Job Description : We are looking for an experienced Security Architect or Security Consultant to join our cybersecurity consulting team. The ideal candidate will be responsible for designing secure enterprise architectures, conducting security assessments, developing security strategies, and helping organizations strengthen their cybersecurity posture. You will work closely with business stakeholders, application teams, cloud engineers, infrastructure teams, and security operations to integrate security into digital transformation initiatives while ensuring compliance with industry standards and regulatory requirements.Key Responsibilities : – Design and implement enterprise security architecture for cloud, on-premises, and hybrid environments.- Develop security strategies, standards, policies, and architectural frameworks aligned with business objectives.- Perform security architecture reviews for applications, infrastructure, cloud platforms, and enterprise systems.- Conduct threat modeling, risk assessments, and security gap analyses for new and existing solutions.- Recommend security controls based on industry best practices and organizational risk appetite.- Define secure design principles across applications, APIs, networks, cloud platforms, and data environments.- Collaborate with development teams to embed security throughout the Software Development Lifecycle (SDLC).- Provide security consulting for digital transformation, cloud migration, and modernization initiatives.- Review infrastructure and application designs to identify vulnerabilities and recommend remediation measures.- Evaluate and recommend security technologies for identity management, endpoint protection, network security, data protection, and cloud security.- Develop security reference architectures and implementation roadmaps.- Support security governance initiatives and ensure adherence to enterprise security policies.- Participate in architecture review boards and provide cybersecurity guidance for strategic technology initiatives.- Work closely with Security Operations, Risk, Compliance, Infrastructure, and DevOps teams.- Assist during internal and external audits by providing security architecture documentation and evidence.- Mentor technical teams on secure architecture principles and cybersecurity best practices.- Stay updated on emerging cyber threats, attack techniques, and evolving security technologies.Required Skills : – Strong understanding of enterprise security architecture principles.- Hands-on experience with cloud security across AWS, Microsoft Azure, and Google Cloud Platform (GCP).- Knowledge of Zero Trust Architecture and modern security frameworks.- Experience with Identity and Access Management (IAM), Single Sign-On (SSO), and Multi-Factor Authentication (MFA).- Strong understanding of network security concepts including firewalls, VPNs, IDS/IPS, WAF, DNS security, and secure network segmentation.- Experience securing web applications, APIs, microservices, and distributed systems.- Knowledge of endpoint security, email security, and data protection technologies.- Familiarity with encryption standards, PKI, certificate management, and key management systems.- Experience conducting threat modeling and security risk assessments.- Strong knowledge of vulnerability management and remediation strategies.- Understanding of DevSecOps practices and security automation.- Experience with SIEM, SOAR, EDR/XDR, and security monitoring solutions.- Knowledge of container and Kubernetes security.- Understanding of application security concepts including OWASP Top 10, secure coding, and API security.- Familiarity with enterprise security tools such as Microsoft Defender, Palo Alto, CrowdStrike, Cisco Security, Splunk, Sentinel, or similar platforms.- Strong understanding of enterprise networking and infrastructure security.Compliance & Security Frameworks : – Experience working with one or more of the following : 1. ISO 270012. NIST Cybersecurity Framework3. CIS Controls4. SOC 25. PCI-DSS6. GDPR7. HIPAA8. SOX9. MITRE ATT&CK FrameworkPreferred Qualifications : – Experience working in cybersecurity consulting or enterprise security architecture roles.- Exposure to cloud migration and security transformation projects.- Experience with enterprise-scale security implementations.- Knowledge of Infrastructure as Code (Terraform, ARM, CloudFormation) is an advantage.- Familiarity with scripting languages such as Python, PowerShell, or Bash for security automation.- Experience with Agile delivery methodologies.- Professional security certifications such as CISSP, CCSP, CISM, SABSA, TOGAF, Azure Security Engineer, AWS Security Specialty, or Google Professional Cloud Security Engineer are highly desirable.Soft Skills : – Excellent analytical and problem-solving skills.- Strong communication and stakeholder management abilities.- Ability to present security recommendations to both technical and business audiences.- Strong documentation and reporting skills.- Ability to manage multiple engagements in a consulting environment.- Collaborative approach with cross-functional teams.- Strong decision-making and leadership capabilities. (ref:hirist.tech)
