Skip to main content
Posted 25 July, 2026

Enterprise Security Architect

CloudPay United Kingdom Limited
Andover, ENG, GB Full Time

Job Description

\n Main responsibilities\n

The Security Architect is a critical leadership role ensuring that our technology, cloud platform, and global operations are secured by design, comply with rigorous global standards, and are guided by a robust security program.

\n
    \n
  • \n

    Security Architecture & Strategy Define and maintain CloudPay’s security architecture vision, principles, standards, and roadmaps. Ensure security architecture aligns with business objectives, regulatory expectations, and risk appetite. Design secure, scalable patterns for APIs, data platforms, AI workloads, and cloud‑native services. Provide authoritative security architecture guidance across engineering, platform, and data teams.

  • \n
  • \n

    Identity & Access Management (IAM) Own the security architecture for workforce and customer identity platforms. Drive adoption of zero‑trust principles, strong authentication, least privilege access, and secure identity lifecycle management. Provide architectural oversight for single sign‑on, federation, privileged access management, and conditional access controls. Define and assess future operating models to ensure robust lifecycle management for Identity & Access management exists for CloudPay globally. Collaborate closely with Identity Partners to ensure design and technologies align to CloudPay’s 3‑A’s strategy which includes Automation, API’s and AI.

  • \n
  • \n

    Cloud Security (AWS & Azure) Lead security architecture across AWS and Azure, including identity, networking, encryption, monitoring, and workload protection. Define security guardrails and reference designs using cloud‑native services and infrastructure‑as‑code. Support secure migration, modernization, and continuous improvement of cloud platforms. Ensure continues best practice security principles are applied to cloud platforms deployed by CloudPay and ensure any remediation activities are prioritized by adopting a risk‑based approach.

  • \n
  • \n

    AI & Emerging Technology Security Design and review security controls for AI/ML systems, including training data protection, model integrity, access control, and inference security working in conjunction with compliance, security and data privacy teams to ensure controls are appropriate and effective to ensure customer, employee and commercially sensitive data has confidentiality, integrity and availability maintained. Assess and advise on risks associated with generative AI, third‑party AI platforms, and internal AI use cases. Support responsible, ethical, and compliant adoption of AI technologies from a security and risk perspective.

  • \n
  • \n

    Architecture Governance & Assurance Chair the Security Architecture Review Board (SARB), ensuring consistent, transparent, and risk‑informed architectural decision‑making. Review and approve security‑relevant architectural designs, exceptions, and risk trade‑offs. Ensure architecture decisions are documented, traceable, and aligned to enterprise standards. Ensure all platforms, infrastructure, architectures and models are documented and regularly maintained.

  • \n
  • \n

    Responsible AI & Ethics Leadership Deputize for the Chief Security & Risk Officer and Director of Compliance at the Responsible AI & Ethics Committee. Provide expert security and risk input into AI governance, ethical assessments, and AI assurance decisions. Contribute to policies, controls, and oversight mechanisms for responsible AI use.

  • \n
  • \n

    Risk, Compliance & Assurance Ensure security designs support compliance with applicable regulations and standards (e.g. ISO 27001, SOC 2, GDPR). Lead threat modeling, security design reviews, and material risk assessments. Support audit, certification, and regulatory activities through well‑evidenced architecture and governance artefacts.

  • \n
  • \n

    Stakeholder Engagement & Leadership Act as a trusted advisor to senior engineering leaders, product teams, and executive stakeholders. Influence outcomes through strong communication, pragmatism, and technical authority. Mentor security engineers and architects and promote security‑by‑design across the organisation. Act as the Subject Matter Expert (SME), partnering with Enterprise Risk Management, Legal, Internal Audit, Product, and Engineering teams to ensure security requirements are understood and met across the business.

  • \n
Experience needed for this role Essential\n
    \n
  • Extensive experience in security architecture, cloud security engineering, or senior security leadership roles.
  • \n
  • Proven track record securing large‑scale, cloud‑native SaaS platforms, ideally in regulated environments.
  • \n
  • Demonstrated experience operating within formal architecture governance frameworks.
  • \n
  • Experience engaging with senior leadership, risk committees, and multidisciplinary decision‑making forums.
  • \n
  • Strong understanding of balancing security risk, business enablement, and delivery velocity.
  • \n
Technical Experience & Skills\n
    \n
  • \n

    Identity & Access Management Deep experience in IAM architecture for both workforce and customer identities. Strong understanding of modern authentication, authorization, and access governance. Practical application of zero trust and identity‑centric security models.

  • \n
  • \n

    Cloud Platforms Advanced knowledge of AWS and Azure security architectures and native security services. Experience designing secure cloud networking, segmentation, encryption, and monitoring. Familiarity with containerized, serverless, and platform‑as‑a‑service security patterns.

  • \n
  • \n

    AI & Data Security Knowledge of security risks across AI/ML lifecycles, including data ingestion, training, and inference. Experience evaluating AI‑related threats such as data leakage, prompt injection, and model abuse. Understanding of AI governance and assurance concepts from a security perspective.

  • \n
  • \n

    Secure Engineering & DevSecOps Experience embedding security into SDLC, CI/CD pipelines, and infrastructure‑as‑code. Strong threat modeling, security design review, and architecture documentation skills.

  • \n
  • \n

    Communication & Architecture Leadership Ability to communicate complex technical concepts clearly to both technical and non‑technical audiences. Confident written and verbal communication suitable for executive, risk, and governance forums.

  • \n
Desirable Qualifications\n
    \n
  • Security or cloud certifications (e.g. CISSP, SABSA, AWS/Azure Security).
  • \n
  • Experience in payments, payroll, financial services, or other highly regulated industries.
  • \n
  • Exposure to AI governance frameworks or ethical technology initiatives.
  • \n
  • Architectural Fluency: Ability to translate complex business and regulatory requirements into concrete, actionable security controls and technical architecture designs.
  • \n
  • Communication: Exceptional ability to communicate complex security risks and technical concepts clearly to both technical teams and executive leadership.
  • \n
  • Analytical & Problem‑Solving: Proven ability to manage multiple priorities, conduct thorough risk assessments, and drive pragmatic, risk‑based remediation strategies.
  • \n
UK Package and benefits\n
    \n
  • Competitive Salary
  • \n
  • Competitive vacation allowance
  • \n
  • Calm app
  • \n
  • WFH Allowance
  • \n
  • Life Assurance
  • \n
  • Private Medical Insurance
  • \n
  • Cycle to Work Scheme
  • \n
  • EAP
  • \n
  • Eye Tests & Glasses Contribution
  • \n
  • Simplyhealth Enhanced Health Plan
  • \n
  • Pension Scheme
  • \n
  • Give‑As‑You‑Earn (GAYE)
  • \n
  • Employee Referral Program
  • \n
  • CloudPay NOW Paid Volunteering days
  • \n
  • Marriage LeaveBereavement Leave
  • \n
  • Vacation Purchase Plan
  • \n
\n

CloudPay is committed to being an equal opportunities employer.

\n
#J-18808-Ljbffr