Principal/Lead Cybersecurity Specialist
Summary
Lead the security architecture for a large-scale enterprise platform, embedding zero-trust and secure-by-design principles while guiding engineering teams on secure coding and DevSecOps practices.
Job Description
Security Architecture & Engineering
- Design and own the security architecture for a large-scale enterprise platform.
- Define trust boundaries, identity and access control strategies, network segmentation, encryption, key management, and zero-trust security patterns.
- Embed secure-by-design principles throughout the software development lifecycle.
- Partner with engineering teams to ensure security controls are implemented directly within platform and application designs.
- Develop and maintain threat models to identify risks and influence architecture decisions.
Platform Resilience & Reliability
- Design platform resilience strategies, including recovery, fault isolation, service continuity, and disaster recovery capabilities.
- Assess and mitigate dependency risks across infrastructure, applications, and third-party integrations.
- Support resilience testing exercises and ensure lessons learned are incorporated into future designs.
Secure Delivery & Continuous Assurance
- Drive adoption of DevSecOps, policy-as-code, and security automation practices.
- Implement continuous security monitoring and automated control validation.
- Establish security guardrails within CI/CD pipelines.
- Promote secure coding practices and mentor engineering teams on building secure applications.
Technical Leadership
- Serve as a trusted advisor to engineering and leadership teams on cybersecurity architecture decisions.
- Provide technical guidance on security tooling, architecture patterns, and secure platform design.
- Influence engineering standards, security practices, and long-term technology strategy.
- Foster a strong security culture through coaching and mentoring.
What We're Looking For
Experience
- 10+ years of experience in software engineering and cybersecurity.
- Proven experience designing and implementing security architecture for large-scale, highly regulated, or mission-critical systems.
- Strong hands-on engineering background with the ability to design solutions and contribute technically when needed.
- Experience partnering closely with software engineers to improve application and platform security.
- Demonstrated ability to balance security, scalability, resilience, and operational requirements.
Technical Expertise
Strong understanding of: Cloud and hybrid-cloud security architectures
- Identity and access management
- Zero Trust security principles
- Encryption and key management
- Network segmentation and micro-segmentation
- Secure SDLC and DevSecOps practices
- Policy-as-Code and Infrastructure-as-Code concepts
Experience with:
- Cloud platforms such as AWS, Azure, or GCPCI/CD platforms and security automation
- Infrastructure and platform security controls
- Threat modelling and security architecture frameworks
Familiarity with security standards and frameworks such as:
- NIST
- ISO 27001
- CIS Controls
- MITRE ATT&CK
Preferred Skills
- Proficiency in one or more scripting/programming languages such as Python, TypeScript, Shell/Bash, or similar.
- Experience with modern cloud-native architectures and container platforms.
- Exposure to Kotlin/JVM and TypeScript environments is advantageous.
- Experience implementing security controls through automation and code.
Certifications (Preferred)
- CISSP or CISSP-ISSAP
- SABSA
- AWS Security Specialty
- Azure Security Engineer
- Other security architecture or cloud security certifications
Why Join Us
- Opportunity to shape the security architecture of a large-scale, business-critical platform.
- Work on complex modernization and cloud transformation initiatives.
- Influence engineering standards and security practices across multiple teams.
- Collaborative environment focused on technical excellence, innovation, and continuous improvement.
- Competitive remuneration and comprehensive benefits package.
- Flexible working arrangements, subject to business requirements.