CPX

Lead Security Architect

CPX

Abu Dhabi Emirate, United Arab Emirates · Full Time

Be the first to apply

Experience
10+ yrs
Salary
—
Openings
1
Posted
1 week ago
Work mode
In office
Education
Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering or related field
Resume
Required to apply

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

Role Overview

The Lead Security Architect serves as a trusted security consultant within the client organization, ensuring that all new projects, applications, platforms, and technologies are securely developed and deployed. This role provides independent and risk-focused security architecture guidance that balances achieving business goals with compliance to security standards, regulatory requirements, enterprise architecture frameworks, and widely accepted industry best practices. The Lead Security Architect spearheads security design assessments, pinpoints architectural vulnerabilities and control deficiencies, and formulates effective security requirements and compensating controls for environments spanning on-premises, cloud, and hybrid models.

Key Responsibilities

  • Act as the primary security architecture advisor for new projects, significant system changes, transformation programs, and technology procurements within the client ecosystem.
  • Conduct thorough evaluations of proposed applications, infrastructure, cloud services, platforms, and emerging technologies prior to deployment or significant modifications.
  • Examine end-to-end solution architectures including controls, trust boundaries, data flow, APIs, integration points, identity and access management, network segmentation, hosting, and deployment configurations.
  • Interpret client security frameworks, regulatory mandates, and enterprise policies into explicit, verifiable architectural and design directives.
  • Detect architectural security risks, control weaknesses, faulty designs, dependencies prone to compromise, and document potential business and technical impacts.
  • Offer practical and balanced recommendations that weigh security needs against usability, delivery schedules, operational support, and business goals.
  • Advocate for security design amendments or compensatory controls when ideal security measures are unattainable, defining residual risk acceptance conditions.
  • Lead security architecture reviews and threat modeling sessions with cross-disciplinary teams including business units, enterprise architects, application, infrastructure, cloud, data, integration, IAM, and cybersecurity personnel.
  • Create and maintain security architecture patterns, guardrails, and reference models addressing identity management, privileged access, segmentation, encryption, key management, API security, logging, monitoring, backup, resiliency, and secure system administration.
  • Evaluate third-party and SaaS solutions focusing on data residency, tenant isolation, supplier access, integration security, shared responsibility, and off-boarding considerations.
  • Review detailed security-related design documentation such as solution architecture blueprints, data-flow diagrams, interface definitions, deployment strategies, and security control matrices.
  • Ensure privacy and data protection considerations are integrated from the design phase, including data classification, minimization, retention policies, encryption, access controls, and secure data transfers.
  • Assess compliance with secure software development and DevSecOps best practices encompassing secrets management, code and dependency security, CI/CD controls, environment segregation, and release assurance.
  • Define security acceptance criteria for architecture and assist in the validation process prior to go-live, including verifying remediation actions, tracking exceptions, and monitoring residual risks.
  • Maintain a clear and traceable record of architectural decisions, risks identified, recommendations, waivers, compensating controls, ownership, and closure status.
  • Support governance committees by reporting significant risks, architectural decisions, exceptions, and treatment strategies to stakeholders.
  • Contribute to ongoing enhancements of client security principles, standards, reusable patterns, review tools, and assurance procedures.
  • Provide expert architecture advice during security incident response, major vulnerability management, or significant technology changes requiring design-level fixes.
  • Mentor security and technology team members, promoting adoption of security-by-design, privacy-by-design, and zero-trust principles across delivery teams.

Required Skills and Certifications

  • In-depth expertise in enterprise security architecture, risk analysis, threat modeling, and security-by-design methodologies.
  • Hands-on experience with cloud, on-premises, and hybrid infrastructure; and comprehensive knowledge across application, infrastructure, network, data, integration, IAM/PAM, and security operations.
  • Understanding of UAE cybersecurity regulations and data protection laws relevant to governmental and healthcare sectors alongside adherence to internal client security policies.
  • Familiarity with established frameworks such as ISO/IEC 27001, NIST Cybersecurity Framework, NIST SP 800-53, CIS Controls, SABSA, TOGAF, and OWASP standards.

Minimum Experience and Education

  • At least 10 years of professional experience in the cybersecurity domain, including a minimum of 5 years specializing in security architecture, solution security, security engineering, or technology risk management positions.
  • A bachelor's degree in Cybersecurity, Computer Science, IT, Engineering, or a related field is required.
  • A master's degree in Cybersecurity, Information Assurance, Enterprise Architecture, or an allied discipline is preferred but not mandatory.

Minimum education

Bachelor's Degree

Industry

Cybersecurity

How they work

Teamwork & Collaboration Leadership Initiative Decision Making
🤖
Online · instant AI help
Broxer