybrid and cloud security architectures and the challenges associated with transitioning from legacy environments.
- Proven experience applying Zero Trust, least privilege, privileged access and defence‑in‑depth principles.
- Strong knowledge of identity and access security, including authentication, Conditional Access, identity protection and administrative controls.
- Experience designing security controls across endpoints, email, data, applications, infrastructure and networks.
- Strong understanding of security logging, monitoring, threat detection and incident‑response requirements.
- Demonstrable experience in threat modelling, security risk assessment, control mapping and architecture assurance.
- Experience assessing security risks associated with migration, coexistence, cutover and transition activities.
- Understanding of data protection, information governance and relevant regulatory or assurance requirements.
- Experience reviewing security exceptions and developing pragmatic risk‑treatment or compensating‑control strategies.
- Strong technical writing skills, with experience producing security architecture documentation, risk assessments, threat models, control matrices and design‑assurance outputs.
- Experience working within formal architecture and security‑governance frameworks.
- Ability to translate technical security risks into clear business impacts, choices and recommendations.
- What we are looking for in you
You will be a pragmatic security professional who understands that effective security is about managing risk, not eliminating change.
You will have the technical depth to challenge architects and engineers, but also the judgement to understand delivery constraints and work collaboratively towards solutions.
You will be confident operating in an environment where information is incomplete and decisions need to be made based on a combination of evidence, risk and professional judgement.
You will be comfortable engaging with senior stakeholders and explaining complex security matters in straightforward language.
When a risk needs to be escalated, you will be able to clearly articulate the issue, potential impact, available options and your recommended approach.
You will also be able to distinguish between genuine security risks and theoretical concerns that do not warrant disproportionate controls.
Most importantly, you will be able to embed security by design while maintaining the momentum of a major transformation programme.
About Methods
Methods is a £100M+ IT Services Consultancy who has partnered with a range of central government departments and agencies to transform the way the public sector operates in the UK.
Established over 30 years ago and UK-based, we apply our skills in transformation, delivery, and collaboration from across the Methods Group, to create end‑to‑end business and technical solutions that are people‑centred, safe, and designed for the future.
Our human touch sets us apart from other consultancies, system integrators and software houses - with people, technology, and data at the heart of who we are, we believe in creating value and sustainability through everything we do for our clients, staff, communities, and the planet.
We support our clients in the success of their projects while working collaboratively to share skill sets and solve problems.
At Methods we have fun while working hard; we are not afraid of making mistakes and learning from them.
Predominantly focused on the public‑sector, Methods is now building a significant private sector client portfolio.
Methods was acquired by the Alten Group in early 2022.
What we offer
- Development - access to Linked In Learning, a management development programme, and training
- Wellness - 24/7 confidential employee assistance programme
- Flexible Working - including home working and part time
- Social - office parties, breakfast Tuesdays, monthly pizza Thursdays, Thirsty Thursdays, and commitment to charitable causes
- Time Off - 25 days of annual leave a year, plus bank holidays, with the option to buy 5 extra days each year
- Volunteering - 2 paid days per year to volunteer in our local communities or within a charity organisation
- #J-18808-Ljbffr
Security Architect - Entra ID/MS/Azure Arbeitgeber: Methods
Methods ist ein hervorragender Arbeitgeber, der seinen Mitarbeitern die Möglichkeit bietet, in einem unterstützenden und kollaborativen Umfeld zu wachsen. Mit einem klaren Fokus auf persönliche Entwicklung, spannenden Projekten im öffentlichen Sektor und einer Vielzahl von Vorteilen, einschließlich flexibler Arbeitszeiten und umfangreicher Weiterbildungsmöglichkeiten, schaffen wir eine Kultur, in der Lernen und Innovation gefördert werden. Unsere Mitarbeiter genießen nicht nur eine ausgewogene Work-Life-Balance, sondern auch die Chance, aktiv zur Verbesserung der Gesellschaft beizutragen.
StudySmarter Expertenrat🤫
Wir sind der Meinung, dass du so Security Architect - Entra ID/MS/Azure erhalten könntest
✨Netzwerken in der IT-Community
In der IT-Consulting-Welt sollten wir regelmäßig auf Veranstaltungen wie Tech-Meetups oder Konferenzen gehen. Hier können wir nicht nur unser Netzwerk erweitern, sondern auch direkt mit potenziellen Arbeitgebern ins Gespräch kommen und unser Interesse an einer Vollzeitstelle zeigen.
✨Online-Foren und Gruppen nutzen
Sich in Online-Foren und Communities wie Stack Overflow oder LinkedIn-Gruppen umzusehen, kann uns helfen, Insider-Tipps zu erhalten und Informationen über offene Stellen in der IT-Beratung zu sammeln. Vergiss nicht, aktiv zu werden und Fragen zu stellen oder dein Wissen zu teilen – das erhöht unsere Sichtbarkeit!
✨Direkt bei Methods bewerben
Viele Unternehmen, wie Methods, stemmen ihre Vollzeitstellen bevorzugt über ihre eigenen Karriere-Webseiten. Also, lass uns regelmäßig auf deren Seite vorbeischauen und uns direkt bewerben, statt nur die üblichen Jobportale zu nutzen.
✨Überzeugende Projekte zeigen
Wir sollten unser Portfolio oder relevante Projekte gut sichtbar machen, egal ob das auf Github, persönlich oder auf LinkedIn ist. Bei IT-Consulting-Stellen kommt es oft auf praktische Erfahrungen an, also lass uns zeigen, was wir können!
Wir glauben, dass du diese Fähigkeiten brauchst, um Security Architect - Entra ID/MS/Azure mit Bravour zu bestehen
Einige Tipps für deine Bewerbung 🫡
Zeige deine technischen Skills!:In der IT-Beratung zählen deine technischen Kenntnisse und Fähigkeiten. Achte darauf, relevante Programmiersprachen, Tools und Systeme in deinem Lebenslauf aufzulisten. Zeig auch, wenn du Zertifikate hast, die deine Kompetenz unterstützen – das könnte dir einen echten Vorteil verschaffen!
Verstehe die Branche!:Unterstreiche in deinem Anschreiben, dass du ein gutes Verständnis für aktuelle Trends und Herausforderungen in der IT-Branche hast. Zeig, dass du nicht nur die technischen Aspekte beherrschst, sondern auch die Bedürfnisse der Kunden erkennen und lösen kannst!
Deine Projekte zählen!:Falls du bereits an IT-Projekten gearbeitet hast, verlinke diese oder beschreibe sie in deinem Lebenslauf. Praktische Erfahrungen – sei es in Form von Praktika oder privaten Projekten – sind besonders wertvoll in der IT-Beratung. Zeige uns, was du kannst!
Individuelle Bewerbung ist der Schlüssel!:Jede Bewerbung sollte individuell auf Methods und die ausgeschriebene Position Security Architect - Entra ID/MS/Azure zugeschnitten sein. Teile uns mit, warum gerade du eine gute Wahl für unser Team bist. Das zeigt dein Engagement und deine Motivation, die über eine Standardbewerbung hinausgeht.
Wie man sich auf ein Vorstellungsgespräch bei Methods vorbereitet
✨Technische Vorbereitung ist alles!
Da du dich auf eine Vollzeitstelle in der IT-Beratung bewirbst, solltest du dir wirklich einen Überblick über die wichtigsten Tools und Technologien verschaffen, die in der Branche verwendet werden. Sei bereit, technische Fragen zu beantworten, die sich auf Software-Architektur oder Systemintegration beziehen könnten.
✨Praxisbeispiele parat haben
In der IT-Beratung ist es wichtig, konkrete Beispiele aus deiner bisherigen Erfahrung zu bringen. Überlege dir Projekte, bei denen du erfolgreich einen Kunden beraten hast oder Herausforderungen gelöst hast. Das zeigt, dass du nicht nur theoretisches Wissen hast, sondern auch in der Praxis erfolgreich sein kannst.
✨Soft Skills betonen
Ein großer Teil der IT-Beratung ist die Kommunikation mit Kunden und das Verständnis ihrer Bedürfnisse. Bereite dich darauf vor, über deine zwischenmenschlichen Fähigkeiten zu sprechen, wie du mit herausfordernden Kunden umgehst oder wie du in Teams arbeitest. Das wird den Interviewern zeigen, dass du mehr als nur technisches Wissen mitbringst!
✨Fragen zum Unternehmen vorbereiten
Schau dir spezifisch die Projekte von Methods an und überlege dir, welche Fragen du dazu stellen möchtest. Zeig Interesse an den aktuellen Herausforderungen, vor denen das Unternehmen steht, und wie du dazu beitragen könntest. Das hebt dich von anderen Bewerbern ab und zeigt, dass du wirklich motiviert bist.