Hybrid - London | 2-Month Initial Contract | Outside IR35 Day Rate: Competitive | Start Date: August 2026
We're looking for a senior Product Security Architect to join an initial two-month engagement, bringing cyber security architecture and product security expertise to a mix of client and internal work. This is a hands-on, secure-by-design role spanning embedded, connected, cloud and software products, not tied to any single sector or regulatory framework. If you thrive on threat modelling, secure architecture and translating standards into practical controls, this one's for you.
What you'll be doing:
Designing, reviewing and documenting secure product, system, application, cloud and infrastructure architectures, advising on IAM, authentication, cryptography, key management, network security, logging, monitoring and data protection. Leading and supporting threat modelling, attack surface analysis and risk assessments, including TARA to ISO/SAE 21434, from item definition through to attack feasibility rating and risk treatment. Defining and embedding security requirements across the secure development lifecycle, covering firmware, embedded systems, cloud services, APIs, CI/CD and software supply-chain security. Improving vulnerability intake, triage, remediation and reporting, plus SBOM/dependency visibility and product security incident readiness. Communicating complex risks to technical and non-technical stakeholders and producing assurance-grade documentation.
What we need from you:
Senior product security or security architecture experience across embedded, connected and cloud products. Demonstrable experience leading or executing TARAs to ISO/SAE 21434. The ability to derive and integrate security requirements into a secure development lifecycle. Strong written communication and assurance-grade documentation skills. Familiarity with Threat Guard (the client's TARA tooling), or the ability to get up to speed quickly. Working knowledge of standards such as ISO/IEC 27001, NIST, OWASP, IEC 62443, ISO/SAE 21434, UNECE R155 & R156, TISAX, Cyber Essentials and the EU Cyber Resilience Act.
Nice to have:
Delivery experience against the EU Cyber Resilience Act. Automotive, off-highway or connected-vehicle domain experience. Relevant certifications (e.g. CISSP, or an ISO/SAE 21434 / product security qualification).If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website Only candidates based in UK and eligible to work in UK are allowed
All Job Ads are subject to GrabJobs’s Terms of Service. We allow users to flag postings that may be in violation of those terms. Job Ads may also be flagged by GrabJobs moderation team. However, no moderation system is perfect, and flagging a posting does not ensure that it will be removed.
Be the first to receive the latest Others Full-Time Jobs in the UK.
Setup your job alert:
By activating job alerts, I agree to GrabJobs Terms & Privacy Policy. I can unsubscribe to job alerts anytime.
Skip
GrabJobs is the no1 job portal in the UK, connecting you to thousands of jobs fast!
Find the best jobs in the UK, apply in 1 click and get a job today!