Location: On-site - Riyadh, Saudi Arabia
Contract/engagement: Project-based managed cybersecurity services (13-month)
Minimum experience: 8+ years
Role Purpose
Design, review, and govern secure enterprise architectures across applications, infrastructure, networks, integrations, and cloud services.
Key Responsibilities
- Review solution and enterprise architectures to identify security risks, control gaps, and design weaknesses
- Define security architecture requirements, patterns, reference designs, and technical control recommendations
- Review application, infrastructure, network, firewall, segmentation, API, third-party integration, and cloud designs
- Provide guidance on defense in depth, Zero Trust, isolation, least privilege, secure connectivity, and resilient architecture
- Perform architecture risk assessments and document findings, remediation actions, exceptions, and residual risk
- Participate in project design reviews, security approval gates, and technical change reviews
- Contribute to the enterprise cybersecurity architecture roadmap and ensure alignment with Ministry policies, NCA controls, and recognized standards
- Coordinate with application, infrastructure, network, cloud, IAM, SOC, and GRC teams to embed security throughout solution lifecycles
Requirements
Technical and Professional Requirements
- Bachelor's degree in Computer Science, Information Security, or a related field
- At least 8 years of enterprise cybersecurity architecture experience
- Strong expertise across application security, infrastructure security, network security, cloud security, IAM, encryption, and security integration
- Proven experience in security design reviews, threat/risk assessment, secure architecture patterns, and technical governance
- Knowledge of Zero Trust, defense in depth, secure SDLC, NCA requirements, and leading architecture/security frameworks
Personal Requirements
- Strategic and systems-oriented thinking with strong attention to technical detail
- Influential communication and the ability to challenge designs constructively
- Strong documentation, presentation, and stakeholder-management skills
- Able to translate risk and regulatory requirements into practical architecture decisions
Professional Certifications
Preferred: SABSA, TOGAF, CCSP, CISSP, GIAC GCSA, or equivalent security architecture certification.