Principal Enterprise Security Architect

Here at Tesco Cyber, we are seeking a highly skilled and experienced Enterprise Security Architect, who will be responsible for ensuring that all enterprise-built platforms and solutions align with our existing security framework and industry standards. This role requires a deep understanding of security principles, technologies, and best practices to protect our information assets and ensure compliance with regulatory requirements. The focus will be on collaborating with key stakeholders across various domains to enable our technology colleagues to work efficiently and manage their environments effectively. You will perform comprehensive risk assessments, develop strategies to mitigate threats, and ensure alignment with organizational security principles and best practices.

You will be responsible for:

Design and implement robust security architectures for enterprise-wide capabilities, which our technology teams rely on regularly to operate their services and perform their day-to-day tasks efficiently, addressing identified threats and vulnerabilities.
Conduct thorough risk assessments for new systems and existing environments, reviewing their designs and architectures to ensure they meet modern security requirements, identifying security risks, and recommending mitigation strategies.
Influence and guide other teams to implement security solutions by collaborating across functions to integrate security principles and ensure systems align with business needs.
Ensure all enterprise-built platforms align with our existing security framework and industry standards, while collaborating with other enabling and architecture teams to integrate security into all aspects of the organization's operations.
Evaluate and enhance security processes to improve their efficiency and comprehensiveness.
Continuously monitor and respond to emerging security trends and threats to workplace environments, virtualization technologies, and databases.
Develop and maintain security architecture documentation, including policies, diagrams, and procedural guides.
Act as an SME and advise on the security of the M365 platform, workplace solutions, and infrastructure control plane capabilities such as virtualization layers (VMWare).
Lead and participate in internal technology initiatives to implement secure enterprise systems, ensuring alignment with security frameworks and organizational goals to enhance security posture.

You will need:

Soft Skills:

Proven leadership experience as a technical individual contributor in complex organizations.
Analytical mindset with a proactive approach to identifying and solving security challenges.
Strong communication and interpersonal skills to articulate complex security concepts to diverse audiences.
Ability to work collaboratively with cross-functional teams while managing multiple initiatives.
Demonstrated curiosity and flexibility in applying knowledge and advice.

Technical Skills:

Demonstrable experience and expertise in designing, implementing, and applying balanced controls from security frameworks such as NIST, CIS, ISO 27001, and MITRE.
Expertise in security controls and best practices for cloud-based workplace environments.
Proficiency in Microsoft 365 security, compliance capabilities, identity and access management, and threat protection, including Microsoft Defender, Microsoft Entra, and Microsoft Purview.
Expertise with virtualization platforms, ideally on VMware security solutions, including VMware NSX, VMware Carbon Black Cloud, and Horizon.
Familiarity with virtualization security best practices and endpoint security.
Proficiency in securing databases (e.g., SQL, NoSQL), with a focus on encryption, authentication, and monitoring solutions.
Proficiency in risk analysis, security controls management planning, and disaster recovery planning.
Experience with security technologies such as firewalls, intrusion detection/prevention systems, and encryption.

Qualifications & Experience:

Strong knowledge of security frameworks and standards (e.g., NIST, ISO 27001).
Bachelor's degree in Computer Science, Information Technology, or a related field.
Minimum of 10 years of experience in information security, with at least 5 years in a security architecture role.
Professional certifications such as SABSA, CISSP, CISM, or TOGAF are highly desirable.
Professional certifications in risk management such as CRISC are desirable.

What's in it for you:

We’re all about the little helps. That’s why we make sure our Tesco colleague benefits package takes care of you – both in and out of work. Click Here to find out more!

Annual bonus scheme of up to 45% of base salary
Car Cash Allowance
Holiday starting at 25 days plus a personal day (plus Bank holidays)
Private medical insurance
Retirement savings plan - save between 6% - 10% and Tesco will contribute 1.5 times this amount
26 weeks maternity and adoption leave (after 1 years’ service) at full pay, followed by 13 weeks of Statutory Maternity Pay or Statutory Adoption Pay, we also offer 6 weeks fully paid paternity leave

About us:

Our vision at Tesco is to become every customer's favourite way to shop, whether they are at home or out on the move. Our core purpose is 'Serving our customers, communities and planet a little better every day'. Serving means more than a transactional relationship with our customers. It means acting as a responsible and sustainable business for all stakeholders, for the communities we are part of and for the planet.

We are proud to have an inclusive culture at Tesco where everyone truly feels able to be themselves. At Tesco, we not only celebrate diversity, but recognise the value and opportunity it brings. We're committed to creating a workplace where differences are valued, and make sure that all colleagues are given the same opportunities. We're a big business with diverse working patterns and many business areas which means that we can find something that works for you. Everyone is welcome at Tesco.

We have recently announced that we will be moving towards a more blended working week – combining office and remote working. Our offices will continue to be where we connect, collaborate and innovate. Please talk to us to about how this can work for you.

NOTE: Should you be successful in your application, your offer will be subject to and conditional upon you providing your bank account details on your agreed start date.

We're proud to have been accredited Disability Confident Leader and we're committed to providing a fully inclusive and accessible recruitment process. For further information on the accessibility support we can offer, please visit https://www.tesco-careers.com/accessibility

Search again

Cart

Your cart contains 0 jobs.

View/apply for these jobs

Save search

Save this search and get email alerts for jobs matching your selections.

email alerts

Share this job

For job seekers

If you're in the job market, it can be a worrying time with the turmoil caused by the pandemic. You should be registering with consultants you can trust. We can't guarantee our ability to help you, but we can guarantee to safeguard your details. If we get in touch with you it's because there's a role we need to discuss. If we don't, then we'll keep your details live pending future positions.

job seekers

For recruiters

RHR has specialist teams in most sectors, from manufacturing to hospitality and from public sector through to retail. We recruit managers and professionals in a wide range of functions, specifically, general management, digital marketing, HR, finance, procurement and supply chain. We have traded for over 30 years and have an enviable reputation for delivery, honesty and integrity.

recruiters