Paul Crossan

Lead Enterprise Architect

United Kingdom

About

Accomplished Lead Security Architect with extensive experience across Financial Services, Government, and Legal sectors. Specialising in Azure, AWS, and M365 security, with strong skills in security design assurance and successful delivery of change programs. Certified as CISSP, Prince 2, and Ethical Hacker. I have not only worked inline with security frameworks such as NIST, SCF and ISO27001 but also helped organisations achieve and maintain certification. I am experienced at forming and leading security architecture teams, have collaborated with CISO’s to develop security strategies aligned not only to operational security needs but business strategy. During my career I have successfully completed complex transformation programs, consistently ensuring the successful delivery of secure solutions, IT infrastructures and commercial procurements.

Experience

  • Lead Enterprise Architect at Charities Aid Foundation (CAF)
    Jan 2025 - Present · 1 yr 7 mos

    Lead Enterprise Architect for the Charities Aid Foundation (CAF) Renew Programme, responsible for modernising CAF’s enterprise architecture, technology estate, and security posture to support its role as a global, regulated financial services provider for the charity sector. Accountable for defining and governing CAF’s target architecture across business, data, application, integration, cloud, and identity domains, ensuring the renew programme delivered a secure, scalable, and compliant platform for future growth. Key responsibilities: • Own the enterprise target architecture for CAF’s renewal • Define architectural principles, standards, and reference architectures • Establish and run Architecture oversight authority (AOA) and support via TDA for architectural governance • Translate regulatory, operational, and business requirements into executable architecture • Lead cross-domain architecture across payments, customer platforms, finance, data, and cloud • Control technical debt, dependencies, and platform risk across the transformation Security leadership: • Own the security architecture for the renewal programme • Embed security-by-design across cloud, identity, data, and application platforms • Define Zero Trust, identity, access, and data protection models aligned to financial-crime, privacy, and regulatory obligations • Ensure all designs pass security and risk assurance before delivery • Align architecture with audit, compliance, and regulatory scrutiny Impact: • Delivered a governed, modern enterprise architecture for CAF’s future operating model • Strengthened cyber security, data protection, and regulatory resilience • Enabled CAF to scale digital services safely across global charity and donor communities This role combined enterprise architecture, cloud strategy, and cyber security leadership for one of the UK’s most trusted financial institutions for the charity sector.

  • Lead Security Architect at HX Hurtigruten Expeditions
    Jan 2024 - Feb 2025 · 1 yr 2 mos

    Acting as the Lead Security Architect on the programme aiming to ensure the successful delivery of the organisations split • Provide Security assurance on the design, build & migration of users and applications to new HX Azure tenant, Active Directory, M365, Dynamics ERP, Salesforce, Digital applications, HX website – identifying/escalating any risks outside of tolerance • Implement new security framework & assurance process, perform GAP analysis & implement security controls in order to protect the organisation examples include: Atomic OSSEC SIEM/EDR/SOAR/FIM/Vulnerability Mgmt/Anti-virus, Cloud Flare, Egress, Cisco Umbrella, • Utilise Confluence & Lucid to document the “as is” security estate building solution blueprint design documents and represent during Architecture review boards • Act as Lead Security SME on multiple commercial procurements of the above-mentioned technologies.

  • Lead Security Architect at Ministry of Justice UK
    May 2023 - Jan 2024 · 9 mos

    Acting as the Lead Security Architect on the programme ensuring the successful delivery of EUCS projects covering: Legacy Estate, Hardened Build, M365 Services, 2nd Line Support services, Hardware support & Procurement my main responsibilities are: • Build relationships with a wide range of stakeholders & act as SME providing guidance, advice & oversight for securing IT architectures • Develop & maintain MoJ’s Evolve security architecture framework & assurance processes • Act as Lead Security SME on multiple commercial procurements • Assurance against Cyber Assessment Framework (CAF), NCSC guidance, CCS procurement Frameworks & Secure Controls Framework • Identify, document and escalate risks that exceed the MOJ’s risk tolerance level • Identification, recommendations & escalation of identified risks • Threat Modelling (STRIDE LM) • Review & provide input on LLD/HLD’s • Manage MSP Security Architecture resources assigned to programme

  • Enterprise Security Architect at Insights by Kantar
    Aug 2021 - May 2023 · 1 yr 10 mos

    Recruited to act as the Director of Enterprise Security Architecture, tasked with setting up the Security architecture function, my main responsibilities were: • Defining enterprise security technology strategy • Defining, implementing, and maintaining network security standards • Defining Architecture assurance framework aligned to SCF framework • Provide cloud security subject matter expertise for Azure, AWS and Office 365 platforms to ensure cloud-related cyber risks are kept within tolerance level/appetite. • Develop reference architectures for common cloud deployment models – IaaS, PaaS and SaaS. • Review cloud security posture management platform to identify and escalate risk – assist with plans on how to remediate • Provide security architectural input (design and implementation) around Microsoft 365/Azure services - Active Directory (AD) / Azure AD (AAD), MFA, Azure Information Protection (AIP), Azure Sentinel, Microsoft Intune, Office 365 Advanced Threat Protection (ATP) • Recruit & manage team of 6 Cyber Security Architects • Collaborate with CISO function to create Security strategy and associated operating model/procurement strategy

  • Enterprise Security Architect at easyJet
    Sep 2018 - Aug 2021 · 3 yrs

    • Defining enterprise security technology strategy • Develop the business, information, and technical artefacts that constitute the enterprise cloud security architecture and solutions. • Act as technical lead on Enterprise Security program (20 million spend) to ensure program success in cyber maturity increase and alignment with business strategy • Architect the adoption and implementation of Azure security technologies - Azure Security Center, Azure Active Directory, Azure Advanced Threat Protection , Azure AD Identity Protection, Azure AD Privileged Identity Management, Azure Tenant Security, Network Security, Azure Sentinel, Azure Firewall • Manage team of 4 Cyber Security Architects