Get more replies from employers
Send a job-specific resume in minutes.
ORIX METRO Leasing and Finance Corporation is seeking a Cybersecurity Architect to design and govern the organization’s security architecture across on‑premises, cloud, network, identity, and applications. You will provide technical leadership to the MSOC, validate detections, and ensure controls align with ISO 27001:2022, NIST, and BSP frameworks.
You will drive security engineering and governance, map risks to standards, lead incident investigations, and mentor ISD staff while coordinating
The Cybersecurity Architect is responsible for designing and governing the organization's security architecture across infrastructure, applications, cloud platforms, and identity environments.
The role provides technical leadership to the Managed Security Operations Center (MSOC), validates monitoring outputs, oversees remediation with ITG, and ensures that security controls are effectively implemented and aligned with ISO 27001:2022, NIST, and BSP regulatory frameworks.
The Architect serves as the technical arm of the Information Security Office, driving security engineering, technical governance, and architectural maturity across the enterprise.
Expertise in designing, validating, and governing enterprise security architecture across on-premises, cloud, network, identity, and application domains.
Strong knowledge of Azure, AWS, and Google Cloud security controls, baselines, and architecture best practices.
Network & Infrastructure Security – Deep understanding of network protocols (TCP/IP, DNS, HTTP/S), firewalls, WAF, VPN/SD-WAN, network segmentation, and Zero-Trust design.
Proficiency in Windows, Linux, Microsoft Defender, Intune, Entra ID, Conditional Access, MFA, PIM/JIT, and endpoint hardening.
Familiarity with SIEM, EDR, SOAR, IDS/IPS, MITRE ATT&CK, Cyber Kill Chain, and detection engineering.
Experience leading technical investigations, RCA, containment, recovery, and forensic evidence handling.
Knowledge of VMDR tools, CIS Benchmarks, misconfiguration analysis, and patch governance.
Ability to map technical risks to ISO 27001, NIST 800-53/CSF, and BSP requirements.
Knowledgeable in ISO/IEC 27001:2022, NIST 800-53, NIST CSF 2.0, BSP Circular 808, BSP Circular 982, and MORNBFI.
Security Documentation & Reporting – Ability to develop diagrams, standards, runbooks, and audit-ready evidence.
Design, document, and maintain the enterprise security architecture across network, cloud, identity, endpoint, and application domains.
Establish security baselines, hardening guides, and secure configuration standards for servers, endpoints, and cloud services.
Provide technical oversight to MSOC, validate detections, and ensure high-quality investigations.
Coordinate with ITG for remediation of MSOC findings, vulnerabilities, and configuration gaps.
Develop and enhance incident response playbooks, forensic procedures, and escalation workflows.
Lead technical root cause analysis for major incidents and recurring vulnerabilities.
Conduct architecture and technical risk assessments for systems, applications, and infrastructure changes.
Perform reviews of cloud configurations, identity governance, network segmentation, endpoint protection, and application controls.
Review technical controls in IT and business projects for compliance with Information Security Standards and ISD-approved MBSS.
Oversee vulnerability management for governance, validate findings, and prioritize remediation.
Maintain security documentation including diagrams, standards, runbooks, and audit evidence.
Provide technical expertise during internal/external audits and regulatory reviews.
Monitor emerging threats and recommend improvements to the organization's security posture.
Mentor ISD personnel and provide technical guidance across the department.
Collaborate with ITG and business units to ensure the secure design, implementation, and operation of systems.Perform other duties that maybe assigned by the Head of Information Security Department
Graduate of BS Information Technology, Computer Science or any 4-years business course or equivalent.
At least 5 to 7 years related work experience
Knowledgeable in Networking protocols as such as TCP/IP, DNS, https, and network devices (routers, switches, firewalls)