- Company Name
- TAGMATIX360
- Job Title
- Security Architect
- Job Description
-
**Job Title**
Security Architect
**Role Summary**
Design, implement, and manage comprehensive security architectures for both IT and OT environments. Lead the development of risk assessment frameworks using STRIDE, enhance incident detection, and strengthen resilience across industrial networks. Deliver cloud and hybrid infrastructure security strategies across Azure, AWS, and GCP, integrate SIEM solutions (Azure Sentinel, Splunk), manage IAM/PAM (CyberArk, BeyondTrust), and ensure compliance with NIST, IEC 62443, ISO 27001, and GDPR.
**Expactations**
* Deliver secure, scalable security designs that meet regulatory and operational requirements.
* Proactively identify and mitigate security risks in industrial and cloud environments.
* Provide expert guidance on cloud security controls, SIEM integration, and identity management.
* Communicate security strategy and risk posture to stakeholders at all levels.
* Continuously evaluate emerging threats and update security architecture accordingly.
**Key Responsibilities**
1. Build and maintain IT/OT security risk assessment frameworks (STRIDE, NIST, IEC 62443).
2. Architect and implement security controls across Azure, AWS, and GCP (GuardDuty, Macie, Config, CloudTrail, Security Hub, Secrets Manager, Shield).
3. Integrate SIEM tools (Azure Sentinel, Splunk) and define event correlation rules for threat detection.
4. Design and administer IAM/PAM solutions (CyberArk, BeyondTrust) to enforce least‑privilege access.
5. Lead security reviews, penetration tests, and audit preparation for ISO 27001, NIST, IEC 62443, GDPR compliance.
6. Develop and deliver security architecture documentation, diagrams, and policies.
7. Mentor and train cross‑functional teams on security best practices and architecture principles.
**Required Skills**
* STRIDE risk assessment and threat modeling.
* Cloud security (Azure, AWS, GCP) – architecture, governance, and best practices.
* SIEM integration (Azure Sentinel, Splunk) and log management.
* Identity & Access Management, Privileged Access Management (CyberArk, BeyondTrust).
* Knowledge of NIST, IEC 62443, ISO 27001, GDPR, and other relevant standards.
* Strong analytical, problem‑solving, and communication abilities.
* Experience with industrial control systems and OT security is highly desirable.
**Required Education & Certifications**
* Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
* CISSP, CISM, or equivalent security certification.
* Cloud security certifications (e.g., Microsoft Certified: Azure Security Engineer Associate, AWS Certified Security – Specialty, Google Professional Cloud Security Engineer).
* IAM/PAM certifications (CyberArk, BeyondTrust) preferred.