Senior Specialist - Cybersecurity Architecture
الوصف الوظيفي
Position Overview
We are seeking a highly skilled and experienced Senior Specialist - Cybersecurity Architecture to lead the design, implementation, and maintenance of our enterprise cybersecurity architecture frameworks and standards. In this critical role, you will collaborate with cross-functional teams to embed robust security principles into every layer of our infrastructure, applications, and cloud environments. Your expertise will be pivotal in safeguarding our digital assets while ensuring compliance with industry-leading frameworks and regulatory requirements.
Key Responsibilities
- Architecture Design and Governance: Develop and maintain enterprise-wide cybersecurity architecture frameworks, standards, and best practices to ensure a cohesive and resilient security posture. Lead the review of solution, infrastructure, cloud, and application architectures to validate the integration of security requirements throughout the entire project lifecycle.
- Security Principles and Reference Architectures: Define and enforce security architecture principles, patterns, and reference architectures that align with industry standards and organizational goals. Drive the adoption of these principles to enhance the security and integrity of our systems.
- Risk Assessment and Mitigation: Conduct comprehensive architecture risk assessments to identify vulnerabilities and recommend appropriate security controls. Provide actionable insights to mitigate risks and enhance the overall security resilience of our enterprise.
- Cross-Functional Collaboration: Partner with Enterprise Architecture, Infrastructure, Cloud, Network, and Application teams to embed security-by-design principles into all initiatives. Foster a culture of security awareness and collaboration across the organization.
- Emerging Technology Evaluation: Stay at the forefront of technological advancements by evaluating emerging tools, platforms, and methodologies. Recommend secure implementation approaches that balance innovation with risk management.
- Cloud Security Leadership: Spearhead cloud security architecture initiatives across multiple cloud platforms, including Azure, AWS, and/or Google Cloud. Define and enforce security policies, controls, and best practices to protect cloud-based assets and data.
- Identity & Access Management (IAM): Establish and maintain robust IAM frameworks, including Zero Trust principles, network segmentation, encryption strategies, and privileged access controls. Ensure these frameworks align with organizational and regulatory requirements.
- Compliance and Regulatory Alignment: Ensure adherence to critical cybersecurity frameworks and regulatory standards, such as NCA ECC, NIST CSF, ISO 27001, and CIS Controls. Develop and implement policies and procedures to maintain compliance and demonstrate due diligence.
Qualifications and Experience
To excel in this role, you will bring a blend of technical expertise, strategic thinking, and leadership skills. The ideal candidate will possess the following qualifications:
- A Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field. A Master's degree in a relevant discipline is highly desirable and will be considered a strong asset.
- Minimum of 3-4 years of hands-on experience in Cybersecurity Architecture or Security Engineering, with a proven track record of designing and implementing secure architectures in enterprise environments.
- In-depth knowledge of cybersecurity principles, frameworks, and regulatory requirements, including NCA ECC, NIST CSF, ISO 27001, and CIS Controls.
- Proficiency in cloud security architecture, with experience across Azure, AWS, and/or Google Cloud environments. Certifications such as AWS Certified Security – Specialty, Microsoft Certified: Azure Security Engineer Associate, or Google Professional Cloud Security Engineer are a plus.
- Strong understanding of Identity & Access Management (IAM), Zero Trust architectures, network segmentation, encryption methodologies, and privileged access controls.
- Excellent analytical, problem-solving, and communication skills, with the ability to articulate complex security concepts to both technical and non-technical stakeholders.
- Certifications such as CISSP, CISM, or CCSP are highly desirable and will strengthen your candidacy.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.