Secure-by-Design & Assurance
JSP 440 / JSP 453 aligned Secure-by-Design processes, self-assessment trackers, risk treatment plans and continuous Authority to Operate evidence packs.

DEFENCE · NUCLEAR · GOVERNMENT
We embed as your senior security and enterprise architecture authority — governing design, evidencing compliance and keeping high-classification programmes inside their Authority to Operate.
Capabilities
JSP 440 / JSP 453 aligned Secure-by-Design processes, self-assessment trackers, risk treatment plans and continuous Authority to Operate evidence packs.
NCSC CAF / GovAssure, GovS 007 & GovS 005, ISO 27001, Cyber Essentials Plus, CIS 18 and NIST SP 800-53/37/30 assessment and audit readiness.
Architecture governance frameworks, security principles, TRMs and ArchiMate modelling aligned to CSOC, NATO STANAGs, NCMS data standards and TOGAF.
Microsoft Sentinel and Defender XDR strategy and delivery, MITRE ATT&CK aligned use cases, AWS/GCP connectors and SOC service onboarding.
Entra ID, Okta, Zscaler, CyberArk SaaS PAM, conditional access and MFA design, data classification, DLP and data access governance (PAM/IAM/CIEM).
NIST SP 800-207 data-centric Zero Trust, Azure/GCP/AWS landing zones, segmentation, crypto and HSM key management to FIPS 140-3 Level 3.
Frameworks & standards
Every artefact we produce — HLDs, threat models, risk treatment plans, ITHC scopes and CAF reports — is written to survive design authority boards, accreditor scrutiny and audit.
Selected engagements
2026
Senior Enterprise Architect — Governance & Assurance
Jun 2025 – Dec 2025
Enterprise Security Architect — Obsolescence Exit & SIEM Strategy
Apr 2023 – Jun 2025
Lead Architect, Security Focus — Capital Programme
May 2021 – Apr 2023
Lead Solutions Architect — Battlespace & Hosting
Apr 2019 – Apr 2021
Senior Design Architect — Data Centre & Application Migration
Contact
Short-notice architecture reviews, secure-by-design assessments and interim security architecture leadership across the UK.