Job summary
- Main area
- Security Architect
- Grade
- Civil Service: Grade 7
- Contract
- Permanent
- Hours
- Full time
- Part time
- Job share
- Flexible working
- Home or remote working
- Job ref
- 919-CW-303679-EXT
- Employer
- UK Health Security Agency
- Employer type
- Public (Non NHS)
- Site
- Home working
- Town
- Any
- Salary
- £54,416 - £68,344 Per Annum,Pro Rata. Plus up to £15000 MPS to be reviewed 31st March 2026
- Salary period
- Yearly
- Closing
- 10/07/2025 23:59
Employer heading

Lead Security Architect
Civil Service: Grade 7
Job overview
UKHSA’s Cyber Security Architecture Delivery team is responsible for defining cyber security technical standards for the organisation, providing technical guidance and consulting to help service teams to deliver against those standards, and supporting the selection of security tools and technology.
The team (of ten) works across the organisation to support projects to ensure that solutions (predominantly AWS & Azure) are securely designed, identifying threats and where appropriate working with pen test teams to scope testing.
As Lead Security Architect, you will be responsible for overseeing the secure delivery of projects and data platforms; ensuring architectural design reviews (HLD/LLD) and threat models are carried out to a high standard. It is an exciting, fast-paced role that will drive strategic change across the organisation both in terms of data and analytic capability, and culture.
You’ll work closely with a variety of stakeholders including business leads, project managers, delivery partners - as well as multi-disciplinary Technology teams who build and run services.
Main duties of the job
The Cyber Security Architecture Delivery team is a mix of permanent civil servants (Two Lead Security Architects and Head of department) and contract Security Architects (6 to 10)
As Lead Security Architect you will:
- Work closely with security architects, overseeing their work and providing assurance that architectural design reviews and threat models are carried out consistently to the required standard
- Ensure the team have the appropriate blueprints, guidance, policies and standards required to complete their work.
- Take a risk based and outcome driven approach to secure architecture
- Develop and communicate meaningful security policies
- Identify and promote best practices for multidisciplinary teams to deliver resilient, secure and scalable services
- Identify, own, and respond to security risks and issues as they arise
- Cultivate and maintain relationships with other security teams within UKHSA, Cabinet Office, NCSC and the rest of government
- Ensure all work is in line with DSPT-CAF compliance and the security architecture framework (blueprints, standards etc…) are maintained.
Working for our organisation
We pride ourselves as being an employer of choice, where Everyone Matters promoting equality of opportunity to actively encourage applications from everyone, including groups currently underrepresented in our workforce. UKHSA ethos is to be an inclusive organisation for all our staff and stakeholders. To create, nurture and sustain an inclusive culture, where differences drive innovative solutions to meet the needs of our workforce and wider communities. We do this through celebrating and protecting differences by removing barriers and promoting equity and equality of opportunity for all. Please visit our careers site for more information https://gov.uk/ukhsa/careers
Detailed job description and main responsibilities
Essential criteria
You will be assessed on the below four essential criteria, which have been selected from the Job Description Document.
- Can demonstrate cyber security knowledge in a previous hands-on role, especially working within big programmes, and have experience of security management and information assurance practices
- Has experience with modern software engineering practices and cloud infrastructure, including building, managing and deploying modern web services
- Understands security end-to-end, from security considerations in the design of services, through to architecture reviews, threat modelling, controls and remediation against existing live services
- Builds strong relationships and communicates effectively with senior stakeholders and colleagues, ensuring that security considerations are well accounted for and built into ways of working
Selection Process Details
This vacancy is using Success Profiles and will assess your Behaviours, Ability and Experience
Stage 1: Application & Sift
Success profiles
You will be required to complete an application form. You will be assessed on the listed four essential criteria, and this will be in the form of a:
-
Application form (‘Employer/ Activity history’ section on the application)
-
500-word Statement of Suitability.
This should outline how your skills, experience, and knowledge, provide evidence of your suitability for the role, with reference to the essential criteria.
The Application form and Statement of Suitability will be marked together.
Longlisting: In the event of a large number of applications we will longlist into 3 piles of:
- Meets all essential criteria
- Meets some essential criteria
- Meets no essential criteria
Please note only 1 & 2 pile will be carried though to shortlisting
Shortlisting: In the event of a large number of applications we will shortlist on:
- Can demonstrate cyber security knowledge in a previous hands-on role, especially working within big programmes, and have experience of security management and information assurance practice
Desirable criteria: This may be used in the event of a large number of applications / large amount of successful candidate
-
Leading a team of technical specialists
If you are successful at this stage, you will progress to interview & assessment
Healthjobs UK has a word limit of 1500, but your statement of suitability must be no more than 500.
Please do not exceed this word limit, we will not consider any words over and above this number. Feedback will not be provided at this stage.
Stage 2: Interview
Success Profiles
You will be invited to a (single) remote interview
Behaviours, experience and ability will be tested at interview.
The Behaviours tested during the interview stage will be: -
- Making effective decisions
- Leadership
- Communicating and Influencing
- Delivering at pace
Once this job has closed, the job advert will no longer be available. You may want to save a copy for your records.
Please note you will not be able to upload your CV. You must complete the application form in as much detail as possible. Please do not email us your CV.
Eligibility Criteria
External
Open to all external applicants (anyone) from outside the Civil Service (including by definition internal applicants).
Location
This role is a Home-based Role. With occasional travel to Core HQ's (London, Leeds, Birmingham, Liverpool) expected when needed.
Security Clearance Level Requirement
Successful candidates must pass a disclosure and barring security check.
Successful candidates must meet the security requirements before they can be appointed. The level of security needed is Security Check (SC)
You should normally have been resident in the United Kingdom for the 5 years to obtain Security Check (SC) clearance.
UK residency less than the outlined periods may not necessarily bar you from gaining national security vetting at this higher level and applicants should contact the Vacancy Holder / Recruiting Manager listed in the advert for further advice.
Person specification
Application form & Statement of Suitablity
Essential criteria
- Application form & Statement of Suitablity
Behaviours
Essential criteria
- Making effective decisions
- Leadership
- Communicating and Influincing
- Delivering at pace
Documents to download
Further details / informal visits contact
- Name
- Chris Williams
- Job title
- Resource Support
- Email address
- [email protected]
List jobs with UK Health Security Agency in Administrative Services or all sectors