Job Description:
Technical Security Architect
Hampshire (site-based)
DXC Technology is looking for an experienced Technical Security Architect to support a client’s Joint Design Team security lead in the provision of technical security advice and guidance to the Joint Design Team and relevant client Third Parties.
This is a critical, site-based role responsible for ensuring the right skills are in place at the right time to meet client demand, working closely with account leadership, delivery teams, and recruitment.
Due to the nature of the work and the customers we support, the successful candidate must be eligible to meet UK Government and contractual personnel security requirements, including the applicable residency requirements for the role, and have the right to work in the United Kingdom. Some roles may also be subject to nationality requirements where these are necessary to meet UK Government or contractual security obligations.
The Role
A senior cybersecurity professional responsible for designing and implementing security architectures based on the Zero Trust principle of “never trust, always verify.” The role focuses on protecting enterprise systems, applications, data, and cloud environments by enforcing strong identity and access controls, least-privilege access, continuous authentication, micro-segmentation, and robust monitoring. You will work closely with business, security, infrastructure, and compliance teams to develop security roadmaps, assess risks, integrate modern security technologies, and ensure alignment with industry frameworks such as NIST 800-207. The role requires extensive experience in security architecture, cloud security, identity management, and enterprise risk management, combined with strong stakeholder engagement and leadership skills to drive security transformation programmes across the organisation.
Qualification:
- BSC and/or MSc in Cyber Security, Computer Science, Information Technology, Information Security or related subject or relevant industry experience.
- CompTIA Security+ CASP+ (or SecurityX)
- Associate membership grade with CIISEC
- ICS2 Certified Cloud Security Professional (CCSP), Certified Information, Systems Security Professional (CISSP), and/or Information Systems Security Architecture Professional (ISSAP)
- CESG Certified Cyber Professional (CCP) in Security Architecture or Risk Management
- Additional cloud security qualifications such as Microsoft Azure, AWS, GoogleAdvanced degree in a relevant field is a plus, CISSP, CISM, CISA or equivalent professional certification.
Key Responsibilities
- Architect solutions and technically lead their implementation, ensuring adherence to customer security policies and standards. Relevant solutions include on-prem secure cloud, zero trust architecture
- Working closely with the customer’s architecture team to develop solutions
- Assess security risks by identifying vulnerabilities and defining security requirements to address known and future threats
- Develop, implement, and enforce security policy standards to ensure compliance with customer security and legal requirements
- Help and support on architectural/technical issues to other team members as required, whilst sharing technical knowledge and experiences
- Gain and maintain a working knowledge of the DXC Portfolio of Security Products and Services, promoting this with the customer and encouraging best fit solutions
- Continually review and enhance existing knowledge of the security aspects of common product sets and technologies
- Provide ‘soft’ consultancy skills and a proactive approach to gain the absolute trust of our customers
- Participate in providing mentoring support and guidance to team members to help grow skills and capabilities
<>
What You’ll Bring
- 5+ years’ experience in cybersecurity, security architecture, or related disciplines, with experience delivering security solutions within Defence or highly regulated environments.
- Proven experience designing and implementing Zero Trust Architectures, aligned to NIST SP 800-207 principles.
- Strong knowledge of Identity and Access Management (IAM), network security, endpoint security, cloud security, and security monitoring capabilities.
- Experience developing and integrating security architectures within broader enterprise, cloud, and infrastructure architectures.
- Ability to engage with stakeholders, capture business and security requirements, and translate them into practical architectural solutions.
- Working knowledge of architectural frameworks such as SABSA and TOGAF.
- Strong understanding of threat modelling, risk assessment, and secure-by-design principles, with the ability to apply outputs to architectural decisions.
- Experience interpreting and applying security standards, frameworks, and regulatory requirements, including NIST, ISO 27001, JSP 440, HMG Security Policy Framework, and other relevant Defence and industry standards.
- Ability to operate across multi-vendor security ecosystems, selecting and integrating appropriate technologies to meet business and security objectives.
- Excellent communication, consultancy, and stakeholder management skills, with the ability to influence security strategy and transformation initiatives.
Essential Requirements
- Security Clearance - requirement
- Ability to work on-site in Location
At DXC Technology, we believe strong connections and community are key to our success. Our work model prioritizes in-person collaboration while offering flexibility to support wellbeing, productivity, individual work styles, and life circumstances. We’re committed to fostering an inclusive environment where everyone can thrive.
Recruitment fraud is a scheme in which fictitious job opportunities are offered to job seekers typically through online services, such as false websites, or through unsolicited emails claiming to be from the company. These emails may request recipients to provide personal information or to make payments as part of their illegitimate recruiting process. DXC does not make offers of employment via social media networks and DXC never asks for any money or payments from applicants at any point in the recruitment process, nor ask a job seeker to purchase IT or other equipment on our behalf. More information on employment scams is available here .

