Live opening · Posted 1 day ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
The Cybersecurity Technical Architect is the enterprise design authority for cybersecurity, responsible for defining, governing, and evolving the organization's end-to-end security architecture across identities, applications, infrastructure, data, AI systems, and third-party ecosystems.
This role combines deep technical expertise, strategic architectural leadership, and hands-on guidance to ensure security capabilities are scalable, resilient, compliant, and aligned with business priorities and emerging threats, including AI-driven and supply chain risks.
The candidate will have responsibilities across the following functions:
Enterprise Security Architecture Leadership:
Own and continuously evolve the enterprise cybersecurity architecture, aligned with NIST CSF, ISO 27001
Zero Trust Architecture (ZTA).
Secure-by-Design and Cloud-Native security principles.
Translate business strategy, regulatory requirements, and threat models into reusable security architecture patterns and reference designs.
Act as Security Design Authority for: Major enterprise initiatives.
Cloud and data center transformations.
AI and digital platform programs.
Asset Management:
Define and govern the IT and Information Asset Management strategy.
Ensure accurate discovery, classification, and ownership of: Applications and APIs.
Infrastructure (on-prem, cloud, hybrid).
Data assets (including sensitive, regulated data).
AI / ML models and datasets.
Integrate asset inventory with: Risk management.
Vulnerability management.
Incident response and threat modeling.
Identity and Access Management (Zero Trust):
Architect and oversee IAM and access control capabilities, including: Identity lifecycle management.
Privileged Access Management (PAM).
Federation, SSO, MFA, adaptive access controls.
Drive enterprise-wide adoption of Zero Trust Architecture, covering: Users and workforce identities.
Devices and endpoints.
Workloads, services, and APIs.
Ensure access decisions are context-aware, risk-based, and continuously validated.
DevSecOps and Secure Development:
Lead the Secure Software Development Lifecycle (SSDLC) strategy.
Define security guardrails for: CI/CD pipelines.
Infrastructure as Code (IaC).
API and microservices security.
Cloud-native and containerized workloads.
Embed and govern security tooling: SAST, DAST, SCA.
Secrets scanning.
Container and Kubernetes security.
Enable developers through security-by-design patterns, automation, and training.
Endpoint Security
Architect endpoint and workload protection across: Laptops and mobile devices.
Servers and VMs.
Cloud workloads and containers.
Govern enterprise standards for: EDR/XDR.
Device compliance and posture management.
Encryption, OS hardening, and baseline configurations.
Security Testing and Assurance:
Own the security testing and assurance framework, including: Continuous vulnerability scanning.
Penetration testing.
Red team and purple team exercises.
Establish remediation tracking, risk acceptance, and exception management aligned with enterprise risk appetite.
Ensuring findings drive measurable risk reduction, not just compliance.
AI Governance and Security:
Define and enforce AI security and governance controls, including: Secure use of GenAI and ML models.
Data privacy and protection of training data.
Model integrity, prompt security, and abuse detection.
Partner with Legal, Compliance, and Data teams to enable responsible, compliant AI adoption.
Assess AI-driven threats such as model poisoning, data leakage, and adversarial prompts.
Third-Party Risk Management:
Lead cybersecurity architecture for supplier and third-party risk management.
Define security requirements covering: Due diligence and onboarding assessments.
Contractual security and audit clauses.
Continuous monitoring and reassessment.
Proactively mitigate supply-chain and concentration risks.
Security Monitoring and Incident Response:
Provide architectural oversight for security awareness and behavior programs.
Ensure Secure-by-Design principles are embedded via: Developer-focused security training.
Phishing simulations and social-engineering awareness.
Role-based security education across the enterprise.
Requirements:
Enterprise security architecture (on-prem, cloud, hybrid).
Identity and Access Management, Zero Trust.
DevSecOps and application security.
SIEM, SOAR, EDR/XDR, vulnerability management.
API, data, and cloud security.
AI / ML security principles and governance.
Bachelor's degree in computer science or equivalent qualification.
CISSP, CISM, SABSA, CCSP, TOGAF.
Cloud security certifications (AWS, Azure, GCP).
Experience in regulated industries and global security programs.
Proven experience leading cross-functional, enterprise-scale security initiatives.
Ability to influence senior leaders, architects, and engineering teams.
Strong architectural documentation, communication, and decision-making skills.
Experience
12-16 yrs
More openings worth a look
Recently tracked roles with full details and direct application links.