The Security Architect plays a crucial role in supporting projects across the business. This role bridges business requirements with technical security controls, ensuring that systems are designed with security built in from the ground up rather than bolted on afterwards.
The Security Architect will also need to support the wider security, compliance, risk and architectural community through the design and delivery of security controls, identification of new and changing requirements and in response to new and emerging threat.
Main duties and responsibilities
- Support projects and initiatives in an advisory capacity as a security SME
- Design secure architectures for networks, systems, applications, and cloud environments in line with business and regulatory requirements
- Ability to assess and architect guardrails for AI agents with tool-use/autonomous action capabilities
- Knowledge of securing LLM and generative AI deployments: prompt injection defences, output validation, data leakage prevention, model access controls
- Understanding of data governance for AI training data (sensitive data handling, PII redaction, data poisoning risks)
- Identify and provide requirements to projects and initiatives
- Review proposed technical solutions to ensure they meet security requirements (implementation governance)
- Produce and maintain architectural artefacts (designs, standards, patterns, reference architectures)
- Supply security requirements into projects and RFI/RFPs
- Evaluate and recommend security tools, technologies and vendors
- Drive improvements, support compliance through the execution of our security strategy
- Mentor engineering and IT teams on secure design principles
- Support and influence technical strategy
About you
- Experience of working to demonstrate compliance with Cloud Technologies (Azure, AWS, GCP) – Azure preferred however not essential.
- Experience with security frameworks: NIST CSF, ISO 27001/27002, CIS Controls, MITRE ATT&CK
- Familiarity with Zero Trust architecture principles
- Knowledge of secure SDLC and DevSecOps practices (SAST, DAST, container/image scanning, CI/CD security)
- Maintained awareness of emerging threats and vulnerability research.
- Working knowledge of the use of Enterprise Systems Management tools
- Familiarity in Agile development processes
The following demonstrable experience is essential (minimum of 5):
- Typically 7+ years in Information Security/IT, with 3+ years in an architecture-focused role
- Cloud Security - Adoption & migration, Governance
- Data Governance - DR, DLP, DRM, Data lifecycle Management
- App & Systems Development Security
- Asset Management including MDM
- Identity & Access management
- Network & Endpoint security
- Logging, Monitoring & Retention
- Threat intelligence, Automation & Orchestration
- Configuration & Vulnerability management
Relevant certifications (one or more preferred):
- CISSP (Certified Information Systems Security Professional)
- SABSA (Sherwood Applied Business Security Architecture)
- CCSP (Certified Cloud Security Professional)
- CISM (Certified Information Security Manager)
- Cloud-specific certifications (AWS/Azure/GCP Security Specialty)
How we work
- Be Supportive: We care about others, value diversity and act thoughtfully - Our Architects work closely with colleagues in all positions, so the ability to form and maintain relationships and produce high quality written communication and documents is essential. We make things easier.
- Be Collaborative: We give, we share and we join in - Our architects are collaborative problem solvers. We take responsibility and practice extreme ownership by default when it comes to supporting others.
- Be Bold: We stand tall and challenge ourselves to think big - Our architects are always thinking about the big picture and looking for opportunities to enable our customers to do more. We don’t work in a silo and need to be prepared to live outside of our comfort zones.
- Be Exceptional: We exceed standards and expectations - Our architects set an example in everything they do and consistently look to go beyond MVP.
About us
We're a global law firm helping our clients achieve their goals wherever they do business. Our pursuit of innovation has transformed our delivery of legal services. With offices in the Americas, Europe, the Middle East, Africa and Asia Pacific, we deliver exceptional outcomes on cross-border projects, critical transactions and high-stakes disputes.
At DLA Piper, we understand that inclusion is not a one-size-fits-all concept. We embrace and celebrate the range of perspectives, backgrounds and experiences that each individual brings to our firm. By fostering a culture that welcomes and appreciates all aspects of our individuality, we ensure that everyone has the opportunity to succeed.
Our commitment to inclusion and positive social impact enables us to provide exceptional service to our clients and communities, while nurturing a unique and inclusive culture for all our people. We welcome the unique contribution that you will bring to our firm and actively encourage applications from all talented people – however your talent is packaged, whatever your background or circumstance and regardless of how you identify.
We are committed to being accessible and accommodating any reasonable adjustments needed throughout the recruitment process to ensure an inclusive experience for all. If you need any support or adjustments, please let us know.
Where local legislation permits, we will conduct relevant pre-engagement screening checks prior to your first day.
Apply nowRequesting Adjustments
At DLA Piper, we aim to make meaningful progress and build an inclusive culture where anyone affected by disability, neurodiversity or a long-term health condition has an equitable and accessible chance of success. If you think you may need adjustments or additional support to enable you to participate in our recruitment process, please contact our Recruitment team and we will be happy to support you.
Agile Working
We recognise that people have responsibilities and interests outside of their career and that as a business, we all benefit from working flexibly. That’s why we are open to discussing with candidates the different ways in which we are able to support requests for agile working arrangements.
Pre-Engagement Screening
In the event that we make an offer to you, and where local legislation permits, we will conduct pre-engagement screening checks that may include but are not limited to your professional and academic qualifications, your eligibility to work in the relevant jurisdiction, any criminal records, your financial stability, and references from previous employers.
Our hiring approach
Our hiring approach enables us to learn about the professional and person you are, and gives you the opportunity to learn about us. Your recruitment experience can differ depending on the type of role you are interviewing for. You will always meet your direct Line Manager for your role, as well as peers and close collaborators for the position. For some of our roles we may also use assessment tools, practical exercises, and panel presentations. Your Recruitment Business Partner will inform you of the recruitment process at the start of any recruitment process, but please let us know if you have any questions prior to making an application.
Lawyers
We’re redefining what an international law firm can be. With a unique global network and an unparalleled range of expertise, this is where you’ll work on the cases that shape the world and will define your career.
Talent Community
Staying in touch with like-minded people is important to us. Our Talent Community provides unique access to our firm so you can discover why we are a different kind of law firm.
Business Professionals
We pride ourselves on the extraordinary impact we make beyond the borders of traditional law. That’s only possible because of the skills our business professionals bring and the environment we create to let them thrive. See where your skills could take you.