The Cybersecurity / Security Architect is responsible for defining and governing enterprise security architecture to ensure that security, privacy, resilience, and regulatory requirements are embedded into business, application, data, technology, cloud, and solution architectures. The role develops security principles, reference architectures, standards, controls, and target-state designs while providing architecture assurance for strategic initiatives and technology solutions.
Requirements
- Develop and maintain enterprise security architecture in alignment with business strategy, enterprise architecture, cybersecurity strategy, and regulatory requirements
- Assess the current-state security architecture across applications, data, infrastructure, cloud, networks, identity, and integration environments
- Define target-state security architecture and security transformation roadmaps
- Develop security architecture principles, standards, patterns, reference architectures, and design guardrails
- Embed security-by-design and privacy-by-design requirements across enterprise and solution architecture activities
- Define Zero Trust architecture principles and implementation patterns across identity, devices, networks, applications, data, and workloads
- Define identity and access management architecture including authentication, authorization, privileged access, federation, and identity lifecycle controls
- Define security architecture for cloud, hybrid, on-premises, SaaS, and externally hosted environments
- Define network security architecture including segmentation, secure connectivity, firewalls, gateways, remote access, and trust boundaries
- Define application and API security architecture requirements across modern and legacy environments
- Define data security architecture including encryption, key management, data classification, data protection, and secure data exchange
- Support threat modeling, architecture risk assessment, and identification of security gaps and mitigation measures
- Review solution architectures and technical designs for compliance with enterprise security standards and control requirements
- Collaborate with enterprise architects, solution architects, cloud architects, application teams, infrastructure teams, data teams, and cybersecurity operations
- Support security technology evaluation, vendor assessment, technical due diligence, and architecture decisions
- Participate in architecture governance, security design reviews, and Architecture Review Boards
- Support alignment with applicable national cybersecurity controls, regulatory requirements, and recognized international security standards
Required Experience
- * Minimum 8-10 years of experience in cybersecurity, information security, infrastructure security, cloud security, solution architecture, or related disciplines
- At least 4-5 years of hands-on experience in Security Architecture or a comparable senior cybersecurity architecture role
- Demonstrated experience designing enterprise-scale security architectures across multiple technology domains
- Strong experience with identity, network, application, cloud, infrastructure, and data security architecture
- Experience supporting large-scale digital transformation, cloud transformation, or cybersecurity improvement programs
- Experience working with enterprise architecture teams, cybersecurity functions, technology teams, vendors, and senior stakeholders
Core Competencies
- Enterprise Security Architecture
- Security-by-design and privacy-by-design
- Zero Trust Architecture
- Identity and Access Management architecture
- Cloud security architecture
- Network and infrastructure security architecture
- Application and API security architecture
- Data security and information protection
- Security controls and reference architectures
- Threat modeling and architecture risk assessment
- Security governance and architecture assurance
- Cybersecurity compliance and regulatory alignment
- Security technology evaluation
- Stakeholder management and consulting
Preferred Frameworks, Standards & Methods
- * SABSA
- TOGAF
- ArchiMate
- NIST Cybersecurity Framework
- NIST security architecture and control guidance
- ISO/IEC 27001 and ISO/IEC 27002
- Zero Trust architecture principles
- Cloud Security Alliance guidance
- Applicable national cybersecurity frameworks and controls
- Secure software development and DevSecOps practices
Preferred Tools & Technology Exposure
- * Enterprise architecture tools such as Bizzdesign, Sparx Enterprise Architect, Orbus/iServer, ARIS, or similar platforms
- Identity and access management, privileged access management, and federation technologies
- SIEM, SOAR, endpoint security, network security, and cloud security technologies
- Encryption, key management, certificate management, and data protection technologies
- Cloud security services across Microsoft Azure, AWS, Google Cloud, or equivalent platforms
- Security architecture, threat modeling, vulnerability management, and risk assessment tools
Preferred Qualifications & Certifications
- * Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Computer Engineering, or a related discipline
- SABSA certification is highly desirable
- CISSP, CCSP, CISM, or equivalent security certification is highly desirable
- TOGAF certification is desirable
- Relevant cloud security, identity, network security, or security architecture certifications are advantageous
Personal Attributes
- Strong analytical and risk-based thinking
- Ability to translate cybersecurity requirements into practical architecture controls and design decisions
- Strong communication, facilitation, and stakeholder management skills
- Ability to balance security, business value, usability, cost, and operational practicality
- Strong attention to detail, architecture quality, and regulatory compliance
- Consulting mindset with the ability to work across multiple stakeholders, programs, and technology domains