Morrisons Head Office
2 days ago
Technology Manager - Security Architecture

We are looking for a skilled Security Architect to join our Technology Architecture team. In this role, you will lead IT Security planning, design, governance, and assurance initiatives, ensuring alignment with the Security Reference Architecture. You will develop security product and application roadmaps, define long-term strategies, and design and govern Security Architecture for key programmes with a high strategic impact. As a Security Architect, you will collaborate with stakeholders across the organisation, attend Architecture and Technical Review boards, and provide expert guidance to ensure robust security solutions are in place.

 

Responsibilities

Planning and Design Activities

• Define and maintain security architecture processes aligned with business, technology, and threat drivers.

• Develop security strategy plans, roadmaps, and architecture artefacts, including models, templates, and standards.

• Establish baseline security standards for operating systems, network segmentation, and identity and access management.

• Contribute to standards for data encryption and tokenization based on data classification criteria.

• Draft security procedures and standards for executive review and approval.

• Establish a taxonomy of indicators of compromise (IOCs) and share insights with security teams.

• Continuously monitor developments in digital business and threat environments to refine security strategies and artefacts.

 

Assurance

• Validate IT infrastructure and reference architectures for security best practices and recommend improvements.

• Ensure proper security configurations for infrastructure tools such as firewalls, IPSs, WAFs, and endpoint protection systems.

• Facilitate threat modelling for services and applications tied to organisational risks.

• Maintain accurate inventories of systems and applications logged in the SIEM.

• Collaborate with DevOps to ensure secure coding practices and escalate risks as necessary.

• Document sensitive data flows and recommend security controls, including encryption and tokenization.

• Review network segmentation and ensure least privilege for network access (Zero Trust).

• Support testing and validation of internal security controls and assess emerging security technologies.

 

Collaboration

• Partner with vendor management to conduct security assessments of vendors, including SaaS, IaaS, MSPs, and payroll providers, ensuring adequate protections in contracts and SOWs.

• Coordinate with operational and facility management teams to assess the security of operational technology (OT) and IoT systems.

• Liaise with architects and practitioners to share best practices and insights.

• Work with the business continuity management (BCM) team to validate security practices during failover operations.

• Participate in application and infrastructure projects to provide security-planning guidance.

• Collaborate with the internal audit team to evaluate the design and effectiveness of security-related controls.

 

Confirm your E-mail: Send Email