Information Security Architect
Melbourne, Victoria, Australia · Full Time
Be the first to apply
- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 2 weeks ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Role
Join HESTA's expanding Information Security team and contribute significantly to advancing security architecture capabilities. You will spearhead embedding Secure-by-Design and Zero Trust principles throughout our organization, guiding technology, digital, data, and cloud projects to design secure solutions. This role supports safe integration of emerging tech such as AI/ML, cloud platforms, SaaS, and contemporary development methodologies.
Key Responsibilities
- Develop and refine the Enterprise Security Architecture Framework based on NIST, ISO 27001, APRA CPS 234, and related Australian standards.
- Establish security standards, reference architectures, baseline controls, and reusable components covering applications, data, and infrastructure.
- Offer expert security architecture advice and critically assess solution designs for major technology and digital initiatives.
- Perform architecture evaluations and threat modeling to identify risks and advise practical controls and mitigations.
- Provide specialist knowledge in cloud platforms like AWS, Azure, and GCP, including IAM, encryption, network security, logging, and cloud posture management.
- Integrate security practices into the SDLC, DevOps, CI/CD, and cloud deployments through tangible guardrails and review mechanisms.
- Enable secure adoption of AI/ML, SaaS, containers, and serverless technologies, focusing on relevant AI security controls.
- Collaborate with Technology, Enterprise Architecture, Risk, Compliance, Digital, and business teams to enhance security capabilities and culture.
Candidate Profile
- Proven experience in security architecture within complex, cloud-first settings.
- Expertise in embedding Secure-by-Design, Zero Trust, and security controls into technology delivery processes.
- Strong cloud security architecture knowledge, preferably with AWS, Azure, and/or GCP.
- Experience conducting threat modeling, architecture reviews, security assessments, and assurance activities.
- Understanding of securing AI/ML and novel technologies, including AI guardrails and model protection.
- Deep knowledge of NIST CSF, ISO 27001, CIS standards, APRA CPS 234/CPS 230, and Australian privacy laws.
- Experience in financial services, superannuation, or other regulated sectors is highly valued.
- Relevant qualifications in cybersecurity, IT, or Computer Science; industry certifications considered advantageous.
Additional Information
This role offers a chance to influence architecture, strengthen team capabilities, and impact a highly regulated industry. It is ideal for professionals passionate about complex problem-solving and future-proofing security implementation.
Employee Benefits
- Generous leave entitlements, including an extra 6 days year-end leave, up to 6 days paid volunteer leave, 20 weeks gender-neutral paid parental leave, Gender Affirmation leave, reproductive health and wellbeing leave, Cultural and Ceremonial leave, early access to long service leave after 3 years, options for half-pay annual leave, and purchasing additional leave.
- Professional development support encompassing up to $5,000 annually and 8 days paid development leave, access to scholarships, and premium learning resources.
- Health and wellbeing initiatives such as complimentary flu vaccinations, skin checks, engaging social events, and 24/7 Employee Assistance Program.
- Financial wellbeing benefits including up to 15% superannuation contributions, financial planning assistance, year-end payments for Enterprise Agreement employees, an incentivised Employee Referral Program, and novated leasing options.
Diversity, Inclusion & Accessibility
HESTA values and celebrates diversity across all backgrounds, genders, cultures, and abilities, with special encouragement for First Nations peoples, persons with disabilities, neurodiverse individuals, LGBTQI+ community members, and individuals of all ages. The organization is recognised as an Employer of Choice for Gender Equity. Reasonable adjustments throughout the application and recruitment process are supported upon request.
Note: Recruitment agencies will not be considered for this vacancy.