- Company Name
- Creo Invent
- Job Title
- Security Architect
- Job Description
-
**Job Title:** Security Architect
**Role Summary:** Design, implement, and govern security solutions across IT and OT environments, ensuring alignment with industry standards and regulatory requirements. Lead risk assessments, architecture decisions, and incident defense strategies for cloud, hybrid, and industrial networks.
**Expectations:**
- Develop and maintain security architecture frameworks and standards.
- Lead cross‑functional teams to embed secure design into product development and operations.
- Continuously assess and mitigate technical and compliance risks.
**Key Responsibilities:**
- Conduct comprehensive IT/OT security risk assessments using STRIDE, producing actionable improvement plans.
- Architect secure cloud environments (Azure, AWS, GCP) integrating services such as GuardDuty, Macie, Config, CloudTrail, Security Hub, Secrets Manager, Shield, Azure Sentinel, and Splunk SIEM.
- Define and enforce IAM/PAM policies and tools (CyberArk, BeyondTrust).
- Implement and manage security controls for network segmentation, device hardening, and data protection in industrial control systems.
- Ensure compliance with NIST, IEC 62443, ISO 27001, and GDPR.
- Develop threat models, incident response plans, and business continuity strategies.
- Liaise with stakeholders to translate security requirements into architecture documentation and operational procedures.
- Monitor security posture and recommend enhancements through continuous improvement cycles.
**Required Skills:**
- Expert knowledge of cloud security (AWS, Azure, GCP) and hybrid infrastructure.
- Proficient with SIEM platforms (Azure Sentinel, Splunk) and log analytics.
- Strong background in IAM, PAM, and privileged access management.
- Deep understanding of OT security protocols, IEC 62443, and network security.
- Skilled in security assessment methodologies (STRIDE, PASTA, NIST CSF).
- Experience with compliance frameworks (ISO 27001, GDPR, NIST).
- Ability to produce clear architecture diagrams, threat models, and policy documentation.
**Required Education & Certifications:**
- Bachelor’s or higher degree in Computer Science, Cybersecurity, or related field.
- Relevant certifications such as CISSP, CISM, or equivalent.
- Cloud‑specific certifications (AWS Security Specialty, Microsoft Certified: Azure Security Engineer Associate, GCP Professional Cloud Security Engineer) preferred.