cover image
CFC

Security Architect

On site

London, United kingdom

Mid level

Full Time

19-02-2026

Share this job:

Skills

Communication Cloud Security CI/CD Architecture Security Architecture Enterprise Architecture Azure AWS Software Development SDLC CI/CD Pipelines

Job Specifications

CFC is embarking on a major transformation of its core platforms and systems. To ensure these changes are secure, resilient, and compliant, we are seeking an experienced Security Architect. This role is critical to embedding secure-by-design principles for the future, supporting our Security Maturity Programme, and aligning with the CISO strategy.

About the role

You will work daily with the Group CISO to ensure consistent high standards in your areas of responsibility and ensure global adherence to security practices. The ideal candidate will have good knowledge of regulatory frameworks such as NYDFS Cybersecurity Regulation, GDPR, and other European and Australian data protection laws, and will bring a proactive, risk-based approach to the governance and operationalisation of security architecture. You will also:

Lead the design and review of secure architecture across strategic change projects.
Define and implement SDLC security standards and best practices across change projects.
Develop and enforce API security standards and secure integration patterns.
Conduct threat modelling and risk assessments for new technology implementations.
Ensure alignment with enterprise architecture and regulatory frameworks.
Support the integration of DevSecOps practices and secure CI/CD pipelines.
Collaborate with engineering, architecture, and compliance teams to embed security from project inception.
Provide expert guidance on privacy-by-design and operational resilience requirements.

About you

Exceptional understanding of secure software development, cloud security, and API security is essential, along with the ability to apply these principles in practical environments. Experience working with DevSecOps, CI/CD pipelines, and modern development practices further strengthens the capability to embed security into every stage of delivery. The role also requires strong skills in conducting threat modelling, performing risk assessments, and reviewing solution architectures, all supported by excellent communication and stakeholder engagement abilities.

Candidates should have proven experience as a Security Architect, ideally with more than five years in regulated environments. Familiarity with regulatory frameworks across the US, UK, and Australia is important, as is holding relevant certifications such as CISSP, SABSA, TOGAF, or AWS/Azure Security, which are highly desirable.

About the Company

CFC is a specialist insurance provider, pioneer in emerging risk and market leader in cyber. Our global insurance platform uses cutting-edge technology and data science to deliver smarter, faster underwriting and protect customers from today’s most critical business risks. Headquartered in London with offices in New York, San Francisco, Austin, Brussels and Brisbane, CFC has over 900 employees and is trusted by more than 150,000 businesses in 90 countries. Know more