×
Register Here to Apply for Jobs or Post Jobs. X

Cyber Security Architect

Job in Cardiff, Cardiff City Area, CF10, Wales, UK
Listing for: Vargo Group
Full Time position
Listed on 2026-01-06
Job specializations:
  • IT/Tech
    Cybersecurity, Systems Engineer
Salary/Wage Range or Industry Benchmark: 85000 GBP Yearly GBP 85000.00 YEAR
Job Description & How to Apply Below

Lead Cloud & Cyber Security Engineer

Permanent

Hybrid

Up to £85,000 + Bens

An exciting opportunity has arisen with our well-established, high profile client based in Central Cardiff. This key leadership and technical role is responsible for the strategic and hands‑on management of the organization's Microsoft 365 and Azure security environments
.

The successful candidate will combine deep technical expertise with leadership skills to ensure the robust protection of corporate data, systems, and identities, driving a Zero Trust security model and secure‑by‑design cloud architecture
.

Key Responsibilities & Focus Areas
  • Cyber Security Leadership: Define the security strategy and roadmap, lead the cyber security function, and take charge of incident management and response to all security events and breaches. Also responsible for vendor security assessments.
  • Identity & Access Management (IAM): Expertly manage Microsoft Entra (Azure AD), implementing Conditional Access and Zero Trust principles, and managing PIM/JIT access,
    MFA
    , and passwordless authentication.
  • Microsoft 365 Security: Configure and monitor the entire Microsoft 365 Defender Suite
    , implement DLP/AIP
    , manage Microsoft Purview for governance and compliance, and secure SharePoint, One Drive, and Teams.
  • Azure Security Engineering: Design and implement security controls including RBAC
    , Managed Identities
    , Network Security Groups,
    Azure Firewall
    , Key Vaults
    , and compliance frameworks using Azure Policy/Blueprints
    .
  • Threat Detection & Incident Response: Utilize Microsoft Sentinel (SIEM) for log analysis, alert triage, and threat hunting. Coordinate incident response playbooks and be familiar with forensics and threat intelligence.
  • Infrastructure & Application Security: Oversee secure configuration for Azure resources (VMs, App Services, Containers), integrate Dev Sec Ops security using tools like Defender for Dev Ops/Git Hub Advanced Security
    , and manage secure configuration via Infrastructure as Code (Bicep/Terraform) and Intune for mobile device security.
  • Risk & Control Management: Maintain the cyber security risk register and associated controls, ensuring the ISMS (Information Security Management System) remains current.
  • Team Management & Mentoring: Develop the security team's skills, promote a secure‑by‑design culture
    , and oversee the cyber security awareness program.

the successful candidate must possess deep, hands‑on expertise in the following Microsoft cloud security technologies:

What'll you need to know:
Microsoft Core Platforms
  • Microsoft Entra  (Azure AD): Architecture, governance, Conditional Access Policies, Zero Trust principles.
  • Privileged Identity Management (PIM) and Just‑In‑Time (JIT) access.
  • Multi‑Factor Authentication (MFA) and passwordless methods (FIDO2).
  • Microsoft 365 Defender Suite: Configuration and monitoring (Endpoint, Identity, Office 365, Cloud Apps).
  • Microsoft Purview: Data Loss Prevention (DLP), Information Protection (AIP), Sensitivity Labels, and Insider Risk Management.
  • Microsoft Sentinel (SIEM): Log ingestion, analytics, alert triage, playbooks, and threat hunting.
Azure Infrastructure Security
  • Azure Role-Based Access Control (RBAC) and Managed Identities
    .
  • Azure Networking Security: NSGs, Azure Firewall, Private Endpoints.
  • Secrets Management: Azure Key Vaults and Disk Encryption.
  • Compliance: Azure Policy, Blueprints, and resource compliance frameworks.
Engineering & Deployment
  • Dev Sec Ops : Integration with tools like Defender for Dev Ops/Git Hub Advanced Security.
  • Infrastructure as Code: Secure configuration using Bicep, Terraform, or ARM.
  • Endpoint/Mobile Security: Endpoint hardening, patch management, and Mobile Device Management (
    Intune
    ).

#LI-TM1

#J-18808-Ljbffr
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary