Apply Edge Start your job search

Cyber Security Solution Architect

Cognizant · Coventry, England, United Kingdom

Apply & track with Apply Edge

About the RoleWe are seeking an experienced Cyber Security Solution Architect to design, implement, and oversee enterprise-wide security architecture. The ideal candidate will have deep expertise across Identity and Access Management (IAM), firewalls, network security, cloud security, endpoint security, and broader cybersecurity domains, acting as the technical authority bridging business requirements with secure, scalable technical solutions.Role requires 3 days working from office in Coventry. Key ResponsibilitiesDesign and architect end-to-end security solutions covering IAM, network security, cloud security, endpoint protection, and perimeter defense across on-prem and multi-cloud environments.Lead the architecture, deployment, and optimization of firewalls, IDS/IPS, VPNs, proxies, and network segmentation strategies.Design and implement IAM frameworks including SSO, MFA, PAM, RBAC/ABAC, identity federation, and lifecycle management.Architect cloud security controls across AWS/Azure/GCP — including IAM policies, network security groups, encryption, key management, workload protection (CWPP), and cloud security posture management (CSPM).Design secure landing zones and cloud architecture patterns aligned with the shared responsibility model.Define endpoint security architecture including EDR/XDR, device hardening, patch management, mobile device management (MDM), and endpoint compliance policies.Develop security reference architectures, standards, and blueprints aligned with industry frameworks (NIST, ISO 27001, CIS, Zero Trust).Conduct security architecture reviews for new projects, applications, cloud migrations, and infrastructure changes.Perform risk assessments, threat modeling, and security gap analyses; recommend remediation strategies.Collaborate with network, cloud, application, DevOps, and endpoint teams to embed security by design.Evaluate, select, and integrate security tools/technologies (SIEM, SOAR, EDR/XDR, DLP, CASB, WAF, CSPM, CNAPP).Define and enforce security policies, standards, and best practices across the organization.Provide technical leadership during incident response and post-incident architecture hardening.Create and maintain documentation: HLDs, LLDs, network diagrams, cloud architecture diagrams, data flow diagrams, and security runbooks.Support audits, compliance assessments, and regulatory requirements (GDPR, PCI-DSS, HIPAA, SOX, etc.).Mentor security engineers and junior architects on best practices and emerging threats.Stay current with emerging threats, vulnerabilities, and technologies; recommend proactive improvements.Required Skills & ExperienceCore Domains:Good experience in cybersecurity and in a solution/security architect roleStrong hands-on and architectural experience in:IAM: Okta, Azure AD/Entra ID, Ping Identity, SailPoint, CyberArk (PAM), ForgeRockFirewalls & Network Security: Palo Alto, Fortinet, Cisco ASA/Firepower, Check Point, JuniperNetwork Security: VPNs, VLANs, segmentation, NAC, SD-WAN, DNS security, secure routing/switchingCloud Security: AWS (IAM, Security Hub, GuardDuty, KMS), Azure (Defender for Cloud, Sentinel, Entra ID), GCP Security Command Center; CSPM/CNAPP tools (Wiz, Prisma Cloud, Orca)Endpoint Security: CrowdStrike, Microsoft Defender for Endpoint, SentinelOne, Symantec; MDM/UEM (Intune, Jamf)Cybersecurity fundamentals: vulnerability management, threat intelligence, encryption/PKI, data protectionArchitecture & Frameworks:Experience designing Zero Trust Architecture (ZTA)Strong understanding of cloud-native security architecture and shared responsibility modelsKnowledge of security frameworks: NIST CSF, ISO 27001, CIS Controls, MITRE ATT&CKOther Technical Skills:SIEM/SOAR platforms (Splunk, QRadar, Sentinel)Scripting/automation (Python, PowerShell, Terraform) is a plusUnderstanding of DevSecOps and CI/CD security integrationContainer and Kubernetes security exposure (a plus)Certifications (preferred, not mandatory):CISSP, CISM, or CCSPCloud: AWS Certified Security – Specialty, Azure Security Engineer, Google Professional Cloud Security EngineerVendor-specific: Palo Alto PCNSE, Fortinet NSE, Cisco CCNP SecurityIAM: CyberArk CDE, Okta Certified ProfessionalTOGAF or other architecture certification (a plus)