East Midlands (England), East of England, London (region), North East England, North West England, Scotland, South East England, South West England, Wales, West Midlands (England), Yorkshire and the Humber
About the job Job summaryThis position is based nationally.
Job descriptionThe HMCTS Security Architect plays a vital role in embedding Secure by Design principles across the technology lifecycle. Working closely with the Chief Information Security Officer, Principal and Lead Security Architects, and the wider security team, the architect ensures that cyber security activities align with HMCTS's strategic goals, risk management framework, and evolving security roadmap.
This role is responsible for maintaining compliance with key standards including PCI DSS, ISO27001, GovAssure, and the National Cyber Security Centre's Cyber Assessment Framework. The architect promotes a strong security culture, ensuring that Secure by Design is understood and consistently applied across programmes and platforms.
Operating across on-premises, cloud, and hybrid environments, the Security Architect provides expert oversight and guidance to technical teams, enabling informed decisions on security controls. They ensure the effective use of common tools and patterns to deliver secure systems, while applying proportionate controls that support business outcomes.
The architect safeguards HMCTS's data, services, and infrastructure by shaping robust security solutions and coordinating assurance activities. They play a key role in enabling secure innovation and ensuring that security is not just a compliance requirement but a strategic enabler.
This role demands a strategic mindset, deep technical expertise, and strong collaboration skills. The Security Architect must influence across multidisciplinary teams, advocate for security best practices, and contribute to the continuous improvement of HMCTS's cyber security posture.
Key Responsibilities:
A security architect creates and designs security for a system or service, maintains security documentation and develops architecture patterns and security approaches to new technologies.
At this role level, you will:
Ensure security architecture aligns with wider Gov security policies and frameworks, legal frameworks, industry regulations and best practise (e.g ISO 27001, NCSC Standards, GDPR, PCI DSS, GovAssure, Secure by Design).
Recommend security controls and identify security solutions that support business objectives.
Provide specialist security guidance and direction during the design, implementation and use phases of systems, applications and infrastructure.
Provide specialist advice and recommendations regarding approaches and technologies across teams and various stakeholders, assessing the risk associated with proposed changes.
Inspire and influence others to execute security principles, communicating widely with other stakeholders.
Support the GovAssure process by coordinating the collection of evidence, and the submission of GovAssure returns to Cabinet Office.
Advise on important security-related technologies and assess the risk associated with proposed changes
Assist, where necessary, with incident response processes to identify architectural issues and solutions.
Proactively engage with internal and external partners, stakeholders and peers to develop your knowledge and inform your decisions.
You will be expected to carry out any other duties that may reasonably be required in line with your main duties.
Continuously keep up to date with changing compliance legislation and initiatives to assess new opportunities for educating colleagues on relevant security standards.
Continue to review ongoing security architectural activities
Essential Skills & Criteria:
Desirable Experience
Please refer to Job Description