Overview
Lead - Security Architecture in Dubai, United Arab Emirates is a senior Information Technology and Services role focused on enterprise security architecture, cyber security strategy, cloud security, design governance, DevSecOps, application security, and secure digital transformation for Majid Al Futtaim Global Solutions. The role is responsible for defining and maturing the Group's security architecture capability while ensuring security controls align with business objectives, risk appetite, regulatory expectations, and technology transformation goals.
Role Context
The Lead - Security Architecture will provide enterprise-level architectural leadership across major programs, platforms, cloud environments, application delivery, data initiatives, and emerging technologies. This position requires a highly experienced security architecture professional who can establish governance frameworks, approve secure designs, manage architecture exceptions, embed Security by Design, and guide delivery teams with scalable security guardrails, reference architectures, and reusable implementation patterns.
Key Responsibilities
- Lead and mature the security architecture capability across the Group, including architecture standards, principles, reference architectures, secure design patterns, and governance practices.
- Define and maintain enterprise security architecture strategy aligned with business goals, cyber risk appetite, regulatory requirements, and digital transformation priorities.
- Establish and operate security architecture governance, including architecture review boards, design authority forums, decision logs, exception management, and compliance traceability.
- Drive adoption of practical security guardrails that help delivery teams move faster through pre-approved patterns, reusable templates, reference implementations, and secure-by-default designs.
- Own and approve security architecture and design for major technology programs, enterprise platforms, cloud initiatives, data platforms, and transformation projects.
- Manage security architecture exceptions from end to end, including business justification, compensating controls, formal risk acceptance, remediation planning, and time-bound closure.
- Embed Security by Design and DevSecOps practices into product, platform, application, and infrastructure delivery lifecycles.
- Own the end-to-end application security architecture engagement from early concept, discovery, and design through production release and ongoing change.
- Provide architectural leadership for cloud security across AWS, Azure, and GCP environments, including secure landing zones, shared responsibility models, identity controls, network security, and workload protection.
- Review and guide security designs for digital platforms, APIs, applications, data services, identity solutions, infrastructure, and emerging technologies.
- Partner with product, engineering, infrastructure, cloud, risk, compliance, audit, and business stakeholders to ensure secure and practical technology outcomes.
- Support the development of security standards, control requirements, design review checklists, risk documentation, and architecture decision records.
- Advise senior technology and security leadership on architecture risks, control gaps, design trade-offs, and remediation priorities.
- Promote consistent security architecture practices across the enterprise while enabling innovation, agility, and responsible technology adoption.
Ideal Profile
- Bachelor’s or master’s degree in cyber security, computer science, engineering, technology, or a related discipline.
- 12 years of experience in information security, cyber security, technology risk, or related technology security roles.
- Significant hands-on experience in enterprise security architecture, application security architecture, cloud security architecture, or cyber security design governance.
- Experience in regulated, high-risk, or large-scale environments such as financial services, retail at scale, critical infrastructure, or complex enterprise technology ecosystems.
- Strong understanding of security architecture frameworks, cyber risk management, secure design principles, threat modeling, DevSecOps, application security, identity security, cloud security, and infrastructure protection.
- Proven ability to define reference architectures, security patterns, reusable guardrails, architecture standards, and design governance processes.
- Practical experience with AWS, Azure, or GCP security architecture, including secure landing zones, cloud identity, network segmentation, workload protection, monitoring, and shared responsibility models.
- Experience managing architecture exceptions, risk acceptance, compensating controls, remediation tracking, and governance documentation.
- Cloud security certifications across AWS, Azure, or GCP are strongly preferred.
- CISSP, CCSP, CREST Registered Technical Security Architect, or equivalent security certifications are preferred.
- SABSA or TOGAF certification is an advantage.
- Strong stakeholder management skills with the ability to communicate complex security architecture topics to technical teams, senior leaders, risk committees, and business stakeholders.
- Strong leadership capability with the ability to influence architecture decisions, mentor security teams, and raise maturity across enterprise technology delivery.
Skills Set
- Enterprise security architecture
- Cyber security strategy
- Security architecture governance
- Security by Design
- DevSecOps
- Application security architecture
- Cloud security architecture
- AWS security
- Azure security
- GCP security
- Secure landing zones
- Reference architecture
- Security guardrails
- Design authority
- Architecture review board
- Risk acceptance
- Exception management
- Compensating controls
- Threat modeling
- Secure design patterns
- Identity and access security
- Data security
- Infrastructure security
- API security
- Compliance traceability
- Architecture decision records
- CISSP
- CCSP
- CREST Registered Technical Security Architect
- SABSA
- TOGAF
- Stakeholder management
- Technology risk management
Why Join Us
This opportunity is ideal for a senior security architecture leader who wants to shape cyber security design standards for a large regional enterprise in Dubai. The role offers the chance to influence major transformation programs, cloud platforms, secure digital services, application delivery, governance models, and enterprise-wide cyber resilience while working with diverse technology, business, risk, and security stakeholders.
About the Company
Majid Al Futtaim is a leading regional business group known for creating retail, lifestyle, shopping mall, leisure, entertainment, hospitality, technology, and customer-focused experiences across the Middle East, Africa, and Asia. Through Majid Al Futtaim Global Solutions, the company supports enterprise services, digital transformation, operational excellence, and technology enablement across the wider Group, helping deliver secure, scalable, and customer-focused solutions for modern business operations.