Location: On-site – Riyadh, Saudi Arabia
Contract/engagement: Project-based managed cybersecurity services (13-month)
Minimum experience: 8+ years
Role Purpose
Design, review, and govern secure enterprise architectures across applications, infrastructure, networks, integrations, and cloud services.
Key Responsibilities
- Review solution and enterprise architectures to identify security risks, control gaps, and design weaknesses.
- Define security architecture requirements, patterns, reference designs, and technical control recommendations.
- Review application, infrastructure, network, firewall, segmentation, API, third-party integration, and cloud designs.
- Provide guidance on defense in depth, Zero Trust, isolation, least privilege, secure connectivity, and resilient architecture.
- Perform architecture risk assessments and document findings, remediation actions, exceptions, and residual risk.
- Participate in project design reviews, security approval gates, and technical change reviews.
- Contribute to the enterprise cybersecurity architecture roadmap and ensure alignment with Ministry policies, NCA controls, and recognized standards.
- Coordinate with application, infrastructure, network, cloud, IAM, SOC, and GRC teams to embed security throughout solution lifecycles.
Technical and Professional Requirements
- Bachelor’s degree in Computer Science, Information Security, or a related field.
- At least 8 years of enterprise cybersecurity architecture experience.
- Strong expertise across application security, infrastructure security, network security, cloud security, IAM, encryption, and security integration.
- Proven experience in security design reviews, threat/risk assessment, secure architecture patterns, and technical governance.
- Knowledge of Zero Trust, defense in depth, secure SDLC, NCA requirements and leading architecture/security frameworks.
Personal Requirements
- Strategic and systems-oriented thinking with strong attention to technical detail.
- Influential communication and the ability to challenge designs constructively.
- Strong documentation, presentation, and stakeholder-management skills.
- Able to translate risk and regulatory requirements into practical architecture decisions.
Professional Certifications
Preferred: SABSA, TOGAF, CCSP, CISSP, GIAC GCSA, or equivalent security architecture certification.