HM Note: This hybrid contract role is three (3) days in office. Candidates resume must include first and last name.
Description:
As a Senior Security Architect in our security architecture practice you will co-develop digital enterprise solutions alongside application platform product and operations teamsembedding cyber security by design principles from the outset. Youll lead client-facing consultative engagements perform end-to-end security assessments architecture and create repeatable architecture patterns and guidelines that ensure compliance with internal standards and industry best practices. and nbsp;
Key Responsibilities and nbsp;
- Partner with business product and engineering stakeholders to define security requirements and translate them into architecture designs. and nbsp;
- Conduct threat modeling risk assessments and security analyses at inception design and implementation phases. and nbsp;
- Develop and maintain reusable secure-by-design patterns for cloud (IaaS/PaaS) SaaS and hybrid deployments. and nbsp;
- Architect identity and access solutions: SSO MFA PKI least-privilege controls and federated identity. and nbsp;
- Design network and infrastructure controls: network segmentation firewalls security groups SASE micro-segmentation. and nbsp;
- Specify data-protection mechanisms: encryption key management transparent data encryption tokenization and database activity monitoring. and nbsp;
- Integrate security telemetrylogs events and alertsinto SIEM (Splunk Cloud Azure Sentinel) and SOAR workflows. and nbsp;
- Embed security requirements into DevSecOps pipelines using IaC tools and CI/CD integrations. and nbsp;
- Facilitate architecture review boards governance gates and security design workshops. and nbsp;
- Mentor and guide junior architects and engineers on secure architecture principles and patterns. and nbsp;
General Skills and nbsp;
- Demonstrated leadership in technical security architecture and solution delivery and nbsp;
- Deep expertise with at least two major public cloud platforms (AWS Azure GCP) and SaaS ecosystems and nbsp;
- Strong knowledge of application architecture networking and security operations and nbsp;
- Proficiency in structured design methodologies and ITIL processes and nbsp;
- Excellent verbal and written communication; skilled at presenting to technical and executive audiences and nbsp;
- Collaborative team player with strong interpersonal negotiation and stakeholder-management skills and nbsp;
- Solid analytical problem-solving and decision-making abilities and nbsp;
- Awareness of emerging security technologies trends and compliance requirements and nbsp;
Skills
Experience and amp; Skill Set Requirements and nbsp;
1. Core Security Technology Domains (45%) and nbsp;
- Identity and amp; Access Management: SSO MFA PKI OAuth/OIDC SAML RBAC/ABAC and nbsp;
- Infrastructure Security: IaaS/PaaS hardening VPC/VNet/VCN and subnet segmentation firewalls Network Security Groups SASE and nbsp;
- Data Protection: KMS/Vault Transparent Data Encryption tokenization Data Loss Prevention Database Activity Monitoring and nbsp;
- Application Security: Secure SDLC threat modeling (STRIDE DREAD) container and serverless security API gateway WAF and nbsp;
- Security Operations Tools: SIEM (Splunk Cloud Azure Sentinel) ingestion correlation searches dashboards; SOAR automation; EDR (Defender Cortex XDR) and nbsp;
2. Agile Project Delivery (15%) and nbsp;
- Hands-on experience with Agile/Scrum: backlog management user-story creation sprint planning stand-ups retrospectives and nbsp;
- Embed security requirements and automated tests into CI/CD pipelines and nbsp;
- Facilitate cross-functional workshops to align SecOps DevOps and product teams and nbsp;
3. Architecture and amp; Design Expertise (35%) and nbsp;
- Apply frameworks (TOGAF NIST CSF CIS Controls) to digital solution blueprints and nbsp;
- Lead requirements gathering conceptual logical and detailed design phases and nbsp;
- Develop solution design artifacts: architecture diagrams data-flow models sequence diagrams policy matrices and nbsp;
- Provide implementation guidance: infrastructure-as-code templates configuration guidance logging-agent deployments and nbsp;
- Chair architecture review boards capture decisions and enforce governance processes and nbsp;
4. Public Sector and amp; Regulatory Awareness (5%) and nbsp;
- Prior public-sector or regulated-industry experience is an asset and nbsp;
- Familiar with mandates and standards (FIPPA PHIPA PCI DSS AODA ISO 27001) and nbsp;
- Embed audit trails data-retention policies and compliance controls into design deliverables and nbsp;
Must-haves:
- General Well-Rounded Senior Security Architect who has experience with cloud-based solutions Enterprise solutions Information cloud app and data security.
- Conduct threat modeling risk assessments and security analyses at the inception design and implementation phases. and nbsp;
- Client Relationship Building skills.