Security Architect
Job Summary:
We are seeking a highly skilled Security Architect to design and implement robust security solutions across enterprise systems and applications. The ideal candidate will have expertise in security architecture, threat modeling, risk management, and secure system design. This role involves collaborating with IT, development, and security teams to establish security frameworks, assess risks, and implement best practices for a secure infrastructure.
Key Responsibilities:
- Design and implement security architectures for applications, cloud, and enterprise systems.
- Conduct threat modeling and risk assessments to identify potential security weaknesses.
- Define security requirements and best practices for software development and infrastructure teams.
- Develop and enforce security policies, standards, and guidelines.
- Assess and recommend security tools, technologies, and solutions for risk mitigation.
- Evaluate and ensure compliance with security regulations and industry standards.
- Lead incident response and forensic analysis in case of security breaches.
- Provide security training and awareness programs for stakeholders.
Required Skills and Experience:
- Strong experience in security architecture, risk management, and secure system design.
- Familiarity with zero trust architecture, IAM, encryption, and data protection.
- Deep understanding of security frameworks such as NIST, ISO 27001, CIS, and MITRE ATT&CK.
- Experience with DevSecOps, security automation, and security operations (SOC/SIEM).
- Knowledge of common threats, vulnerabilities, and attack vectors (e.g., OWASP Top 10, MITRE CWE).
- Strong analytical and problem-solving skills with a proactive security mindset.
- Excellent communication skills and ability to work with cross-functional teams.
Preferred Qualifications:
- Relevant security certifications such as CISSP, CISM, CCSP, OSCP, TOGAF, or SABSA.
- Experience with container security, API security, and Kubernetes security.
- Knowledge of regulatory compliance frameworks such as PCI-DSS, GDPR, HIPAA, and SOC 2.