The Principal Security Architect will orchestrate the design and deployment of comprehensive security architectures across cloud platforms, microservices, and enterprise systems within the consumer business. They will drive the development and execution of the consumer security strategy, ensuring the implementation of technology roadmaps that improve and safeguard the company's overall security posture.
This role requires a deep understanding of cloud-native security, application security, data security, and enterprise security technologies. You will work closely with developers, security engineers, and DevSecOps teams to integrate security into the entire software development lifecycle and enterprise infrastructure.
Key Responsibilities:
- Develop and maintain comprehensive security architecture documentation aligned with business goals, enterprise target architecture, and industry standards.
- Design and implement security frameworks for cloud-native environments, ensuring secure deployment on platforms like GCP and AWS (GCP Preferred), and integrating security into CI/CD pipelines and microservices.
- Lead the Security Architecture Review Board and promote secure coding practices, ensuring security is embedded, maintained, and thoroughly documented. Build, maintain, and standardize security architecture artifacts, including standards, patterns, and procedures for consistent implementation.
- Define and implement security standards for data protection, IAM, encryption, network security, and regulatory compliance (GDPR, PCI DSS).
- Collaborate across teams to integrate security controls, handle threat modelling, and address risks related to application, API, and cloud security.
- Lead threat modelling exercises and define security controls that address application security risks (e.g., OWASP Top 10, API security) and cloud security standard methodologies.
- Provide strategic mentorship on security tools and enterprise technologies, advising on secure architecture patterns, cloud automation, and evolving security threats.
- Own the evaluation of security tools and recommend technologies for intrusion detection and prevention, security monitoring, web application firewalls (WAF), and data encryption, among others.
- Lead the evaluation of security tools and recommend technologies for intrusion detection and prevention, security monitoring, web application firewalls (WAF), and data encryption, among others.