AWS IT Security Architect
My client, a Pension administrator company, based in London, are looking for an AWS IT Security Architect to join their growing team. The office split is two days per week in. This role is currently Inside IR35 but if there is a possibility to move it to Outside IR35 I will find out later this week (w/c 17th August). For now consider it Inside IR35.
About the AWS IT Security Architect role:
My client is looking for a highly skilled Security Architect with deep expertise in AWS cloud security, zero trust network architecture, and modern identity and access management. This role will shape the future of my client's security architecture as they continue to modernise their platforms, strengthen their cloud native footprint, and embed security by design across their technology landscape.
You will act as the principal architect for cloud and enterprise security, working closely with engineering and architecture teams to design secure patterns, influence solution design, and ensure that their security controls remain effective, scalable, and aligned with their strategic direction. The role requires strong hands-on technical knowledge, excellent collaboration skills, and the ability to translate complex security concepts into practical designs for a rapidly evolving environment.
Main responsibilities:
Design and maintain my client's security reference architecture, with specific emphasis on AWS, identity, network segmentation, and zero trust principles.
• Define secure-by-design patterns for cloud services, container workloads, serverless functions, data protection, and third party integrations.
• Evaluate solution designs to ensure alignment with security policies, regulatory expectations, and architectural best practice.
• Lead the evolution of our zero-trust network strategy, working with Infrastructure and Network teams to embed Zscaler, ZTNA, identity-driven access, and micro-segmentation across our estate.
• Partner with cloud engineering teams to ensure secure configuration baselines, IaC guardrails, and continuous compliance mechanisms are in place for AWS environments.
• Influence IAM roadmap direction, including expansion of passwordless authentication, role-based access, adaptive authentication, and integration with identity providers.
• Provide architectural oversight for the deployment of security tools across our cloud and hybrid environments, including EDR, CSPM, CIEM, and secrets management.
• Support security governance, contributing to technical standards, cloud policies, and architecture review boards.
• Conduct threat modelling for key new products, features, and third-party services.
• Work with 3rd party partners to ensure architectural alignment and effective design reviews for critical platforms.
• Stay current with emerging cloud threats and controls, ensuring Aptia’s architecture remains resilient against evolving techniques
Required experience and technical knowledge:
Extensive experience designing secure architectures in AWS, including strong understanding of VPC design, IAM, KMS, networking, control tower, landing zones, and security services.
• Deep knowledge of zero trust architecture, including identity centric access, ZTNA, network segmentation, and cloud-native implementations. • Experience working in complex multi account AWS environments with modern DevOps/IaC approaches (CloudFormation, Terraform, CDK).
• Hands-on knowledge of cloud security tooling, such as CSPM, CIEM, secret managers, EDR/XDR, and SIEM.
• Familiarity with secure integration patterns (OAuth, OpenID Connect, API gateway security, mTLS).
• Understanding of relevant security frameworks (NIST CSF, ISO 27001, CIS Benchmarks)
Experience working with hybrid environments and integrating cloud security with identity, endpoint, and network platforms such as Zscaler, CrowdStrike, M365, and Entra ID.
Required skills and behaviours:
Ability to translate security and architectural requirements into clear, usable design patterns.
• Strong analytical and problem-solving capability with the ability to assess risks and make informed architectural trade offs.
• Demonstrated ability to work in a fast-moving, cloud first environment.
Desirable:
• Excellent communication skills, able to work collaboratively with engineering, product, and operational teams
• Comfortable influencing stakeholders and advocating for secure design principles
• Passion for continuous learning and staying ahead of emerging cloud security trends
If the above role is of interest, please apply to this advertisement, or call me on 0207 509 8040 to find out more.
Robert Walters Operations Limited is an employment business and employment agency and welcomes applications from all candidates
About the job
Contract Type: Permanent
Specialism: Technology & Digital
Focus: Information Security
Industry: Banking
Salary: £600 - £650 per day
Workplace Type: Hybrid
Experience Level: Senior Management
Location: London
FULL_TIMEJob Reference: 7RZNXB-C53276C8
Date posted: 17 August 2026
Consultant: Darius Goodarzi
london information-technology/information-security 2026-08-17 2026-10-16 banking London London GB GBP 600 650 650 DAY Robert Walters https://www.robertwalters.co.uk https://www.robertwalters.co.uk/content/dam/robert-walters/global/images/logos/web-logos/square-logo.png true