All Jobs Vacancy

CISO Solution Architect (9936)

Posted 3 days ago by Salt

Key Responsibilities

  • Lead the design and delivery of end-to-end security architecture across enterprise applications, platforms and cloud environments.
  • Develop high-level security designs and translate business, technology and risk requirements into practical security architecture.
  • Define and maintain security architecture principles, standards, patterns and reusable design guidance.
  • Provide architecture governance and design assurance, challenging proposed solutions and ensuring security requirements are addressed throughout the delivery lifecycle.
  • Act as a Subject Matter Expert for Data Protection and Cloud Security, providing technical guidance to architecture, engineering and business teams.
  • Design and govern enterprise data protection and data security controls, including:
  • Data discovery and inventory
  • Data classification and sensitivity labelling
  • Data Loss Prevention (DLP)
  • Data governance
  • Data retention and disposal
  • Data lifecycle controls
  • Protection of structured and unstructured information
  • Encryption and access controls
  • Support the secure design and adoption of Microsoft Azure, alongside AWS, SaaS and hybrid-cloud environments.
  • Ensure appropriate security controls across applications, infrastructure, identities, networks and data.
  • Translate cyber risks and regulatory requirements into appropriate security controls and non-functional requirements (NFRs).
  • Conduct and support security architecture reviews, threat/risk assessments and design validation.
  • Work closely with Enterprise Architecture, Engineering, Cloud, DevSecOps, Risk, Compliance and CISO teams.
  • Identify gaps within the existing security landscape and recommend improvements.
  • Support secure technology adoption and major transformation initiatives.

Essential Experience

  • We are looking for candidates with strong experience across both Security Architecture and Data/Cloud Security.
  • You should have:
  • Significant experience as a Security Architect, Cyber Security Architect, Security Solution Architect or Enterprise Security Architect.
  • Proven experience delivering end-to-end security architecture within large and complex organisations.
  • Strong knowledge of security architecture governance, including standards, patterns, design reviews and architecture assurance.
  • Strong Data Protection / Data Security Architecture experience.
  • Experience with data classification, discovery, inventory, labelling, governance, retention/disposal and lifecycle controls.
  • Understanding of security controls for both structured and unstructured data.
  • Strong Microsoft Azure Security architecture experience.
  • Good knowledge of AWS, SaaS and hybrid/multi-cloud security.
  • Experience securing enterprise applications, infrastructure and cloud platforms.
  • Understanding of IAM, Zero Trust, encryption, key management and access-control principles.
  • Ability to translate risk assessments and regulatory requirements into technical security architecture.
  • Experience working within regulatory frameworks such as GDPR, DORA, PCI-DSS, SOX and/or SWIFT CSP.
  • Excellent communication skills with the ability to engage with senior stakeholders, architects, engineers, risk and compliance teams.

Highly Desirable

  • Experience with Microsoft Purview, particularly Information Protection, data classification, sensitivity labelling, DLP and information governance.
  • Experience defining data-protection architecture across Azure and Microsoft 365 environments.
  • Financial Services, Banking, Payments, Market Infrastructure or other highly regulated/critical infrastructure experience.
  • Experience with security architecture frameworks such as SABSA, TOGAF or similar.
  • Knowledge of DevSecOps and secure SDLC practices.
  • Experience working within Agile delivery environments and across multiple release trains.
  • Relevant certifications such as CISSP, CCSP, SABSA, TOGAF, Azure Security/Architecture, CISM or equivalent.
Rate:
Not specified
Location:
London
IR35 Status:
Inside
Remote Status:
Hybrid
Industry:
Cybersecurity
Seniority Level:
Senior

Take-Home Pay

Not Available

Visit calculators for additional details

Create a free account to view the take-home pay for this contract

Share job