About this role
Salary: £? - ? per year
Requirements: Senior product security or security architecture experience across embedded, connected and cloud products.Demonstrable experience leading or executing TARAs to ISO/SAE 21434.Ability to derive and integrate security requirements into a secure development lifecycle.Strong written communication and assurance-grade documentation skills.Familiarity with Threat Guard, or the ability to get up to speed quickly.Working knowledge of standards such as ISO/IEC 27001, NIST, OWASP, IEC 62443, ISO/SAE 21434, UNECE R155 and R156, TISAX, Cyber Essentials and the EU Cyber Resilience Act.Nice to have: delivery experience against the EU Cyber Resilience Act.Nice to have: automotive, off-highway or connected-vehicle domain experience.Nice to have: relevant certifications such as CISSP or an ISO/SAE 21434/product security qualification. Responsibilities: Design, review and document secure product, system, application, cloud and infrastructure architectures.Advise on IAM, authentication, cryptography, key management, network security, logging, monitoring and data protection.Lead and support threat modelling, attack surface analysis and risk assessments, including TARA to ISO/SAE 21434 from item definition through to attack feasibility rating and risk treatment.Define and embed security requirements across the secure development lifecycle, covering firmware, embedded systems, cloud services, APIs, CI/CD and software supply-chain security.Improve vulnerability intake, triage, remediation and reporting, as well as SBOM/dependency visibility and product security incident readiness.Communicate complex risks to technical and non-technical stakeholders and produce assurance-grade documentation. Technologies: CI/CDCloudCryptographyEmbeddedFirmwareIAMSupportNetworkOWASPSecurityArchitect More:
We are hiring for an initial two-month hybrid contract based in London, with a competitive day rate and an outside IR35 arrangement. This is a senior, hands-on secure-by-design product security architecture role spanning embedded, connected, cloud and software products, supporting both client and internal work. We offer an opportunity to apply cyber security architecture expertise across a broad range of products and standards, with the engagement starting in August 2026.
last updated 29 week of 2026