Rodeo
Get started

Medicines and Healthcare products Regulatory Agency

Lead Security Architect

Leeds
£22.8k/yr
Posted about 12 hours ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

We are currently looking for a Lead Security Architect to join our Strategy & Architecture Function within the Digital & Technology group.

This is a full-time opportunity, on a permanent basis. The role will be based in 7/8 Wellington Place, Leeds, LS1 4AP.

Government departments and agencies are working towards implementing a minimum 60% attendance in office sites.

We are currently implementing a flexible, hybrid way of working, with a minimum of 8 days per month working on site to enable the collaboration and contact with partners and stakeholders needed to deliver MHRA business. Attendance on site is driven by business needs so depending on the nature of the role, this can flex up to 12 days a month, with the remainder of time worked either remotely or in the office. Some roles will need to be on site more regularly. Please discuss this with the recruiting manager before accepting an appointment.

In recognition of the need to attract and retain employees with specialist skills this role attracts a Market Pay Supplement of up to £22,802 per annum. This non-contractual supplement is reviewed at the end of the probation period and thereafter annually and is non-pensionable.

Who are we?

The Medicines and Healthcare products Regulatory Agency enhance and improve the health of millions of people every day through the effective regulation of medicines and medical devices, underpinned by science and research.

The Digital and Technology Group (DTG) lies at the heart of the Agency and is responsible for delivering an optimised IT infrastructure and maximising the secure use of data to enable our scientists, inspectors, and the rest of the organisation to deliver world class services which can improve outcomes for patients and the general public. The Group was essential in the race to approve COVID-19 vaccines in 2020 and in supporting the UK to set up its own medicines and devices approvals systems following our exit from the EU. The work we do matters!

Its centre of excellence is also responsible for delivering a broad portfolio of change initiatives, both to transform the Agency’s legacy technologies and to deliver innovative new solutions, designed around our customers’ needs. DTG works in a holistic way to combine digital and technology change, data and information management, project delivery, business process, product management and cultural change to maximise out impact and ensure sustainability.

We plan to be at the heart of one of the most digitally advanced medical regulators in the world and we need people who can help us deliver that ambition. DTG is a great place to build your career, and we are committed to enabling our people to do the best work of their lives.

What’s the role?

As an IT Security Architect, you will play a critical role in safeguarding the department’s IT infrastructure and sensitive data, responsible for designing, building, and maintaining robust security architectures that protect the department's systems from threats and vulnerabilities.

Your primary goal is to ensure that all IT services and solutions are secure by design and compliant with government security policies and standards.

This role requires a strategic thinker with deep technical expertise knowledge, an understanding of emerging threats, and the ability to work collaboratively with various stakeholders to embed security principles throughout the IT landscape. You will work closely with various stakeholders, including business leaders, IT teams, and external partners, to develop and implement security strategies that align with the department's objectives and regulatory requirements.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Key responsibilities:

  • Security Architecture Design
  • Security Policy Development and Compliance
  • Security Awareness and Training
  • Stakeholder Engagement and Collaboration
  • Innovation and Continuous Improvement

Who are we looking for?

Our successful candidate will:

  • Develop and maintain a comprehensive Security Architecture framework that aligns with the IT strategy, government policies, and best practices.

  • Develop, implement, and maintain security policies, standards, and procedures in line with government regulations, industry standards, and departmental needs, ensuring that all IT systems and solutions comply with relevant legal, regulatory, and governmental standards, such as GDPR, Cyber Essentials, Secure By Design.

  • Collaborate with cross-functional teams to ensure security is integrated into all aspects of the Agency’s digital transformation initiatives.

  • Stay abreast of industry trends, emerging technologies, and best practices in Technical Architecture, bringing forward recommendations for improvement.

Person Specification:

Method of assessment: A=Application, T=Test, I=Interview, P=Presentation

Behaviour Criteria:

  • Leadership (I)
  • Making Effective Decisions (I)
  • Working Together (I)
  • Communicating and Influencing (P)

Experience Criteria:

  • Extensive experience designing, implementing, and managing the security architecture for large, complex organisations, with deep expertise in security architecture principles including defence in depth, zero trust, least privilege, and secure by design approaches (A, I, P)

  • Strong risk and assurance capability, including conducting risk assessments and threat modelling, developing risk management strategies, and leading internal and external security audits, assessments, and penetration testing aligned to frameworks such as CAF and NIST (A, I)

  • Proven track record in security governance and continuous improvement, including developing and maintaining security policies, standards, and procedures in line with industry best practice, and applying up to date knowledge of emerging threats, vulnerabilities, and trends to strengthen organisational security posture (A)

Technical Criteria:

  • Experience in designing and implementing secure network architectures, including knowledge of network protocols, segmentation, firewalls, VPNs, and intrusion detection/prevention systems (IDS/IPS) in on-premise and cloud environments (A, P)

  • Demonstrable experience with a range of security technologies and tools, including but not limited to:

    • Identity and Access Management (IAM), SIEM tools, endpoint protection, and cryptography and encryption solutions, Data Protection and Privacy Controls, Vulnerability Management, Security Orchestration, Automation, and Response (SOAR) Tools, Secure Mobile and Endpoint Computing and securing web applications, APIs, and microservices
  • Degree level or significant professional experience (A)

  • Desirable: Familiarity with UK public sector regulations, standards, and frameworks, such as the Government Digital Service (GDS), Secure by Design, Cyber Essentials, NCSC guidelines, GDPR, and ISO/IEC 27001 (A)

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job
  • Desirable: Security qualification e.g. CISSP, SABSA (A)

If you would like to find out more about this fantastic opportunity, please read our Job Description and Person Specification [https://mhra-gov.filecamp.com/static/files/YyjoypP4oP8FO8R1.pdf]!

Please note: The job description may not open in some internet browsers. Please use Chrome or Microsoft Edge. If you have any issue viewing the job description, please contact careers@mhra.gov.uk

The selection process:

We use the Civil Service Success Profiles to assess our candidates, find out more here [https://www.gov.uk/government/publications/success-profiles].

  • Online application form, including questions based on the Behaviour, Experience and Technical Success Profiles. Please ensure all application questions are completed in full; your application may not be considered if any responses are left blank. Our applications are CV blind, and our Hiring Managers will not be able to access your CV when reviewing your application.

  • Presentation, to be prepared as part of your interview, with further information being supplied when you reach this stage.

  • Interview, which can include questions based on the Behaviour, Experience, Technical and Strengths Success Profiles.

In the instance that we receive a high number of applications, we will hold an initial sift based on the lead criteria of Extensive experience designing, implementing, and managing the security architecture for large, complex organisations, with deep expertise in security architecture principles including defence in depth, zero trust, least privilege, and secure by design approaches.

Applicants are assessed on whether they meet any mandatory requirements as well as the necessary skills and experience for the role. Applications are scored based on the competency-based answers provided- ensure you have read these thoroughly and allow sufficient time. You can view the competencies for this role in the job description.

Use of AI in Job Applications

Artificial Intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance [https://www.civil-service-careers.gov.uk/artificial-intelligence-and-recruitment/]for more information on appropriate and inappropriate use.

If you require any disability related adjustments at any point during the process, please contact careers@mhra.gov.uk as soon as possible.

Closing date: 6th September 2026

Shortlisting date: from 11th September 2026

Interview date: from 28th September 2026

If you need assistance applying for this role or have any other questions, please contact careers@mhra.gov.uk

Candidates will be subject to UK immigration requirements as well as Civil Service nationality rules. Further information on whether you are able

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Security architecture
Risk assessment
Threat modelling
Security governance
Network security
Identity and access management
SIEM
Cryptography
Vulnerability management
SOAR
Cloud security
GDPR
Cyber essentials
Secure by design
Zero trust
Defence in depth

Location

Leeds, England, United Kingdom

Sign up to applySee more jobs like this