Senior Information Security Architect
BBC
- Salford, England, United Kingdom
- Salford, England, United Kingdom
Über
Purpose of the Role The BBC Information Security Team works with BBC teams around the world to provide expert advice, review systems and deal with threats. The Security Engineering & Architecture team focuses on ensuring the BBC’s digital products and platforms are secure by collaborating with product teams during the early stages of the SDLC and providing expert technical advice. The team also fosters relationships across the business, runs a large network of Security Champions and provides technical expertise to other areas of Information Security.
Your Key Responsibilities And Impact
Architecture of Systems
Perform security risk assessments on BBC Digital Product environments at various stages of the Software Development Life Cycle (SDLC) and recommend security enhancements, remediation and mitigation strategies.
Digital Policy & Guidance – research and understand new security technologies, trends and threats and provide guidance to stakeholders and 3rd parties.
Assist in running the BBC Security Champions network – facilitate sessions, engage champions and evolve the network.
Support tactical initiatives to secure Digital Product environments – contribute to policies, procedures and standards.
Develop and maintain relationships with Digital Product key suppliers, staff, Security Champions and other stakeholders.
Peer with the InfoSec team to design, develop and deploy code for systems that assist the BBC InfoSec function and help teams understand their current risk posture.
Vulnerability Management – support processes around security issues identified in Digital Product environments, including investigation, validation and revalidation.
Essential Criteria
Familiarity with at least one coding language (e.g., Python, JavaScript) and demonstrable experience designing and implementing digital software projects.
Ability to convey complex technical knowledge and guidance in written and verbal form to multiple audiences.
Demonstrable ability to break complex problems into tangible parts, self‑direct required learning and operate in a semi‑autonomous manner.
Experience deploying systems and applications from code to a cloud environment (e.g., AWS).
Demonstrable experience of a wide range of technical security knowledge and applying it to identify and remediate security issues in digital software products.
Desired But Not Required
Experience of being involved in a community and taking an active lead in organising and facilitating.
Experience with STRIDE Threat Modelling and mitigating issues from application security tooling would be ideal.
Next Steps Submit your application on the BBC careers page. At each stage you may need to disclose any unspent convictions or police charges in line with our Contracts of Employment policy.
#J-18808-Ljbffr
Sprachkenntnisse
- English
Hinweis für Nutzer
Dieses Stellenangebot stammt von einer Partnerplattform von TieTalent. Klicken Sie auf „Jetzt Bewerben“, um Ihre Bewerbung direkt auf deren Website einzureichen.