Roles and Responsibilities:
- Lead and deliver enterprise-wide architecture and security configuration assessments for IT and cloud environments.
- Evaluate the security posture of clients infrastructure, platforms, and applications against industry standards (e.g., NIST, CIS, ISO 27001, CSA CCM).
- Provide actionable recommendations to improve architectural design, system configurations, and recommend hardening best practices to reduce risk exposure.
- Develop secure architecture blueprints and hardening guidelines tailored to client needs, technology stack, and regulatory requirements.
- Guide clients through security architecture initiatives, including secure cloud adoption, network segmentation, and security controls improvements.
- Conduct design reviews for new or evolving systems to ensure security-by-design principles are integrated early.
- Lead architecture risk analysis, threat modeling, and security control validation activities.
- Mentor and coach consultants on assessment methodologies and best practices.
- Conduct end-to-end assessments to identify misconfigurations across IT & Cloud infrastructures, systems, networks, applications, and security controls.
- Develop and enhance internal frameworks, tools, and templates for consistent, high-quality delivery.
Minimum Requirements:
- Bachelor's or master's degree in information security, Computer Engineering, Cybersecurity, or a related discipline.
- 7+ years of experience in cybersecurity, with at least 5 years in architecture, infrastructure security, or cloud security.
- Professional certifications such as GDSA, CISSP, CISM, CCSP, SABSA.
- Strong understanding of secure architecture frameworks (e.g., SABSA, TOGAF Security Architecture), secure cloud reference architectures, and zero trust principles.
- Hands-on experience assessing and securing systems across hybrid environments (on-prem, public cloud, multi-cloud).
- Deep familiarity with OS, network, application, and database hardening best practices.
- Experience in aligning infrastructure and application security with industry best practices and benchmarks (e.g., CIS, NIST, NCA CCC)
- Ability to produce detailed technical analysis reports as well as executive-level summaries.
- Strong project leadership skills, including scoping, planning, client engagement, and quality assurance.
- Commitment to continuous learning, certifications, and staying current with evolving cybersecurity threats and technologies.
- Must be a Saudi National.