Contract Description
£500 p/d outside IR35 GBP
Hybrid WORKING
Location: High Wycombe, Central London, Greater London - United Kingdom Type: Contract
Junior Security Architect - Defence
Contract: Initial contract
Rate: Up to £500 per day
Location: High Wycombe - two days onsite per week
Working Pattern: Hybrid - three days working remotely
Clearance: Active SC clearance required
We are looking for a Junior Security Architect / Security Consultant to support a major UK Defence digital programme developing cutting-edge AI and software applications for national security.
Working within a Through Life Support function, you will help maintain and assure a portfolio of live applications. The role combines security architecture, risk management and compliance within an Agile DevSecOps environment.
You will act as a first-line security SME, helping delivery teams embed security throughout the software development lifecycle and ensuring applications are delivered rapidly, responsibly and securely.
Key Responsibilities
• Support the implementation of Secure by Design principles across digital product teams.
• Maintain security cases and ensure assurance evidence remains accurate and current.
• Conduct continuous security risk assessments using recognised frameworks.
• Maintain product-level risk registers and track security remediation activities.
• Identify and escalate risks that fall outside agreed tolerances.
• Support the preparation of High-Level Designs, security governance documents and through-life management plans.
• Maintain Security Management Plans and supporting assurance artefacts.
• Help prepare a large portfolio of applications for security and architecture review boards.
• Support technical release-readiness assessments across Discovery, Alpha, Beta and Live phases.
• Contribute to Authority to Test, Interim Authority to Operate and Continuous Authority to Operate processes.
• Work closely with product owners, engineers, delivery leads, security assurers and accreditors.
• Support responsible AI governance in accordance with relevant Defence policies. Required Skills and Experience
• At least three years' experience within cyber security, information assurance or security architecture.
• Previous MOD or Defence experience.
• Active SC clearance.
• Strong understanding of security risk and compliance within government environments.
• Experience implementing or assessing Secure by Design principles.
• Knowledge of relevant MOD security policies and standards, including JSP 440, JSP 451 and JSP 453.
• Understanding of government security and assurance frameworks.
• Experience applying Cyber Assessment Framework principles.
• Knowledge of ISO 27001 and wider information security standards.
• Ability to produce and maintain security risk assessments, governance documents and assurance evidence.
• Strong organisation and time-management skills, with the ability to manage multiple applications and deadlines.
• Confident communication and stakeholder-management skills. Desirable Experience
• Experience working within Agile or DevSecOps software-development environments.
• Familiarity with the NIST Risk Management Framework.
• Experience using vulnerability and risk-management tools such as DefectDojo or Vigilant.
• Knowledge of GDS delivery phases and government accreditation processes.
• Exposure to AI security, responsible AI practices or JSP 936.
• Experience supporting complex Defence digital programmes. This opportunity would suit a Security Consultant, Security Analyst or Junior Security Architect looking to develop their architecture and assurance experience within a high-profile Defence environment.
Reach out to