Overview
Expleo is a trusted partner for end-to-end, integrated engineering, quality services, and management consulting for digital transformation. We help businesses harness technological change to deliver innovation, improve resilience, and support the secure delivery of complex products, platforms, and systems.
As part of the Expleo UK Cybersecurity Practice, you will join a managed Cyber Operations service for a major UK energy network operator that forms part of the UK's Critical National Infrastructure (CNI). The service is governed by Expleo in the UK, with a 24/7 UK Security Operations Centre delivered by a specialist partner and an Expleo consultancy team in India providing design, engineering and assurance expertise across the client's security tooling estate.
As Senior Security Architect, you will be the senior technical adviser within the offshore consultancy team. Working under the technical direction of the UK Head of Service, who holds design authority, you will produce the security architecture, design and risk material that underpins the service, and provide technical leadership to the offshore engineers.
This is a design, review and advisory role. You will work within Expleo's offshore consultancy team, outside the client's operational environment. You will not have access to the client's operational systems or data and will not make live changes. Operational changes are implemented by UK-based, security-cleared personnel; your work provides the designs, analysis, recommendations and assurance that those changes depend on. You will work from information released to the team through Expleo's controlled UK service boundary.
Responsibilities
Responsibilities
- Produce and maintain security architecture and design documentation (high-level and low-level designs) for the client's security tooling estate, for approval by the UK Head of Service.
- Carry out architecture and risk reviews of proposed high-risk changes (firewall, intrusion prevention, gateway, privileged access and application control) before they are presented to the client's Change Advisory Board.
- Define logging and audit requirements for in-scope security tools, including log sources, feed requirements for the client's retained SIEM, and a retention architecture aligned with client policy and regulatory obligations.
- Assess and recommend tooling and approaches for PKI and secrets management.
- Produce NIS Regulations and NCSC Cyber Assessment Framework (CAF) alignment assessments and contribute evidence to the client's regulatory reporting.
- Prepare inputs for the client's governance, risk, and compliance (GRC) reporting on the enterprise's security status.
- Develop risk treatment plans in line with client policy and industry best practice and maintain inputs to the security risk register.
- Prepare technical content and risk papers for the client's cyber security governance board, in support of the UK Head of Service and the Lead Information Risk Manager.
- Maintain the master set of security architecture diagrams and ensure that diagrams produced by the engineering team are consistent and up to date.
- Identify and assess continual improvement opportunities, including benefit-cost appraisal and sequencing into quick wins, foundational change and strategic uplift.
- Apply appropriate consideration of operational technology (OT) and IT/OT boundary risk in all architecture and design work.
- Provide technical leadership, peer review and mentoring to the Lead Security Engineer, Security Engineers and Vulnerability and Patch Manager.
- Support the growth of Expleo's Cybersecurity Practice through knowledge sharing, technical contribution and client-facing delivery excellence.
Qualifications
- Degree in computer science, cybersecurity, information systems or a related discipline, or equivalent professional experience.
- CISSP, CISSP-ISSAP or SABSA Chartered Foundation (at least one required).
- TOGAF, a cloud security certification (e.g. CCSP, AZ-500, AWS Security Specialty) or GICSP/ISA/IEC 62443 certification would be advantageous.
Essential skills
- Enterprise security architecture across network, identity, endpoint, cloud and data security domains.
- Designing logging and SIEM integration architectures, including log source definition and retention requirements.
- Applying risk assessment methods such as ISO/IEC 27005 and NIST SP 800-30.
- Working knowledge of the NIS Regulations, NCSC CAF, ISO/IEC 27001, NIST CSF and CIS Controls.
- Reviewing proposed changes for architectural and security risk, and producing clear, evidence-based recommendations.
- Excellent written communication for executive, governance and regulator-facing documentation.
Ability to lead and quality-assure the work of other engineers
Desired skills
- Energy, utilities or other CNI sector experience.
- Knowledge of OT/ICS security concepts, the Purdue model and IEC 62443.
- Experience with GRC tooling (e.g. ServiceNow IRM, Archer).
- Experience with Ofgem or NIS-regulated cyber assurance activity.
Experience
- 12+ years in IT and cybersecurity, including 6+ years in security architecture for enterprise or CNI environments.
- Experience producing architecture, design and risk artefacts for regulated organisations.
- Experience supporting governance boards, risk registers and GRC reporting.
- Experience working with multi-supplier environments and managed security service providers.
What do I need before I apply
- Have the right to work in India.
- Be based in, or willing to relocate to, Chennai.
- Be willing to complete Expleo enhanced pre-employment background screening (equivalent in standard to the UK Baseline Personnel Security Standard) and any additional vetting the client requires.
- Be able to work hours that overlap with the UK business day, with occasional out-of-hours advisory support during major incidents.
- Have excellent written and spoken English, suitable for engagement with senior UK stakeholders.
- Be comfortable working within a strict security boundary, with no access to the client's operational systems or data.
Benefits
- Collaborative working environment: we stand shoulder to shoulder with our clients and our peers through good times and challenges.
- We empower all passionate, technology-loving professionals to expand their skills and take part in inspiring projects.
- Expleo Academy enables you to acquire and develop the right skills by delivering a suite of accredited training courses.
- Competitive local company benefits [India HR to confirm the benefits package].
- Always working as one team, our people are not afraid to think big and challenge the status quo.
“We are an equal opportunities employer and welcome applications from all suitably qualified persons regardless of their race, sex, disability, religion/belief, sexual orientation or age.”
If you are an experienced Security Architect with a strong background in enterprise and CNI security architecture, and you enjoy shaping how critical services are secured, we encourage you to apply today.