Role Overview
The Security Architect is responsible for designing, evaluating, and strengthening the security posture of the organization''s applications, infrastructure, cloud environments, and data ecosystems. This role partners with engineering, infrastructure, and business teams to embed security into solutions from inception through deployment, ensuring that systems are resilient, compliant, and aligned with industry best practices.
Key Responsibilities
Security Architecture Reviews
Conduct end-to-end security architecture reviews for applications, SaaS platforms, and infrastructure projects. Evaluate proposed designs against established security standards, identify gaps and risks, and recommend practical mitigations. Partner with project teams early in the design lifecycle to ensure secure-by-design principles are applied.
Data Risk and Protection
Perform data risk assessments by analyzing how data flows across systems, where it is stored, and how it is accessed. Evaluate controls protecting sensitive data and recommend improvements to encryption, masking, access governance, and monitoring. Provide architectural guidance on data security tooling such as Databricks security configurations and Varonis for data classification, access auditing, and insider threat monitoring.
Cloud Security Assessments
Lead security assessments of cloud environments and workloads, evaluating configurations, network segmentation, identity boundaries, logging, and workload protections. Recommend hardening measures aligned with cloud provider best practices and the organization''s cloud security framework.
Application and API Security
Provide architectural oversight for application security activities including penetration testing, SAST, and DAST. Review findings, recommend remediation strategies, and validate that secure development practices are followed. Assess API security designs including authentication, authorization, rate limiting, and the proper handling of API keys, secrets, and tokens through approved secrets management solutions.
Identity, Access, and Endpoint Security
Apply IAM and PAM principles to architectural decisions, ensuring least privilege, separation of duties, and strong authentication patterns. Champion phishing-resistant MFA approaches (such as FIDO2 / hardware-backed authenticators) across critical systems. Provide guidance on MDM and MAM strategies to ensure mobile and endpoint devices accessing corporate resources meet security requirements.
Network Security and Vulnerability Management
Evaluate network architectures, segmentation strategies, and perimeter and zero-trust controls. Collaborate with infrastructure and operations teams on vulnerability remediation, helping prioritize risks and recommending architectural changes that reduce exposure.
Advisory and Governance
Serve as a trusted advisor across the organization on security architecture matters. Document architectural decisions, maintain reference architectures and security patterns, and contribute to security standards and policies.
Required Skills and Experience
Technical Expertise
• Demonstrated experience performing security architecture reviews across applications, SaaS solutions, and infrastructure
• Strong background in data security, including data flow analysis, data risk assessments, and tooling such as Databricks and Varonis
• Hands-on knowledge of cloud security assessments and cloud-native security controls
• Solid understanding of API security patterns and management of keys, secrets, and tokens
• Working knowledge of IAM and PAM concepts, including authentication, authorization, privilege management, and identity governance
• Familiarity with phishing-resistant MFA technologies and modern authentication standards
• Knowledge of MDM and MAM platforms and mobile/endpoint security strategies
• Understanding of networking fundamentals (TCP/IP, segmentation, firewalls, proxies, DNS) and vulnerability remediation practices
• Application security experience, including familiarity with penetration testing, SAST, and DAST tools and processes
• Experience with Cyber Resilience capabilities and Disaster Recovery technologies.
Professional Skills
• Ability to translate complex security concepts into clear, actionable recommendations for technical and non-technical audiences
• Strong analytical and risk-based thinking, with the ability to balance security with business needs
• Excellent written and verbal communication skills, with experience producing architecture documents, assessment reports, and design diagrams
• Collaborative approach, comfortable engaging with developers, infrastructure engineers, cloud teams, and business stakeholders
• Self-directed and able to manage multiple reviews and assessments concurrently
Preferred Qualifications
• Industry certifications such as CISSP, CCSP, SABSA, AWS/Azure/Google Cloud Platform security certifications, or equivalent
• Experience aligning security architecture work to frameworks such as NIST CSF, ISO 27001, CIS, or zero-trust reference models
• Prior experience in regulated environments (e.g., HIPAA, PCI, SOX, GDPR)