Whitehall Resources
Security Architect

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Security Architect
Whitehall Resources are currently looking for a Security Architect based in Cambridge for an initial 6 month contract.
INSIDE IR35
Job Overview
Shape the security foundations of a greenfield on-prem Private Cloud Platform. Embedded full-time within the Engineering IT-led programme, you will be its dedicated Enterprise Security partner. Working alongside architects and engineers, you will translate threats and corporate requirements into secure designs, working controls, automated tests and auditable evidence.
This is a highly technical, hands-on role, requiring deliverables of secure architecture designs, code and configuration reviews, influence engineering decisions, and validation that controls work as designed. Your work will help the organisation enhance services securely in transition to the new platform rather than replicate existing environments through lift-and-shift migration.
Responsibilities
- Own threat modelling across the platform, management plane, infrastructure, workloads, operations and service-onboarding pathways, keeping it current as the architecture evolves.
- Develop realistic threat stories and translate them into engineering requirements, acceptance criteria and delivery priorities, working directly with engineers to design and implement mitigations.
- Maintain traceability of threats and requirements through control implementation, testing and evidence. Own security findings through closure, maintaining the risk and control backlog, assigning actions, tracking remediation and verifying implementation.
- Embed security through infrastructure as code, CI/CD, policy as code, hardened image pipelines and configuration automation.
- Define reusable security standards for identity, privileged access, secrets, PKI, cryptographic keys, secure boot, workload isolation, network segmentation, hardened images, logging, administration and recovery, aligning to existing standards where required.
- Define measurable onboarding requirements and production readiness criteria for services using the platform.
- Translate corporate requirements and frameworks such as NIST and STIGs into pragmatic, testable controls, constructively challenging requirements that do not improve security outcomes.
- Automate security posture and compliance evidence through platform configuration, pipelines, telemetry and tooling wherever possible.
- Establish continuous validation through automated control testing, vulnerability assessment, attack simulation and proportionate penetration testing.
- Act as the conduit between the programme, IT Engineering and Enterprise Security, maintaining shared awareness of requirements, risks and decisions.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Required Skills and Experience


Get help with your application
Your very own career expert that helps elevate your application to the next level.
- Extensive hands-on security architecture and engineering experience across complex data-centre, private-cloud, hybrid-cloud or similarly large-scale infrastructure.
- Strong threat-modelling and attack-path analysis skills, with experience turning findings into implemented engineering controls.
- Practical knowledge of compute, virtualisation, containers, orchestration, storage, networking and platform-management technologies.
- Experience with infrastructure as code, CI/CD, policy as code, configuration automation and hardened image pipelines.
- Deep understanding of identity, privileged access, secrets management, PKI, network segmentation, workload isolation, logging and infrastructure hardening.
- Experience defining reusable security patterns, technical standards and measurable acceptance criteria.
- Knowledge of vulnerability management, automated security testing, attack simulation and penetration testing.
- Experience applying frameworks such as NIST and STIGs pragmatically in engineering environments.
- Experience influencing multidisciplinary teams within major infrastructure or transformation programmes.
- Strong judgement and the ability to balance risk, delivery, resilience, cost and engineering efficiency.
- Clear communication skills and the technical credibility to work effectively with engineers, security specialists and senior stakeholders.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London