Job Title: Head of Security Design and Engineering
Department: IT Department
Reporting to: Head of Cyber Security
Main Role: Lead the design and engineering phase of the security-control lifecycle by translating control objectives and minimum-security standards into secure architectures, engineering patterns, integrated platforms and automated controls across infrastructure, applications, cloud and identity.
Principal Duties and Responsibilities
1. Core Accountabilities
- Own security architecture principles, guardrails, patterns and reference architectures.
- Direct engineering and integration of platform, infrastructure, cloud, application and identity security capabilities.
- Embed security into SDLC and DevSecOps, including SAST, DAST, SCA, secrets, API, container and Kubernetes security.
- Maintain the security-technology inventory, lifecycle, ownership, licensing, use cases and technical roadmap.
- Establish security-by-design, threat-modelling and architecture-review services for projects and material changes.
- Drive policy-as-code, orchestration and automation to improve control consistency, speed and evidence.
2. Governance Stakeholder and Reporting Responsibilities
- Maintain clear operating procedures, evidence, service metrics and management reporting for the assigned security services.
- Coordinate with IT operations, architecture, application, risk, compliance, audit and business stakeholders to resolve control gaps and delivery dependencies.
- Escalate material risks, incidents, SLA breaches and control weaknesses through the approved governance and incident-management channels.
- Support regulatory examinations, internal and external audits, risk assessments and management committees by providing accurate evidence and subject-matter input.
Personnel Specification
1. Education and Experience
- Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Information Technology, Engineering or a related discipline; a relevant master’s degree is advantageous.
- 10-15 years, including at least 5 years leading security architecture or engineering teams.
- Demonstrated experience in a regulated, high-availability or financial-services environment is strongly preferred.
2. Technical Knowledge and Skills
- Enterprise security architecture and control engineering.
- Cloud, infrastructure, application, API, container, network and identity security.
- Security technology lifecycle, integration architecture, automation and engineering assurance.
- Secure SDLC, DevSecOps, threat modelling and architecture governance.
- Working knowledge of NIST Cybersecurity Framework 2.0, ISO/IEC 27001 and the control lifecycle from design through operation and assurance.
- Ability to translate business, regulatory and risk requirements into measurable security outcomes, procedures and service metrics.
- Strong analytical, written communication, stakeholder-management and evidence-management skills in a regulated environment.
3. Operational and Behavioral Skills
- Sound judgement, integrity and the ability to handle sensitive information and high-pressure situations appropriately.
- Ability to prioritize risk, manage competing demands and deliver clear decisions, actions and escalation.
- Strong collaboration, influencing and communication skills across technical, business and executive audiences.
- Commitment to measurable service quality, continuous improvement and disciplined documentation.
- Ability to work effectively with internal teams, external suppliers, auditors and regulators.
Desired Certifications
- CISSP, preferably ISSAP
- SABSA Chartered Security Architect or TOGAF
- CCSP or recognised cloud security certification
- CISM