Information Security Architect
Job Objective
- To establish a strategic security architecture vision, including standards and frameworks that are aligned with overall business strategy through:
- Working closely with Security Services Managers in understanding client’s business requirements; and working closely with the infrastructure and operations teams within various Lines of Business in order to understand T-Systems technical delivery capabilities.
- Working with Portfolio and Solutions Design (PSD) team and participate in solution architecture design; lead security efforts by assisting with the integration and initial implementation of solutions.
- To continually review existing architecture, identify design gaps, recommend, and implement security enhancements.
- To achieve security architecture compliance on requirements, including but not limited to:
- Protection of Personal Information Legislation
- Electronic Communication and Transactions Legislation
- Sarbanes-Oxley (Where applicable)
- Sherwood Applied Business Security Architecture
- ITILv3
- COBIT
- ISO 27001/2
- Payment Card Industry Data Security Standards
- South African bureau of Standards
- T – Systems internal and DTAG architectural guidelines and standards
- To serve as information security subject matter expert; and provide advisory and consulting services in line with Master Services Agreement (MSA) requirements.
- Understand current as well as emerging security threats and design security architecture to mitigate threats where possible.
- Ensure that all Architectural documents are kept up to date and centrally stored in accordance to the change management processes
- Ensure that designed systems are adequately documented to allow for operational usage, this includes but is not limited to process flow design, best use guides, reference guides
- To understand the customer service contracts (Statement of Work) and ensure that contracted security services are designed to be delivered based on the agreed key performance indicators.
- Manage and monitor other third parties to ensure that contracted security architecture services are delivered as per contract/statement of work and internal set guidelines and criteria
- Ensure ALL designed systems are documented to maintain traceability from both customers’ and companys’ contextual views, strategic views, design views, build views, component views as well as service views
- Ensure use cases and RACIs are properly documented for each system (current and future)
- Serve as Project Technical Architect for Security related projects and ensuring the projects are delivered in accordance
- Perform regular review of the Architecture of Security Systems in production and ensure they remain compliant to business and security architecture requirements
Qualifications
- Bachelor’s degree in computer science, or related field preferred.
- Master’s Degree is ideal.
- In-depth understanding of Architecture Frameworks such as SABSA, Zachmann, TOGAF-9, Archimate and Frameworx. Certificates in CISSP, SANS GIAC, and SABSA will be an advantage.
- Minimum of 10 years in the information Technology in large enterprise environments
- Minimum of 5 years of hands-on Technical Information Security Operational experience
- Minimum of 6 years’ experience designing and implementing security solutions within large enterprise or consulting roles