We are looking for an experienced Security Architect to define, review, and govern enterprise security architecture across business applications, infrastructure, cloud platforms, and technology initiatives. The role focuses on embedding security into solution design, performing architecture assessments, defining security standards, and ensuring security controls align with business objectives, risk requirements, and industry best practices.
The successful candidate will provide security architecture guidance across hybrid and multi-cloud environments and work closely with technology teams, business stakeholders, and leadership teams.
Key Responsibilities Define and maintain enterprise security architecture frameworks, standards, reference architectures, and security design principles using TOGAF/SABSA methodologies. Review and approve security designs, HLDs, LLDs, solution architectures, technical proposals, and architecture documentation. Ensure security-by-design and security-by-default principles are applied across new technology initiatives. Conduct security architecture reviews, threat modelling, risk assessments, and design evaluations for enterprise solutions. Assess and improve existing platforms, applications, infrastructure, and security controls based on security standards and best practices. Design and review security architectures across IAM, network security, cloud security, endpoint security, email security, and SIEM/SOAR platforms. Evaluate Microsoft Azure, hybrid cloud, multi-cloud, and VMware environments to ensure secure architecture implementation. Identify security gaps, provide remediation recommendations, and support security improvement initiatives. Support internal and external audits by ensuring security architecture documentation, controls, and evidence are maintained. Provide technical guidance to architects, engineering teams, and business stakeholders on secure technology decisions.
Required Skills & Experience10–12 years of experience in cybersecurity architecture, enterprise security design, or security consulting. TOGAF and/or SABSA certification. Strong understanding of enterprise security architecture principles, Zero Trust, and security-by-design approaches. Experience designing and reviewing security solutions across:IAM platforms including Sail Point, IBM IAM, Imprivata, SSO, MFA, PAM, and access governance. Network security platforms including Fortinet, Palo Alto Networks, Cisco ASA, VPN technologies, and network segmentation. Cloud security platforms including Microsoft Defender for Cloud, Microsoft Sentinel, Microsoft Intune, Microsoft Purview, and Defender XDR. Endpoint and email security solutions including Microsoft Defender for Endpoint, Proofpoint, Trend Micro, and Microsoft Exchange Online Protection. Experience preparing HLDs, LLDs, security architecture diagrams, technical designs, and security recommendations. Strong knowledge of threat modelling, risk assessment methodologies, security controls, and architecture governance. Experience evaluating security solutions across hybrid and multi-cloud environments.
Preferred Skills CISSP, CCSP, or Azure Security certification. Experience with VMware security architecture. Knowledge of security frameworks including ISO 27001, NIST, SOC 2, and PCI-DSS. Experience with SIEM/SOAR integration and security operations processes. Exposure to Dev Sec Ops practices and secure software development lifecycle. Strong communication, documentation, presentation, and stakeholder management skills.
نحن نبحث عن مهندس أمن سيبراني ذو خبرة لتحديد ومراجعة وحوكمة بنية الأمن المؤسسي عبر تطبيقات الأعمال، والبنية التحتية، ومنصات السحابة، والمبادرات التقنية. يركز هذا الدور على دمج الأمن في تصميم الحلول، وإجراء تقييمات البنية التحتية، وتحديد معايير الأمن، وضمان توافق ضوابط الأمن مع أهداف العمل ومتطلبات المخاطر وأفضل الممارسات في القطاع.
سيقدم المرشح الناجح توجيهات حول بنية الأمن عبر بيئات السحابة الهجينة والمتعددة، وسيعمل عن كثب مع فرق التكنولوجيا وأصحاب المصلحة في الأعمال والفرق القيادية.
المسؤوليات الرئيسية: تحديد وصيانة أطر عمل بنية الأمن المؤسسي، والمعايير، وبنيات المرجع، ومبادئ تصميم الأمن باستخدام منهجيات TOGAF/SABSA. مراجعة واعتماد تصميمات الأمن، والتصميمات عالية المستوى (HLDs)، والتصميمات منخفضة المستوى (LLDs)، وهندسة الحلول، والمقترحات الفنية، ووثائق البنية التحتية. ضمان تطبيق مبادئ "الأمن بالتصميم" و"الأمن الافتراضي" عبر المبادرات التقنية الجديدة. إجراء مراجعات لبنية الأمن، ونمذجة التهديدات، وتقييمات المخاطر، وتقييمات التصميم لحلول المؤسسة. تقييم وتحسين المنصات والتطبيقات والبنية التحتية وضوابط الأمن الحالية بناءً على معايير الأمن وأفضل الممارسات. تصميم ومراجعة بنى الأمن عبر منصات إدارة الهوية والوصول (IAM)، وأمن الشبكات، وأمن السحابة، وأمن نقاط النهاية، وأمن البريد الإلكتروني، ومنصات SIEM/SOAR. تقييم بيئات Microsoft Azure، والسحابة الهجينة، والسحابة المتعددة، وبيئات VMware لضمان تنفيذ بنية آمنة. تحديد الثغرات الأمنية، وتقديم توصيات المعالجة، ودعم مبادرات تحسين الأمن. دعم عمليات التدقيق الداخلية والخارجية من خلال ضمان الحفاظ على وثائق بنية الأمن والضوابط والأدلة. تقديم التوجيه الفني للمهندسين وفرق العمل وأصحاب المصلحة في الأعمال بشأن قرارات التكنولوجيا الآمنة.
المهارات والخبرات المطلوبة: خبرة تتراوح بين 10-12 سنة في بنية الأمن السيبراني، أو تصميم أمن المؤسسات، أو استشارات الأمن. شهادة TOGAF و/أو SABSA. فهم قوي لمبادئ بنية الأمن المؤسسي، ونهج "الثقة الصفرية" (Zero Trust)، وأساليب "الأمن بالتصميم". خبرة في تصميم ومراجعة حلول الأمن عبر: منصات IAM بما في ذلك Sail Point، وIBM IAM، وImprivata، وSSO، وMFA، وPAM، وحوكمة الوصول. منصات أمن الشبكات بما في ذلك Fortinet، وPalo Alto Networks، وCisco ASA، وتقنيات VPN، وتجزئة الشبكات. منصات أمن السحابة بما في ذلك Microsoft Defender for Cloud، وMicrosoft Sentinel، وMicrosoft Intune، وMicrosoft Purview، وDefender XDR. حلول أمن نقاط النهاية والبريد الإلكتروني بما في ذلك Microsoft Defender for Endpoint، وProofpoint، وTrend Micro، وMicrosoft Exchange Online Protection. خبرة في إعداد HLDs، وLLDs، ورسوم بنية الأمن، والتصميمات الفنية، وتوصيات الأمن. معرفة قوية بنمذجة التهديدات، ومنهجيات تقييم المخاطر، وضوابط الأمن، وحوكمة البنية التحتية. خبرة في تقييم حلول الأمن عبر بيئات السحابة الهجينة والمتعددة.
المهارات المفضلة: شهادة CISSP، أو CCSP، أو Azure Security. خبرة في بنية أمن VMware. معرفة بأطر عمل الأمن بما في ذلك ISO 27001، وNIST، وSOC 2، وPCI-DSS. خبرة في تكامل SIEM/SOAR وعمليات الأمن التشغيلية. التعرض لممارسات DevSecOps ودورة حياة تطوير البرمجيات الآمنة. مهارات قوية في التواصل، والتوثيق، والعروض التقديمية، وإدارة أصحاب المصلحة.