Job Description & How to Apply Below
The Lead - Security Architect acts as a trusted advisor to the Client, ensuring that new initiatives, applications, platforms and technologies are designed and introduced securely. The role provides independent, risk-based security architecture guidance so that business objectives are achieved while maintaining alignment with client security standards, regulatory obligations, enterprise architecture principles and recognized industry good practices. The role leads security design reviews, identifies architectural risks and control gaps, and defines practical security requirements and compensating controls across on-premises, cloud and hybrid environments.
Key Responsibilities:-
- Serve as the security architecture advisor for new initiatives, major changes, transformation programs and technology procurements within the client environment.
- Review proposed applications, platforms, infrastructure services, cloud services and emerging technologies before implementation or material change.
- Assess end-to-end solution architecture, including security controls, trust boundaries, data flows, interfaces, APIs, integration points, identity and access, network zones, hosting and deployment models.
- Translate client security standards, regulatory obligations and enterprise policies into clear, testable architecture and design requirements.
- Identify security risks, control gaps, design weaknesses, insecure dependencies and single points of compromise, and document their potential business and technical impact.
- Provide practical, proportionate and risk-based recommendations that balance security, usability, delivery timelines, operational supportability and business outcomes.
- Recommend security improvements, design changes or compensating controls where target controls cannot be implemented and define conditions for residual-risk acceptance.
- Lead security architecture reviews and threat-modelling workshops with business, enterprise architecture, application, infrastructure, cloud, data, integration, IAM and cybersecurity stakeholders.
- Define security architecture patterns, guardrails and reference designs covering identity, privileged access, segmentation, encryption, key management, API security, logging, monitoring, backup, resilience and secure administration.
- Evaluate third-party and SaaS solution designs, including data residency, tenant isolation, supplier access, integration security, shared-responsibility boundaries and exit considerations.
- Review security-relevant design artefacts such as solution architecture documents, high- and low-level designs, data-flow diagrams, interface specifications, deployment models and security control matrices.
- Ensure privacy and data-protection requirements are considered by design, including data classification, minimization, retention, encryption, access restrictions and secure data exchange.
- Assess alignment with secure software development and Dev Sec Ops practices, including secrets management, code and dependency security, CI/CD controls, environment segregation and release assurance.
- Define architecture-related security acceptance criteria and support validation before go-live, including review of remediation evidence, exceptions and outstanding residual risks.
- Maintain a traceable record of architecture decisions, risks, recommendations, waivers, compensating controls, owners and closure status.
- Support security governance forums by presenting material risks, design decisions, exceptions and recommended treatment options to relevant stakeholders.
- Contribute to the continuous improvement of client security principles, architecture standards, reusable patterns, review checklists and assurance processes.
- Provide architecture guidance during security incidents, major vulnerabilities or material technology changes where design-level remediation is required.
- Mentor security and technology team members and promote security-by-design, privacy-by-design and zero-trust principles across delivery teams
Certifications:
-
- Strong knowledge of enterprise security architecture, risk management, threat modelling and security-by-design principles.
- Practical experience across cloud, on-premises and hybrid architectures; application, infrastructure, network, data, integration, IAM/PAM and security operations domains.
- Working knowledge of UAE cybersecurity and data-protection obligations relevant to government and healthcare environments, together with applicable client standards and policies.
- Knowledge of recognized…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×