Back to jobs
New

Security & Information Security Architect

London, England, United Kingdom

THE ROLE

NextEnergy Group develops, builds, and operates large-scale solar Photovoltaic (PV) assets and battery storage projects across Europe. As our Security & Information Security Architect, you will set the security vision and implement secure-by-design principles for every layer of the organization — from field-level Operational Technology networks and real-time trading engines right through to corporate business systems.

A critical dimension of the role will be tight collaboration with:

  • Data Protection Officer (DPO): embedding privacy-by-design, supporting DPIAs and audits
  • Network & Security Engineering team: turning architecture patterns into robust, monitored, and recoverable configurations in production
  • External security advisors & key technology suppliers to align architectural controls with best practice guidance, managed service deliverables, and secure software supply chain requirements

This is a strategic yet hands-on role that balances secure-by-design principles with practical delivery across cloud, on-prem, and SaaS estates.

KEY RESPONSIBILITIES

  • Set & evolve enterprise security architecture (reference models, standards, patterns) covering IT, OT and hybrid-cloud environments that collect, process and trade renewable-generation data
  • Embed security & privacy requirements into solution designs, CI/CD pipelines and infrastructure as code, working closely with product squads and the DPO
  • Drive threat-modelling, technical risk assessments, and STRIDE/PASTA analyses for new solar-plant builds, grid integration projects and SaaS platforms
  • Act as lead architect on secure network topologies (IT/OT segmentation, zero-trust, IEC 62443 zones) in partnership with Network & Security Engineers
  • Define IAM, encryption-at-rest/in-transit, secrets management and key-management standards aligned with ISO 27001/27019 and NIS2
  • Review and select third-party security solutions; lead due diligence with EPC, O&M and SCADA vendors
  • Serve as technical SME for compliance frameworks (ISO 27001, NIST CSF, GDPR, IEC 62443, CIS Controls)
  • Collaborate with the DPO on data flow mapping, impact assessments (DPIA), breach notification readiness and audit responses
  • Track emerging threats to the energy sector (e.g., TSO/DSO interface risks, supply chain attacks on inverters) and update architecture roadmaps accordingly

SKILLS & COMPETENCIES

To be successful in this role, you will demonstrate:

  • Time management & prioritisation skills - things can get a little hectic, so the ability to effectively manage yourself and your workload is critical
  • Excellent interpersonal and communication skills (in English or/and other European languages) - you must be able to organise your thoughts in a way that others find clear and compelling. You will be expected to put together well-written, grammatically correct emails and other communications. When communicating verbally – whether over the phone, on video calls, in person or in meetings – you will need to be articulate, warm and engaging
  • Flexibility - being an effective team player means being flexible in your approach and open to getting involved with new things, even if they are not spelt out in your job description
  • Intellectual Curiosity – we are looking for someone who is truly interested in our profession and has the intellectual curiosity to delve deep into topics and bring fresh ideas to the team
  • Delivery focus – it may sound obvious, but the ability to proactively churn through work at pace and deliver quality outputs really matters
  • Strong critical thinking and problem-solving skills
  • Passion for our mission ‘to generate a more sustainable future by leading the transition to clean energy
  • Our values: be a leader, build trust, be responsible, be innovative and ‘bring your alpha’.

EXPERIENCE & QUALIFICATIONS 

  • 5+ years in security architecture/cyber engineering, incl. 3+ years securing renewable energy, utilities or critical-infrastructure environments
  • Deep knowledge of Azure security services, hybrid networking, container/serverless security and DevSecOps tooling
  • Demonstrable experience hardening corporate business platforms (ERP, CRM, HR, finance, M365, identity providers, SaaS)
  • Working familiarity with offensive-security / ethical-hacking techniques; able to think like an attacker, interpret red-team reports and translate findings into architectural controls
  • Strong grasp of OT protocols (Modbus/TCP, IEC 61850, DNP3) and SCADA/RTU architectures
  • Excellent stakeholder skills; proven record partnering with Data Protection Officer, Risk and Compliance, Security Operations. 
  • CISSP, CISM, SABSA, TOGAF (Security), or Azure Security Speciality (desirable)
  • ISA/IEC 62443 Cybersecurity Specialist or GIAC GICSP, demonstrating ethical-hacking capability (desirable)
  • Experience navigating ISO 27001/27019 certification, NIS2 readiness, or TSO cybersecurity codes (desirable)
  • The right to work in the UK.

WHAT WE OFFER

  • A busy role in a supportive team, with plenty of opportunities to learn
  • International scope – we operate in over 8 countries
  • Hybrid working – we will need you in the central London (Mayfair) office at least twice a week, but you will normally be able to work remotely for the remainder of the week
  • 30 days’ holiday per year (3 of which are taken during the festive shutdown in December)
  • Private pension
  • BUPA Healthcare for you and qualifying dependents
  • Cycle to work and electric vehicle leasing schemes
  • Annual discretionary bonus.

HOW TO APPLY

If you are interested in this opportunity, please follow the link to apply or send your application to careers@nextenergygroup.com. If you have been shortlisted for the next stage, we will be in contact within 14 days. 

By selecting “Apply” or sending us your CV, you indicate you have read and acknowledged NextEnergy Group’s Candidate Privacy Notice.

DIVERSITY AND INCLUSION

Our approach to diversity and inclusion is a natural extension of our values. Our entrepreneurial culture inspires us to try new things, be open to different viewpoints and be bold. Our Group is committed to cultivating and preserving a culture of connectedness that values difference and gives space for individual expression. The collective sum of our individual differences, life experiences, knowledge, innovation, self-expression, and talent and hard work form the bedrock of who we are and who we aspire to be.

We are committed to equal employment and advancement opportunity irrespective of race, color, ancestry, social background, religion, gender, national origin, sexual orientation, age, citizenship, marital status, disability and gender identity.

ABOUT US

NextEnergy Group was founded in 2007 to become a leading market participant in the international solar sector.  Since its inception, it has been active in the development, construction, and ownership of solar assets across multiple jurisdictions.  NextEnergy Group operates via its three business units: NextEnergy Capital (Investment Management), WiseEnergy (Operating Asset Management), and Starlight (Asset Development). 

NextEnergy Capital manages the Group's investment activities and has invested in over 520 solar plants, exceeding 2GW in capacity across its institutional funds.

  • NextEnergy Solar Fund (NESF): Listed on the London Stock Exchange, NESF manages 102 solar and energy storage assets in the UK and Italy, with a total installed capacity of 983MW and a gross asset value of £1,014m.
  • NextPower II (NPII): A private fund of 105 solar plants (149MW) focused on Italy, successfully divested in January 2022, delivering net IRRs exceeding its 10-12% target.
  • NextPower III ESG (NPIII ESG): A private fund targeting solar infrastructure in OECD countries (e.g., US, Spain, Italy), with $896m raised, exceeding its $750m target.
  • NextPower UK ESG (NPUK ESG): A private fund dedicated to new-build solar plants in the UK, with ~£600m raised.
  • NextPower V ESG (NPV ESG): A private OECD solar fund investing in solar and adjacent technologies like battery storage. To date, it has raised $745m, targeting $1.5bn ($2bn ceiling).

WiseEnergy® is NextEnergy Group’s operating asset manager.  WiseEnergy is a leading specialist operating asset manager in the solar sector.  Since its founding, WiseEnergy has provided solar asset management, monitoring, technical due diligence and under construction services to over 1,500 utility-scale solar power plants with an installed total capacity in excess of 3.4 GW.  WiseEnergy clients comprise leading banks and equity financiers in the energy and infrastructure sector.  

Starlight is NextEnergy Group’s development company that is active in the development phase of solar projects.  It has developed over 100 utility-scale projects internationally and continues to progress a large pipeline of c.10GW of both green and brownfield project developments across global geographies. 

NextSTEP is the venture capital fund of NextEnergy Group, dedicated to investing in innovative startups in the field of environmental sustainability. The fund primarily focuses on investments in Italy and the United Kingdom but also extends its reach to the rest of Europe and the United States, targeting startups in the pre-seed and seed stages. NextSTEP pays particular attention to emerging entities from incubators, startup accelerators, universities, and research centers, supporting projects that address global challenges in crucial areas such as Climate Change, Energy Transition, CO2 Capture and Sequestration, Circular Economy, Sustainable Cities, Sustainable Mobility, Sustainable Fashion, Waste Management, Water and much more. 

NextEnergy Foundation is a non-profit organisation founded in 2016 by the NextEnergy Group that operates internationally and whose mission is to proactively participate in the global effort to reduce carbon emissions by providing clean energy sources in regions where they are not yet available and thereby contributing to poverty reduction. As the main sponsor of this foundation, the NextEnergy Group donates at least 5% of its consolidated net profits each year. The NextEnergy Foundation has no overhead costs and therefore 100% of the funds raised go to donations for the various projects. Since 2016, in 8 years of operation the foundation has donated more than £1.2 million, supporting over 30 projects in 27 different countries around the world.

Create a Job Alert

Interested in building your career at NextEnergy Group? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...

At NextEnergy Group, we value your privacy and are committed to protecting your personal data. In accordance with the General Data Protection Regulation (GDPR), we require your consent for the processing of your personal information.

Under the GDPR, you have the right to request access to your personal data, to request that your personal data be rectified or erased, and to request that processing of your personal data be restricted. You also have to right to data portability. In addition, you may lodge a complaint with an EU supervisory authority.

Thank you for your trust and cooperation.

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in NextEnergy Group’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.