31 Jul
|
3i Infotech
|
India
The Cyber Security Architect is responsible for designing, governing, and continuously improving the organisation's security architecture across on-prem, cloud, network, applications, data, and identities. The role translates business and regulatory requirements into secure, practical technical designs and guides their implementation in line with frameworks such as ISO 27001, NIST, CIS, and Zero Trust principles.
Key Responsibilities :
1. Security strategy and architecture design :
- Define and maintain the enterprise security architecture, security principles, reference patterns, and roadmaps covering network, infrastructure, cloud, applications, data, and endpoints.
- Align security architecture with business strategy, risk appetite, and compliance obligations (ISO 27001, SOC 2, sectoral regulations, data protection laws).
2. Solution and project design assurance :
- Work with solution/enterprise architects to review and approve designs for new systems, integrations, and cloud services, ensuring security by design and Zero Trust principles.
- Define security requirements for infrastructure components (networks, firewalls, WAF, VPN, IAM, EDR, SIEM, DLP, key management) and ensure they are implemented consistently.
3. Risk assessment and threat modelling :
- Conduct or oversee threat modelling and security risk assessments for critical systems and changes, using frameworks such as STRIDE, NIST CSF, CIS Controls.
- Recommend layered controls and compensating measures to reduce risk to acceptable levels and document residual risks for decision-makers.
4. Security standards, policies, and patterns :
- Develop and maintain security policies, standards, baselines, and configuration hardening guides for operating systems, databases, network devices, cloud resources, and applications.
- Create reusable reference architectures and design patterns (e.g., secure DMZ, remote access, B2B APIs, privileged access, multi-cloud landing zones).
5. Security technology roadmap and tooling :
- Evaluate, select, and guide implementation of security technologies (SIEM/SOAR, IAM/PAM, EDR/XDR, CSPM, WAF, SASE/SD-WAN, encryption/HSM, vulnerability management).
- Ensure integration between security tools and with ITSM, monitoring, and DevOps pipelines to support detection, response, and compliance.
6. Security operations and incident support :
- Provide architectural guidance to SOC and incident response teams during major incidents and post-incident reviews, ensuring learnings feed back into architecture and controls.
- Define logging, monitoring, and telemetry requirements (what to log, retention, SIEM correlation rules) for critical systems.
7. Cloud and DevSecOps security :
- Design secure architectures for cloud and hybrid environments, including identity, network segmentation, key management, and workload protection.
- Work with DevOps teams to embed security controls in CI/CD, container/orchestration platforms, and infrastructure-as-code (IaC) templates.
8. Governance, stakeholder engagement, and advisory :
- Act as a senior security advisor to CIO/CTO/Heads of Business, explaining risk, trade-offs, and recommended controls in business language.
- Contribute to security governance forums, architecture boards, change advisory boards (CAB), and risk committees.
Required Skills and Experience :
Experience :
- Typically 8 - 12+ years in information security, infrastructure, or architecture roles, including hands-on experience in network, systems, or cloud security, and several years in a design/architecture capacity.
Technical competencies :
- Strong understanding of network and infrastructure security (TCP/IP, routing, firewalls, VPN, WAF, proxies, load balancers, DDoS, segmentation).
- Solid knowledge of identity and access management, SSO, MFA, federation, and privileged access management.
- Experience with cloud platforms (AWS/Azure/GCP/OCI), their security services, and cloud security reference architectures.
- Familiarity with application security concepts (OWASP, secure SDLC, API security) and data protection (encryption, tokenisation, DLP).
- Hands-on exposure to SIEM/SOAR, EDR/XDR, vulnerability management, and security monitoring tools.
- Technical Proposal building.
Frameworks and compliance :
- Working knowledge of ISO/IEC 27001, NIST CSF/800-53, CIS Controls, Zero Trust (e.g., NIST SP 800-207), and relevant regulatory requirements for your sector.
Soft skills :
- Ability to communicate complex security concepts to both technical and non-technical stakeholders; strong documentation and presentation skills.
- Strong analytical, problem-solving, and decision-making skills; ability to balance security, usability, and cost.
Education and certifications :
- Bachelors degree in Computer Science, Information Security, Engineering or related field; a relevant Masters is a plus.
- One or more skilled certifications, e.g. :
i. CISSP, CCSP, CISM, SABSA, TOGAF.
ii.
Microsoft Cybersecurity Architect
Expert, cloud security certs (AWS/Azure/GCP security).
📌 3i Infotech - Cyber Security Architect (India)
🏢 3i Infotech
📍 India