Cyber Security Architect & Engineering Lead
Moore Kingston SmithMoore Kingston Smith, a London-based firm, is seeking a seasoned Cyber Security Architect & Engineering Lead to join its IT Infrastructure team. This is a permanent, full-time role based onsite in City, London, reporting to the Head of Information Security. It’s an opportunity for someone who wants to shape security design across the whole organisation and drive practical outcomes, not just compliance.
The role blends hands-on technical leadership with architecture and engineering work. You’ll translate security strategy and business needs into secure designs, practical controls, technical standards and measurable results. It’s not only about advisory work: you’ll design, prototype, configure, guide implementations and validate the effectiveness of security controls across identity, cloud, data, endpoints, applications, networks and third-party services. A key focus will be helping the firm adopt AI and emerging technologies securely, including Microsoft 365 Copilot, AI agents, custom AI applications and data-driven platforms.
Architecting security across the firm
You will define and maintain the security architecture across identity, endpoints, networks, cloud, SaaS, data, applications and integration platforms. The role calls for designing and implementing modern controls with a Zero Trust and secure-by-design mindset, and with automation at the forefront. You’ll lead security architecture reviews and threat modelling for major projects, new products, high-risk integrations and evolving technologies, and you’ll act as the technical lead for AI security, shaping controls for Microsoft 365 Copilot, AI agents, custom AI applications and related technologies.
Beyond design, you’ll provide senior technical oversight for security monitoring, detection engineering, incident response and recovery capabilities. When incidents occur, you’ll either lead or support the response, coordinating with internal teams, external SOC providers and specialist partners. You’ll continually improve vulnerability and exposure management by weighing business risk, exploitability, attack paths and threat intelligence to prioritise remediation. The role also supports the technical implementation and evidence required for ISO 27001, Cyber Essentials Plus, client assurance and other regulatory or contractual obligations.
Clear, risk-based technical guidance to senior leaders, project teams and technology owners will be part of your day-to-day, alongside coaching technology teams in secure design and engineering practices to grow security capability beyond the core security function.
What you’ll bring to the role
We’re looking for someone with demonstrable experience in cyber security architecture, security engineering or a closely related senior technical security role. Here’s what will help you succeed:
- Strong hands-on experience designing and implementing security controls in a Microsoft-centric environment, including Microsoft 365, Entra ID, Defender XDR, Sentinel, Azure and Purview
- Solid knowledge across identity security, Zero Trust, cloud security, data security, endpoints, networks, applications, APIs and secure software development
- Experience conducting security architecture reviews, threat modelling, creating technical standards, reference architectures and control designs
- Practical exposure to incident response, detection engineering, threat hunting, vulnerability or exposure management and security automation
- Ability to automate security and assurance processes using Python, PowerShell, Logic Apps, Azure Functions, APIs, infrastructure as code or equivalent platforms
- Working knowledge of ISO 27001, Cyber Essentials Plus, NIST CSF and recognised AI security or governance frameworks
- Capability to explain complex technical risk clearly to senior stakeholders and to influence delivery teams without relying on formal authority
- A practical, outcome-focused approach, with a track record of taking ownership, improving controls and validating their effectiveness
Experience in regulated, client-confidential or professional services environments would be advantageous. Certifications that would be beneficial include the Microsoft Certified: Cybersecurity Architect Expert (SC-100), CISSP or CCSP, Microsoft security certifications such as AZ-500 or SC-200, GIAC certifications in incident response, cloud, detection or forensics, ISO 27001 Lead Implementer or Lead Auditor, and architecture or threat-modelling accreditation such as SABSA or TOGAF, or equivalent practical experience.
You’ll be a practical problem-solver who is comfortable moving between architecture, configuration, testing and stakeholder engagement. You’ll challenge outdated controls and practices while staying pragmatic, commercially aware and focused on business outcomes. You’ll also stay calm under pressure, collaborate well and build trust with both technical and non-technical colleagues.
If interested please download the full job spec.
Pay and practical details
The role offers a salary of £75,000 per year and is based in City, London. It is a permanent, full-time position and work is on site. The reporting line is to the Head of Information Security.
Advice for applicants
Lead with the Microsoft-centric security architecture you’ve built. On your resume, name key products you’ve implemented like M365, Entra ID, Defender XDR, Sentinel, and Purview, and describe the business outcomes you achieved.
Be ready to demonstrate threat modelling and security architecture reviews you’ve led, including how you defined standards or reference architectures and how you validated that controls worked in practice.
Prepare to discuss automation in depth. Have concrete examples of scripts, pipelines or IaC you’ve used with Python, PowerShell, Logic Apps, Azure Functions or similar to automate security tasks or assurance processes.
Think about AI security specifics and be prepared to talk about practical controls for Microsoft 365 Copilot, AI agents, and related technologies, plus how you’d measure success in this role. A thoughtful question to ask could be how the firm plans to govern AI usage and security across departments.