CISO Solution Architect (9936)

Salt Search Ltd.
London, UK
2 days ago
Apply on www.careerboard.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Microsoft Windows Amazon Web Services Microsoft Azure Software as a Service Cloud Computing Cloud Computing Security Cyber Security Data Discovery Data Governance Information Leak Prevention Data Retention Data Security
+15 more
Identity and Access Management Key Management PCI Data Security Standards Cloud Services Zero Trust Network Access Sherwood Applied Business Security Architecture Unstructured Data Enterprise Data Management Enterprise Software Applications Cloud Platform System Data Classification Multi-Cloud HybridCloud Togaf Devsecops

Job description

This is a senior architecture position within a large, complex and highly regulated environment. You will work across business, technology, engineering, risk and security teams to ensure new applications, platforms and cloud solutions are designed securely from the outset., * Lead the design and delivery of end-to-end security architecture across enterprise applications, platforms and cloud environments.

  • Develop high-level security designs and translate business, technology and risk requirements into practical security architecture.
  • Define and maintain security architecture principles, standards, patterns and reusable design guidance.
  • Provide architecture governance and design assurance, challenging proposed solutions and ensuring security requirements are addressed throughout the delivery life cycle.
  • Act as a Subject Matter Expert for Data Protection and Cloud Security, providing technical guidance to architecture, engineering and business teams.
  • Design and govern enterprise data protection and data security controls, including:

  • Data discovery and inventory
  • Data classification and sensitivity labelling
  • Data Loss Prevention (DLP)
  • Data governance
  • Data retention and disposal
  • Data life cycle controls
  • Protection of structured and unstructured information
  • Encryption and access controls

Support the secure design and adoption of Microsoft Azure, alongside AWS, SaaS and hybrid-cloud environments.

Ensure appropriate security controls across applications, infrastructure, identities, networks and data.

Translate cyber risks and regulatory requirements into appropriate security controls and non-functional requirements (NFRs).

Conduct and support security architecture reviews, threat/risk assessments and design validation.

Work closely with Enterprise Architecture, Engineering, Cloud, DevSecOps, Risk, Compliance and CISO teams.

Identify gaps within the existing security landscape and recommend improvements.

Support secure technology adoption and major transformation initiatives.

Requirements

  • Significant experience as a Security Architect, Cyber Security Architect, Security Solution Architect or Enterprise Security Architect.
  • Proven experience delivering end-to-end security architecture within large and complex organisations.
  • Strong knowledge of security architecture governance, including standards, patterns, design reviews and architecture assurance.
  • Strong Data Protection/Data Security Architecture experience.
  • Experience with data classification, discovery, inventory, labelling, governance, retention/disposal and life cycle controls.
  • Understanding of security controls for both structured and unstructured data.
  • Strong Microsoft Azure Security architecture experience.
  • Good knowledge of AWS, SaaS and hybrid/multi-cloud security.
  • Experience securing enterprise applications, infrastructure and cloud platforms.
  • Understanding of IAM, Zero Trust, encryption, key management and access-control principles.
  • Ability to translate risk assessments and regulatory requirements into technical security architecture.
  • Experience working within regulatory frameworks such as GDPR, DORA, PCI-DSS, SOX and/or SWIFT CSP.
  • Excellent communication skills with the ability to engage with senior stakeholders, architects, engineers, risk and compliance teams.

Highly Desirable

  • Experience with Microsoft Purview, particularly Information Protection, data classification, sensitivity labelling, DLP and information governance.
  • Experience defining data-protection architecture across Azure and Microsoft 365 environments.
  • Financial Services, Banking, Payments, Market Infrastructure or other highly regulated/critical infrastructure experience.
  • Experience with security architecture frameworks such as SABSA, TOGAF or similar.
  • Knowledge of DevSecOps and secure SDLC practices.
  • Experience working within Agile delivery environments and across multiple release trains.
  • Relevant certifications such as CISSP, CCSP, SABSA, TOGAF, Azure Security/Architecture, CISM or equivalent.

*Rates depend on experience and client requirements

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerboard.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

Videos

See all

Related articles

See all