Principal Security design consultant
Salary: Competitive
Location: Hybrid (London/Home)
Working Pattern: Hybrid (at least 3 days in office)
Job Type: Permanent
Start date: ASAP
Level: SFIA 5
Reports to: CSA: Head of Practice
THE VACANCY:
This Principal Security Design Consultant role is designed for an experienced security architecture specialist who can lead complex protective monitoring and Security Operations Centre (SOC) transformation engagements. Candidates are expected to have progressed through architecture, engineering, SOC or consultancy roles and to have delivered enterprise-scale SIEM, EDR/XDR and managed security service change.
The role will initially lead a major enterprise migration from an incumbent endpoint detection and limited-hours outsourced monitoring model to Microsoft Defender XDR and Microsoft Sentinel, transitioning into a Cyro-managed SOC. The successful candidate will own the engagement from discovery and target-state design through migration, assurance and service transition.
This is not a single-technology role. The successful candidate must also be able to lead broader security architecture engagements across cloud, identity, network, endpoint, data protection and hybrid environments, while providing authoritative advice, mentoring colleagues and contributing to Cyro's propositions and pre-sales activity.
Primary responsibilities:
soc architecture and Transformation:
Lead discovery, current-state assessment and target-state design for SOC, SIEM, SOAR, EDR/XDR and protective monitoring engagements.
Define monitoring strategies, target operating models, service boundaries, responsibilities, escalation paths, service levels and transition plans for client-operated and managed SOC services.
Design Microsoft Sentinel and Defender XDR solutions, including Defender for Endpoint, Defender for Identity, Defender for Office 365 and Defender for Cloud Apps where relevant, making effective use of Microsoft 365 E5 capabilities.
Plan and govern migrations from incumbent platforms and service providers, including coexistence, endpoint migration, telemetry validation, cutover, rollback and decommissioning.
Define log-source onboarding, data connector, normalisation, retention, ingestion, cost-management and data-residency requirements across cloud, on-premises and third-party services.
Develop detection and response architectures covering analytics rules, MITRE ATT&CK-aligned use cases, threat hunting, workbooks, watchlists, automation and SOAR playbooks.
Design secure integrations with ITSM, CMDB, threat intelligence, vulnerability management, identity, network and incident response processes.
Produce and own architecture artefacts including requirements, High-Level Designs (HLDs), Low-Level Designs (LLDs), reference patterns, design decisions, migration roadmaps, test criteria and as-built assurance.
Broader security architecture:
Lead architecture reviews and design engagements across cloud and hybrid platforms, identity and access management, network security, endpoint and workload protection, data security and logging and monitoring.
Translate business, risk and regulatory requirements into proportionate technical controls aligned to the NCSC Cyber Assessment Framework (CAF), NIST Cybersecurity Framework, ISO 27001 and client-specific standards.
Provide technical assurance throughout implementation, working with engineering and delivery teams to resolve design risks, exceptions and deviations.
engagement leadership and client managment:
Act as the lead consultant and trusted advisor for strategic clients, chairing workshops and design authorities and maintaining accountability for outcomes, time, cost and quality.
Coordinate Cyro architecture and SOC resources, client teams and third parties; define work packages, delegate activity, assure deliverables and mentor colleagues.
Communicate technical risk, architectural decisions and service implications clearly to engineering, operational, risk and executive stakeholders.
pre-sales and capability development:
Support opportunity qualification, scoping, estimating, solution design, proposals, tender responses and client presentations for SOC and wider security architecture engagements.
Develop reusable reference architectures, methods and design patterns, and contribute to the continual improvement of Cyro's managed SOC and architecture services.
Evaluate emerging security technologies, service models and licensing options, making evidence-based recommendations that balance security, operability and cost.
Desirable skills and experience:
Microsoft security certifications such as SC-100, SC-200 or AZ-500.
Hands-on experience with other SIEM and EDR/XDR platforms such as CrowdStrike, Splunk, QRadar, Rapid7 or Elastic.
Experience with KQL, Sigma, Logic Apps, PowerShell or other automation and detection-as-code approaches.
Knowledge of MITRE ATT&CK, NIST SP 800-61, NCSC CAF and recognised security operations maturity models.
Experience of ITIL-aligned service design, service transition and onboarding to managed SOC services.
Architecture certification or demonstrable application of frameworks such as TOGAF or SABSA.
Experience working in or with Critical National Infrastructure, UK Government or similarly regulated sectors.
Professional registration awarded by the UK Cyber Security Council (Principal or Chartered Security Professional).
Essential Skills and Experience:
Substantial experience as a SOC Architect, Security Architect or senior technical consultant leading enterprise SIEM, EDR/XDR or protective monitoring transformations.
Deep practical design experience with Microsoft Sentinel, Defender XDR and Defender for Endpoint, including Log Analytics, KQL, data connectors, analytics and automation.
Full lifecycle delivery experience from discovery and HLD/LLD development through migration, testing, service transition and implementation assurance.
Experience migrating from third-party EDR, SIEM or outsourced SOC services, including platforms such as CrowdStrike.
Strong understanding of SOC operations, detection engineering, incident response, threat hunting and managed security service operating models.
Broad enterprise security architecture capability across Azure and Microsoft 365, identity, network, endpoint, data protection and hybrid environments.
Experience designing telemetry and integration patterns for complex environments, including retention, ingestion cost, access control and data residency considerations.
Demonstrable leadership, stakeholder management, supplier management and client-facing consulting skills.
Experience delivering significant work outcomes within complex, regulated or high-availability enterprise environments.
Eligibility for UK Security Clearance (successful appointment will be subject to being granted Security Clearance).
Levels of responsibility: SFIA Level 5
So why choose Cyro for your next opportunity?
To build, run and maintain a successful compliance programme, you need a connected approach – a team you can trust from strategy to support, and everything in between. At Cyro, this is what we do!
As part of our team, you could be working with some of the biggest names in the Critical Nation Infrastructure and Service Provider sectors including London Underground, Network Rail, Transport for London, RNLI, MOD and more. You’ll help us ensure the most important messages get through – however tough the conditions.
Here are just some of the ways we’re different:
You’ll go further with us. We understand the importance of career development and will give you all the support you need to realise your potential. You’ll receive formal training, e-learning and mentoring from top professionals. And we offer opportunities to transfer to other sectors – or even different technology areas.
You’ll make a difference. You could be working outdoors, battling the elements, or in one of our many offices helping us develop the network infrastructures of tomorrow.
You’ll be treated as an individual. We’re not a vast corporation, which means every individual counts. With us, you’ll be valued and supported, involved and empowered from day one.
You’ll be well rewarded. We offer salary progression that reflects market rates and personal performance, a flexible working environment and excellent training.
Excellent Employee Benefits:
Cyro is committed to ensuring that we offer industry leading career opportunities, salary and benefits packages. Join us and you can expect to receive:
25 days holiday, including public holidays, plus the option to buy or sell five days each year
Company pension scheme
A range of family friendly policies
An employee-funded car leasing scheme
Occupational health support
Cyro Rewards Scheme
apply now:
Please send your CV to hr@cyro.uk
Click here to view our company information pack
Cyro is an equal opportunities employer and is committed to diversity and inclusion.
We reserve the right to close this vacancy once we have received sufficient applications.
This job description sets out the duties and responsibilities of the job at the time when it was drawn up. Such duties and responsibilities may vary from time to time without changing the general character of the duties or the level of responsibility entailed. Such variations are a common occurrence and cannot in themselves justify a reconsideration of the grading of the job.