Senior Cyber Security Solution Architects (IT & OT) Services
Posted
Summary
Lead security architecture authority for client IT and OT initiatives: designing secure architectures across enterprise IT, ICS/SCADA and critical infrastructure, plus cloud (Azure, AWS, GCP), IAM/PAM, Zero Trust and SOC/SIEM stacks. Requires 10-15 years in cybersecurity with 7+ in security architecture.
The Senior Cyber Security Solution Architect will serve as the lead security architecture
authority for assigned IT and OT initiatives and perform the following services:
v Align and maintain cyber security architecture across IT, OT, cloud, identity, network, application and data domains.
v Develop target-state reference architectures, standards, patterns, principles and technology roadmaps.
v Design secure architectures for enterprise IT, ICS, SCADA, generation, transmission, distribution, critical infrastructure
and OT networks.
v Define segmentation, IT/OT integration, secure remote access and third-party connectivity using Purdue and Zero Trust
principles.
v Review and approve security architectures, solution designs and technical specifications and conduct threat modelling
and architecture risk assessments.
v Develop Azure, AWS, Google Cloud, SaaS, hybrid and multi-cloud security architectures and guide secure adoption of AI,
analytics, IoT and emerging technologies.
v Define IAM, PAM, authentication and authorization architectures and Zero Trust access Principles
v Guide SOC, SIEM, SOAR, XDR, EDR, threat intelligence, cyber resilience, business continuity, disaster recovery and
ransomware recovery architectures.
v Support governance, audit, regulatory engagements, procurement security requirements, technology evaluations, proofs
of concept and rationalisation initiatives.
Requirements
Key Performance Indicators
Improvement in IT/OT cyber security maturity and security control coverage.
Reduction and timely closure of high-risk architecture findings.
Compliance of reviewed solutions with approved security architecture standards.
On-time secure delivery of strategic projects and agreed architecture-review turnaround times.
Reduction in cyber risk exposure and improvement in resilience and recovery capability.
Adoption of Zero Trust and secure-by-design practices
Identified security technology optimisation and cost-saving opportunities.
Qualifications and certifications
- Bachelor’s Degree in Computer Science, Information Systems, Cyber Security,
- Electrical Engineering, Telecommunications or Information Technology.
- Honours or Master’s Degree in Cyber Security, Information Systems, Engineering or Business Technology is preferred.
- At least one of CISSP, CISM, SABSA, TOGAF or CCSP is required.
- GICSP, ISA/IEC 62443 Cybersecurity Expert, Azure Security Engineer Associate,
- AWS Security Specialty, CRISC, CISA or CEH is preferred.
Experience
- 10 to 15 years of cybersecurity experience, including at least 7 years in security architecture.
- Demonstrated experience securing critical infrastructure and working across both IT and OT environments.
- Experience in security operations, identity management, cloud security, network security and enterprise security
architecture development.
Prerequisites and skills
- Strategic thinking, executive communication, stakeholder management, influencing and negotiation.
- Strong decision-making, problem-solving, innovation, team leadership, vendor management and programme leadership.
- Ability to operate as security design authority and collaborate with Enterprise Architecture, IT, OT, engineering, risk,
procurement and project teams.
- Ability to produce clear architecture artefacts and communicate complex security risk to technical and executive
audiences.
Technical requirements
- Demonstrated capability in enterprise security architecture, IT/OT convergence, ICS/SCADA security, Zero Trust, cloud
security, network segmentation, IAM/PAM, threat modelling, security engineering and cyber resilience.
- Working knowledge of SCADA, DCS, PLC environments, industrial protocols, Purdue architecture and industrial
cybersecurity controls.
- Practical application of ISO 27001, NIST CSF, NIST 800-53, ISA/IEC 62443, SABSA, TOGAF, COBIT, ISO 22301 and
MITRE ATT&CK.
- Experience with SIEM, SOAR, XDR, EDR, vulnerability management and secure software development considerations.
Platforms and technology experience
- Microsoft Azure, AWS, Google Cloud and SaaS platforms.
- ICS, SCADA, DCS, PLC and industrial network environments.
- IAM/PAM and security operations technologies, including SIEM, SOAR, XDR and EDR.
Delivery point and working arrangement
- Clients sites and approved remote-working locations, as directed by the requestor and subject to operational and
security requirements.
- Travel to IT, OT and critical infrastructure sites may be required where architecture assessments, workshops or
assurance activities must be performed on site.
Security clearance and vetting
All resources will be required to undergo security clearance and vetting
TRAINING AND SKILLS TRANSFER
The resource must provide continuous knowledge transfer to nominated internal personnel through architecture workshops, joint
design reviews, mentoring, walkthroughs of standards and patterns, and documented handover of all artefacts. A skills-transfer
plan and competency or attendance record must be maintained, with formal handover completed before task-order closure.