As a Cyber Security Architect, you will define, design, and govern secure architecture standards across the enterprise. You will ensure that technology solutions, IT projects, cloud platforms, and cybersecurity tools align with the organisation's security strategy, regulatory expectations, and risk management frameworks. Acting as a senior security advisor, you will evaluate new solutions, drive integration of security technologies, and provide subject‑matter expertise across core cybersecurity domains.
What You'll Do and How You'll Succeed
Security Architecture & Design
- Develop, maintain, and publish enterprise security architecture standards, patterns, and roadmaps.
- Embed security principles across cloud, on‑prem, application, data, network, and endpoint environments.
- Review project solution designs and provide secure architecture recommendations.
- Translate business and technology needs into secure, scalable, compliant, and cost‑effective designs.
- Support secure‑by‑design adoption across projects and platforms.
Technology Governance & Assurance
- Conduct architectural assessments, design reviews, and security evaluations for new initiatives.
- Validate configuration and integration of enterprise cybersecurity tools against standards.
- Ensure adherence to regulatory and compliance frameworks (ISO 27001, NIST CSF, CIS, GDPR, RBI/SEBI).
- Maintain alignment with enterprise architecture, global cybersecurity strategy, and risk appetite.
Cybersecurity SME – Domain Expertise
- Provide expertise across cloud, endpoint, network, application, and data security domains.
- Architect secure cloud landing zones, policies, identity models, and monitoring solutions.
- Design endpoint security baselines and detection models using EDR/XDR platforms.
- Architect secure network topology, segmentation, and threat prevention using firewalls, proxies, VPN, and IDS/IPS.
- Define secure application architecture, threat modelling, and DevSecOps integration.
- Design enterprise data protection models including encryption, DLP, tokenisation, and key management.
- Lead adoption of Zero Trust principles across cloud, network, and applications.
Stakeholder Engagement & Advisory
- Act as a trusted advisor to IT, Security, Cloud, Infrastructure, Application, and Business teams.
- Conduct architectural walkthroughs and provide guidance to project managers and engineers.
- Support vendor evaluations and conduct security due diligence on third‑party solutions.
Documentation & Communication
- Produce architecture blueprints, HLD/LLD documents, security patterns, and integration diagrams.
- Document design gaps, risks, mitigations, and deliver clear technical recommendations.
- Maintain security reference architectures and reusable templates for enterprise use.
We'd Love to Hear From You If...
Experience
- You have 8+ years of experience in cybersecurity or information security roles.
- You have strong understanding of enterprise security architecture, frameworks, and best practices.
- You have expertise across cloud, network, endpoint, application, data security, and monitoring.
- You have experience with security tools and platforms for data, endpoint protection, and cloud security.
- You have strong secondary‑level education in a technical or analytical discipline (A‑level or equivalent).
- You have a qualification in Cyber Security, IT, Risk Management, or a related field (advantageous).
Technical Expertise
- You have knowledge of risk assessment and secure design principles.
- You have the ability to design secure architectures, review solutions, and provide guidance to technical teams.
- You have exposure to Zero Trust, SASE, DevSecOps, threat modelling, and container security (preferred).
- You have familiarity with automation (Python, PowerShell, Terraform), IaC security, and CI/CD pipelines (preferred).
Ways of Working
- You collaborate effectively with IT, security, and business stakeholders.
- You communicate clearly and document thoroughly.
- You lead with a focus on secure‑by‑design adoption and risk mitigation.
- You balance delivery timelines with compliance and technical excellence.