Security Architect

The Zero Trust
United States
8 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Artificial Intelligence Microsoft Azure Cloud Computing Cloud Computing Security Cyber Security Information Leak Prevention Hardware Security Module High-Level Architecture Identity and Access Management Machine Learning Network Segmentation Zero Trust Network Access
+6 more
Sherwood Applied Business Security Architecture Microsoft Power Automate Firewalls (Computer Science) Togaf Azure Service Fabric Api Management

Job description

A leading international firm is seeking an experienced Security Architect to own and develop its enterprise security architecture strategy across cloud, on-premises and hybrid environments.

Working within the Strategy and Architecture team, you will act as the firm’s technical authority on cybersecurity. You will define security standards, patterns and roadmaps while ensuring security is Embedded into the design and implementation of new technologies, platforms and services.

The role will work closely with the CTO, CISO, Information Security, Risk and Compliance teams, as well as architects and senior business stakeholders across the firm., * Own the enterprise security architecture strategy, vision and roadmap.

  • Design security solutions across Azure, on-premises, hybrid and network environments.
  • Develop and maintain security architecture standards, principles, patterns and high-level designs.
  • Lead the architectural approach to Zero Trust and SASE.
  • Embed security requirements into new products, platforms and technology projects.
  • Assess technology vendors and recommend appropriate security solutions.
  • Advise on identity and access management, network segmentation, encryption, data residency and cloud security.
  • Contribute to Architecture Review Boards and technical design authorities.
  • Translate ISO 27001, NIST, CIS, GDPR and other regulatory requirements into practical architectural controls.
  • Help define security standards governing the safe adoption of AI and machine-learning technologies.
  • Act as a trusted security adviser to senior technology and business stakeholders.

Requirements

  • Proven experience working as a Security Architect within a law firm or in-house legal environment.
  • Strong experience designing enterprise security solutions across Azure, cloud, on-premises and hybrid environments.
  • Practical knowledge of Zero Trust and SASE architectures.
  • Experience with technologies including ZTNA, CASB, identity and access management, Firewalls, NAC and network segmentation.
  • Strong Azure networking knowledge, including VNETs, VNET peering and VNET gateways.
  • Experience owning security designs from strategy and roadmap through to implementation.
  • Strong understanding of security architecture frameworks, ISO 27001, NIST, GDPR and data-residency requirements.
  • Experience producing architectural documentation, standards, security patterns and non-functional requirements.
  • Confidence presenting architectural recommendations to CTO, CISO and senior stakeholder audiences.

Desirable experience:

  • CISSP certification.
  • TOGAF certification, with CISM or SABSA also advantageous.
  • Experience with Zscaler, Palo Alto Prisma or comparable SASE platforms.
  • Knowledge of AI-security risks such as data leakage, prompt injection, model integrity and supply-chain threats.
  • Understanding of encryption, BYOK and hardware security modules.
  • Experience with Azure PaaS services such as APIM, Azure AI Foundry and Logic Apps.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on computerjobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

4:27 min

Running custom code and managing API security policies

Sander ten Brinke Sander ten Brinke · WWC 2024

10:19 min

Continuous learning strategies and emerging industry trends

Kurt Eder · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

8:46 min

Securing applications with data management browser APIs

Sasha Shynkevich · JS Congress

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all