HM Note: This hybrid contract role is three (3) days in office. Candidates resume must include first and last name.
Description
Key Responsibilities and nbsp;
- Lead end-to-end security design and architecture reviews for common cloud platforms (AWS Azure GCP) and major SaaS applications and nbsp;
- Develop and maintain secure-by-design reference architectures patterns and guidelines tailored to IaaS PaaS and SaaS deployments and nbsp;
- Perform threat modeling risk assessments and gap analyses to align solutions with internal security standards and regulatory requirements and nbsp;
- Define identity and access control strategies including SSO MFA PKI and least-privilege models and nbsp;
- Design various network and infrastructure security controls: e.g. network segmentation security groups firewalls SASE IPS/IDS and nbsp;
- Architect data protection solutions: encryption key management Transparent Data Encryption tokenization DLP for cloud and SaaS data and nbsp;
- Integrate application and infrastructure logs into SIEM platforms (Splunk Cloud Azure Sentinel) and design SOAR playbooks for automated response and nbsp;
- Collaborate with DevOps and engineering teams to embed security requirements in CI/CD pipelines leveraging IaC tools and nbsp; and nbsp;
- Facilitate design workshops governance gates and architecture review boards; document decisions and action items and nbsp;
- Mentor junior architects and security engineers sharing best practices and driving continuous improvement and nbsp;
General Skills and nbsp;
- Proven leadership in technical security architecture for enterprise environments and nbsp;
- Deep expertise across cloud service providers (AWS Azure GCP) and SaaS ecosystems and nbsp;
- Strong grounding in application architecture networking and security operations and nbsp;
- Proficiency in structured design methodologies and ITIL service-management practices and nbsp;
- Ability to translate complex business requirements into actionable security solutions and nbsp;
- Experience creating conceptual logical and physical process/data models and nbsp;
- Track record of developing recommending and governing security architecture and nbsp;
- Awareness of emerging technologies industry trends and security best practices and nbsp;
- Excellent analytical problem-solving decision-making and interpersonal skills and nbsp;
- Clear verbal and written communication; skilled at presenting to technical and executive audiences and nbsp;
- Collaborative team player with a consistent record of meeting deadlines and nbsp;
Skills
Experience and Skill Set Requirements
Core Security Technology Domains (45%) and nbsp;
- Identity and amp; Access Management: and nbsp;SSO MFA PKI identity federation (OAuth/OIDC SAML) and nbsp;
- Infrastructure and amp; Network Security: and nbsp;VCN/VNet/subnet design firewalls security groups micro-segmentation SASE patterns and nbsp;
- Data Protection: and nbsp;KMS/Vault key management TDE tokenization DLP data classification and discovery and nbsp;
- Application Security: and nbsp;Secure SDLC container and serverless hardening API gateway policies WAF integration and nbsp;
- Security Operations and amp; Visibility: and nbsp;SIEM ingestion pipelines correlation searches dashboards SOAR automation EDR tools and nbsp;
Agile Project Delivery (15%) and nbsp;
- Hands-on experience in Agile/Scrum environments: backlog management user-story creation sprint planning retrospectives and nbsp;
- Embed security requirements and automated testing into CI/CD pipelines and nbsp;
- Facilitate cross-functional workshops (threat modeling design sprints) to align SecOps DevOps and architecture teams and nbsp;
Architecture and amp; Design Expertise (35%) and nbsp;
- Apply frameworks (TOGAF NIST CSF CIS Controls) to cloud and SaaS solutions and nbsp;
- Lead requirements gathering conceptual logical and detailed design phases and nbsp;
- Provide engineering implementation support: IaC (Terraform CloudFormation) configuration templates logging-agent deployments and nbsp;
- Guide peers through design reviews governance gates and operational handovers and nbsp;
Public Sector and amp; Regulatory Awareness (5%) and nbsp;
- Previous public-sector or regulated-industry experience is a plus and nbsp;
- Familiarity with mandates and standards (FIPPA PHIPA PCI DSS AODA ISO 27001) and nbsp;
- Embed audit trails retention policies and compliance checks into design artifacts and nbsp;
Must-haves:
- Security arch and design with Cloud Platforms -(AWS Azure)
- Client Relationship Building skills.