Aviva
Cyber Security Architect
This is a contract opportunity for someone who is an experienced cyber security professional with a strong understanding of security governance, risk management, and project delivery. This role would suit someone who can quickly integrate into a complex organisation, provide expert security guidance to stakeholders, and proactively identify and manage cyber security risks across projects and business initiatives.
You'll be confident working independently, engaging with technical and non-technical stakeholders, and influencing security-related decisions to ensure risks are appropriately managed and mitigated.
Key Responsibilities
Support security risk management decisions across projects, programmes, and business change initiatives by identifying potential cyber security risks and recommending appropriate controls.
Review and assess technical designs to identify security vulnerabilities, weaknesses, and compliance gaps.
Provide expert guidance on Aviva security processes, including penetration testing, business impact assessments, and security assurance activities.
Deliver consultancy and advice on security governance frameworks, including Security Fundamentals, TPISA processes, and related security standards.
Provide cyber security input throughout the project lifecycle to ensure security requirements are embedded from inception through delivery.
Produce management information reports, dashboards, and metrics that provide visibility of security risks and remediation activities.
Create and deliver security awareness and training materials to improve security culture and promote best practices.
Engage with internal teams, third-party suppliers, and business partners to encourage and maintain strong security practices.
Ensure security findings are accurately documented, tracked, and managed, with appropriate remediation plans or risk acceptances in place.
Develop concise and effective materials that clearly articulate cyber security risks, options, recommendations, and business impacts for stakeholders and leadership teams.
Skills and Experience
Demonstrable experience in cyber security, information security, or security risk management roles within complex enterprise environments.
Strong understanding of security governance, security assurance, and risk management frameworks.
Experience reviewing technical solutions, architectures, and designs from a security perspective.
Knowledge of penetration testing processes, vulnerability management, and security assessment methodologies.
Experience supporting projects and change initiatives by providing pragmatic security advice and risk-based recommendations.
Strong stakeholder management skills with the ability to communicate technical security concepts to both technical and non-technical audiences.
Experience creating management reports, security metrics, presentations, and awareness materials.
Proven ability to manage multiple priorities and deliver outcomes in a fast-paced environment.
Experience working with third-party suppliers and managing security considerations within external partnerships.
Excellent written and verbal communication skills, including the ability to present findings, recommendations, and risk assessments to senior stakeholders.
Please ensure that you attach an up-to-date CV to your application.
We’re inclusive and welcome everyone. We want applications from all backgrounds and experiences. Excited but not sure you tick every box? Even if you don't, we would still encourage you to apply. We also consider all forms of flexible working, including part-time and job shares.