Information Security Architect
At Unit4 , we’re in Business for People. The Global Security organisation protects our people, platforms, products, and customers by driving secure design, resilience, and maturity across the entire business. As we strengthen our architecture capability across CISO, IT, and CloudOps, we are seeking an experienced Security Architect to partner across the enterprise and help shape Unit4 ’s future‑state security landscape.
This role sits within the CISO Security Team but works with Product/Engineering, Enterprise Architecture and CloudOps. You will play a pivotal role in designing, governing, and embedding secure architectural principles across Unit4 ’s technology estate.
Job Description
The Security Architect will develop, and mature Unit4 ’s enterprise security architecture across cloud, infrastructure, identity, SaaS, and endpoint domains. You will collaborate with senior stakeholders, guide teams, and translate business strategy and risk into secure, scalable, and pragmatic designs.
This is a hands‑on architectural role for someone who thrives in complex environments, can operate strategically and tactically, and who brings expertise across security architecture, cloud, and modern enterprise platforms.
Key Responsibilities
Enterprise Security Architecture
- Lead the security target state architecture and multi-year roadmap, aligning risk reduction and business outcomes; socialize tradeoffs with leadership.
- Lead enterprise architecture assessments across multiple environments, including:
- Cloud (Azure) security and network infrastructure, including Kubernetes
- Identity & access management (zero trust, conditional access, PAM/PIM)
- CI/CD pipelines and secure software development
- AI / LLM
- Partner closely with Cloud Ops and Product Architecture to ensure security is designed into enterprise platforms and product roadmaps.
- Develop security reference architectures, and patterns aligned to Unit4 ’s security vision.
- Design and implementation of layered enterprise security architectures, ensuring defence-in-depth and resilience across digital estates.
- Act as a architectural authority in engagements interdepartmentally, providing well reasoned viewpoints on security principles, technologies, and patterns.
- Ensure architectural decisions incorporate regulatory, customer, and audit requirements and are evidenced through pattern adoption and architecture reviews.
- Partner closely with Product/Engineering, Enterprise Architecture and CloudOps to embed security controls, influence technology decisions, and ensure alignment to security strategy.
- Engage with senior stakeholders to shape cyber direction and ensure architectural consistency across teams.
Cloud & Infrastructure Security
- Secure architecture for multi‑cloud environments (Azure primary; awareness of AWS/GCP) across networking, compute, data, containers, and serverless.
- Collaborate on the security design, engineering, and implementation of solutions within the Microsoft 365 (M365) and Entra ID ecosystems.
- Consult on Microsoft security tooling including Microsoft Defender XDR, Defender for Cloud, Azure Policy, Endpoint management, Azure Network Security, and Conditional Access.
- Evaluate new cloud services, ensuring risks are identified and mitigated before adoption.
Cloud Operations and Product
- Collaborate on the security design for workloads deployed on cloud environments (Microsoft Azure preferred) (IaaS, PaaS, and Serverless), ensuring alignment with corporate security policy and regulatory requirements.
- Develop secure reference architectures for Azure cloud services, covering:
- Container platforms including AKS: cluster governance and baseline policies, workload identity, secrets management, runtime threat detection, tenancy/isolation and scale/cost guardrails.
- Compute: VMs, scale sets, serverless workloads.
- Storage & Data Services: Storage Accounts, Azure SQL, managed databases, key m