What You'll Be Doing
The Lead Enterprise Security Architecture is responsible for defining and leading the Group's Enterprise Security Architecture capability, ensuring security is embedded by design across business transformation, technology delivery, digital innovation and operational change.
The role owns the enterprise security architecture strategy, standards, governance and target-state roadmap, providing architectural leadership across the Group's technology landscape. Working in close partnership with Enterprise Architecture, Engineering, Infrastructure, Digital, Data, Product, SAP and business leadership teams, the role ensures that technology investments are secure, resilient, scalable and aligned with the Group Information Security Strategy.
As the Group's senior security architecture authority, this role enables business growth through pragmatic risk management, modern security engineering practices and strategic technology governance.
- Define, own and continuously evolve the Group Enterprise Security Architecture strategy, standards, principles and target-state roadmap.
- Establish security architecture patterns and reference architectures that support business transformation and technology modernisation.
- Drive continuous improvement of the Group's enterprise security architecture capability and maturity.
- Own the Security Design Authority and provide governance for enterprise architecture decisions, security design standards, architecture exceptions and technology risk across the Group.
- Ensure security is embedded throughout the technology lifecycle and incorporated into solution design from inception.
- Govern architecture decisions, design exceptions and technology risk to ensure alignment with enterprise standards and business objectives.
- Provide enterprise security architecture leadership across strategic programmes, digital initiatives and enterprise technology platforms.
- Partner with Enterprise Architecture to shape enterprise technology roadmaps, ensuring security requirements are embedded into strategic technology decisions and future-state architectures.
- Evaluate new technologies and major investments to ensure they meet security, resilience and architectural standards.
- Develop and maintain enterprise security architecture standards aligned with recognised industry frameworks and regulatory requirements.
- Provide independent security architecture assurance and technical due diligence for strategic programmes, enterprise platforms, cloud services, third-party solutions and technology investments.
- Represent Information Security at architecture, technology governance and investment forums.
- Assess emerging technologies and evolving cyber threats to inform the Group's security architecture strategy.
- Embed Security by Design across the full technology lifecycle, ensuring security requirements are considered from concept through implementation and operational transition.
- Drive the adoption of modern security architecture practices, automation and engineering capabilities. Continuously develop and mature the Group's Enterprise Security Architecture capability, standards, methodologies and operating model.
- Promote standardisation, simplification and continuous improvement across the technology landscape.
- Act as the trusted security architecture advisor to senior technology and business leaders ensuring technology enables business growth while effectively managing cyber risk.
- Build strong partnerships across Technology & Data, Digital, Product, Engineering and business functions. Provide architectural leadership across identity, cloud, infrastructure, applications, data, enterprise platforms and emerging technologies.
- Lead and develop the Enterprise Security Architecture capability, fostering technical excellence, collaboration and innovation.