About Us
Solirius Reply, part of the Reply Group, is a technology consultancy and digital transformation partner that helps organisations solve complex challenges through strategy, design, engineering, and delivery.
We work closely with our clients to deliver secure, accessible, user-focused services that evolve with their needs. By combining deep technical expertise with people-centred design, we create solutions that deliver meaningful, lasting impact.
Our consultants partner directly with client teams, embedding into organisations to understand their goals, challenges, and users. This collaborative approach enables us to deliver tailored solutions that drive measurable outcomes across public and private sectors.
Past and present clients include the Ministry of Justice, Department for Education, Ministry of Housing, Communities and Local Government, UEFA, International Olympic Committee, and Mercedes-Benz. Our services span the full digital delivery life cycle, including architecture, engineering, delivery management, user-centred design, business analysis, data, DevOps, and AI.
About You
You are a motivated and adaptable professional with a strong analytical mindset and a passion for using technology to solve real-world problems. You enjoy working in collaborative, agile teams and take pride in delivering high-quality solutions that make a tangible impact. With strong communication skills and a consultative approach, you're comfortable engaging with clients, understanding their needs, and translating them into effective outcomes.
Role Overview
As a Senior Security Advisor, you will serve as the strategic and technical cyber security authority across our public sector cloud transformation initiatives. You will work closely with the team to embed security-by-design.
You will ensure that all digital services and Azure infrastructure meet stringent public sector cyber security baselines, maintain regulatory compliance, and remain resilient against evolving threat landscapes.
Key Responsibilities
1. Security Architecture & Azure Governance
Secure Cloud Design: Provide expert security consultancy and design patterns for Microsoft Azure infrastructure, workloads, and SaaS applications (including Enterprise Scale Landing Zones, Hub-Spoke topologies, and Microsegmentation).
Policy Enforcement & Guardrails: Define and enforce cloud security baselines, RBAC structures, Privileged Identity Management (PIM), and automated guardrails using Azure Policy and Microsoft Defender for Cloud.
Zero Trust Strategy: Drive the continuous adoption of Zero Trust architecture principles across identity (Microsoft Entra ID), network segmentation, endpoint management, and data handling.
2. Public Sector Compliance, Governance & Assurance
Standards Alignment: Align organizational posture with national public sector standards, including the NCSC Cyber Assessment Framework (CAF), GovAssure, ISO 27001, and HMG Security Policy Framework (SPF).
Risk & Threat Modeling: Lead threat modelling exercises (STRIDE) and cyber risk assessments for new digital public services, presenting clear risk posture metrics to executive and non-technical leadership.
Third-Party & Supply Chain Risk: Evaluate risk across suppliers, third-party software, and public sector inter-agency integrations.
3. Cyber Operations & Threat Defense Oversight
SIEM & SOC Alignment: Work alongside SOC/SecOps teams to optimize Microsoft Sentinel (KQL analytics rules, automation playbooks, and log telemetry) to maintain high-signal threat detection.
Incident Response Escalation: Serve as a subject matter expert for major cyber incident investigations, threat hunting, and post-incident reviews.
Vulnerability & Posture Management: Monitor and drive remediation of high-severity vulnerabilities and security recommendations surfaced via Microsoft Defender and Azure Advisor.
4. Culture & Advisory Leadership
Security Engagement: Foster a security-first culture across multi-disciplinary agile delivery teams, technical developers, and non-technical delivery managers.
Stakeholder Management: Translate complex Azure security concepts into actionable risk decisions for Senior Information Risk Owners (SIRO), Chief Information Security Officers (CISO), and program directors.
Person Specification
Essential Experience & Technical Skills
Desirable Criteria
Knowledge of Infrastructure-as-Code (IaC) security scanning for Terraform, Bicep, or ARM templates.
Familiarity with Microsoft Purview for data loss prevention (DLP), classification, and records management in public sector contexts.
Experience working within central/local government, NHS/healthcare, or Critical National Infrastructure (CNI) environments.
Certifications & Qualifications
Essential/Desirable Certifications
Microsoft Azure Certifications:
AZ-500: Microsoft Certified: Azure Security Engineer Associate (Highly Desirable)
SC-100: Microsoft Cybersecurity Architect (Desirable)
Industry Security Certifications:
CISSP (Certified Information Systems Security Professional)
CISM (Certified Information Security Manager)
CRISC (Certified in Risk and Information Systems Control) or CCSP (Certified Cloud Security Professional)