Moore Kingston Smith
Cyber Security Architect & Engineering Lead

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Department: IT Infrastructure
Location: City, London
Compensation: £75,000 / year
Description
We are looking for a senior, hands-on Cyber Security Architect & Engineering Lead to help shape and strengthen our future security architecture at Moore Kingston Smith.
This is a technical leadership role, sitting within our Information Security team and reporting to the Head of Information Security. You will be responsible for translating security strategy and business requirements into secure designs, practical controls, technical standards, and measurable outcomes.
This is not a purely advisory or compliance-focused position. We are looking for someone who can design, prototype, configure, guide implementation, and validate the effectiveness of security controls across identity, cloud, data, endpoints, applications, networks, and third-party services.
A key part of the role will be helping the firm adopt AI and emerging technologies securely, including Microsoft 365 Copilot, AI agents, custom AI applications, and data-driven platforms.
Key Responsibilities
- Define and maintain security architecture across identity, endpoints, networks, cloud, SaaS, data, applications, and integration platforms.
- Design and implement modern security controls, with a strong focus on Zero Trust, secure-by-design principles, and automation.
- Lead security architecture reviews and threat modelling for major projects, new products, high-risk integrations, and emerging technologies.
- Act as the technical lead for AI security, helping to establish practical controls for Microsoft 365 Copilot, AI agents, custom AI applications, and related technologies.
- Provide senior technical oversight across security monitoring, detection engineering, incident response, and recovery capability.
- Lead or support the response to complex or high-severity security incidents, working with internal teams, external SOC providers, and specialist partners.
- Improve vulnerability and exposure management, using business risk, exploitability, attack-path context, and threat intelligence to prioritise remediation.
- Support the technical implementation and evidence required for ISO 27001, Cyber Essentials Plus, client assurance, and other regulatory or contractual obligations.
- Provide clear, risk-based technical advice to senior leaders, project teams, and technology owners.
- Coach technology teams in secure design and engineering practices, helping to build security capability beyond the core security team.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
What we’re looking for
We are looking for someone with demonstrable experience in cyber security architecture, security engineering, or a closely related senior technical security role.
You will need:
- Strong experience designing and implementing security controls in a Microsoft-centric environment, including Microsoft 365, Entra ID, Defender XDR, Sentinel, Azure, and Microsoft Purview.
- Strong knowledge of identity security, Zero Trust, cloud security, data security, endpoint security, network security, application security, API security, and secure software development.
- Experience of security architecture review, threat modelling, technical standards, reference architecture, and control design.
- Practical experience across incident response, detection engineering, threat hunting, vulnerability or exposure management, and security automation.
- Ability to automate security and assurance processes using tools such as Python, PowerShell, Logic Apps, Azure Functions, APIs, infrastructure as code, or equivalent platforms.
- Working knowledge of ISO 27001, Cyber Essentials Plus, NIST CSF, and recognised AI security or governance frameworks.
- The ability to explain complex technical risk clearly to senior stakeholders and influence delivery teams without relying on formal authority.
- A practical, outcome-focused approach, with a track record of taking ownership, improving controls, and validating that they work effectively.
- Experience in a regulated, client-confidential, or professional services environment would be advantageous.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Desirable certifications
Relevant certifications would be beneficial, such as:
- Microsoft Certified: Cybersecurity Architect Expert, SC-100
- CISSP or CCSP
- Microsoft security certifications such as AZ-500 or SC-200
- GIAC certifications in incident response, cloud, detection, or forensics
- ISO 27001 Lead Implementer or Lead Auditor
- Architecture or threat-modelling accreditation such as SABSA, TOGAF, or equivalent practical experience
About you
You will be a practical problem-solver who is comfortable moving between architecture, configuration, testing, and stakeholder engagement. You’ll be confident challenging outdated controls and practices, while staying pragmatic, commercially aware, and focused on business outcomes.
You’ll also be calm under pressure, collaborative in your approach, and able to build trust with both technical and non-technical teams.
If interested, please download the full job spec.
Job Benefits
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location