RQ00773 Security Architect Senior
Job Summary
Security architecture assessments and consultations are required as a prerequisite to the go live in order to comply with OH Policies and standards. Security architecture assessments ensure compliance of product/project architectures with approved security architectures standards and cloud decision records prior to the project go-live date. The Sr. Security Architect will support the project influx and ensure the mandatory security architecture assessment is done in a timely manner that doesnt intervene with the projects go-live dates.
Required Skills:
- 10 or more years of experience in IT security principles practices technologies programs and procedures with a solid knowledge of cloud architecture and security controls.
- Certifications in in any of the following cyber security and cloud security architecture (e.g. CISSP-ISSAP CCSP GDSA)
- Certifications in any of the following are an asset. ArchiMate TOGAF SABSA Zachman
Responsibilities:
- Develop and maintain security reference architectures network diagrams and other guidelines to support the policies and standards enabling the delivery of target state enterprise-level Information Security capabilities and reducing the risk of siloed and redundant solutions.
- Develop security requirements and advise on technologies to be used in cloud environments during an entire project lifecycle.
- Ensure optimal placement and adequacy of the technology to achieve an ideal cloud security architecture with respect to the cloud service model being used.
- Analyze proposed solution architectures technology design and IT development processes to identify potential threats and vulnerabilities and to recommend options that enhance the security of solutions and business processes.
- Acts as a subject matter expert and may take on more complex work in developing plans and deliverables and interacting with key internal partners.
- Manage multiple security related projects simultaneously and present status updates to upper management.
- Leverage existing best practices in addition to proposing developing and integrating best practices as they relate to business policy information security application and technical infrastructure architecture
- Identify and escalate issues and work with projects to ensure application management and quality standards are adhered to
Desired Skills:
- Strong knowledge and understanding of cloud and on-prem system and applications architectures and security controls.
- Deep understanding of security threats vulnerabilities and safeguards relevant to application development test and QA environments and IT (data center) operations.
- Strong knowledge of a wide variety of information systems and security technologies including Operating Systems security LAN and WAN Internet protocols and applications secure communications firewalls IDS/IPS PKI identity and access management identification and authentication techniques role-based access control malware defense etc.
- Strong Knowledge an understanding of information security frameworks such as ISO 27001/2 and NIST.
- Good verbal and written communication skills including preparing and presenting and articulating architecture-related concepts to both technical and non-technical audiences
- Functions at a high level of autonomy in setting objectives based on direction from management
- Ability to build sustainable relationships with stakeholders partner and colleague
Rated Criteria:
- Threat Modeling: - 5-7 years of hands-on experience with threat modeling techniques such as STRIDE PASTA and MITRE ATT&CK including the development of data flow diagrams and identification of attack vectors to inform secure design decisions and guide risk mitigation strategies across systems and applications. 30 Points
- 57 years of extensive experience with cloud and on-prem security controls and architecture with a strong ability to identify gaps between the current security posture and industry standards best practices and regulatory requirements and proposing security architecture enhancements and mitigations. 30 Points
- Team Player: - Demonstrates strong collaboration skills by working effectively with colleagues across functions openly sharing information supporting others to achieve shared goals and contributing to a positive respectful team environment. 20 Points
- Presentation Deck: - Over 5 years of experience authoring technical and executive-level reports and delivering presentations to stakeholders and senior leadership. 20 Points
Deliverables:
- Analyze proposed solution architectures technology design conducting an assessment to identify security architecture gaps and deviations from approved standards/patterns and to identify potential threats and vulnerabilities then recommend options that enhance the security of solutions.
- Development update and contribution to security architecture standards patterns and reference architectures for cloud environments.
- Ensure optimal placement and adequacy of the technology to achieve an ideal cloud security architecture with respect to the cloud service model being used.
Must Haves:
- 10 or more years of experience in IT security principles practices technologies programs and procedures with a solid knowledge of cloud architecture and security controls.
- Certifications in in any of the following cyber security and cloud security architecture (e.g. CISSP-ISSAP CCSP GDSA)
- Certifications in any of the following are an asset. ArchiMate TOGAF SABSA Zachman