- Company Name
- Galaxi Consulting Group
- Job Title
- Security Architect
- Job Description
-
**Job Title**
Security Architect
**Role Summary**
Design, implement, and maintain comprehensive security architectures for IT and OT environments in critical infrastructure, utilities, and finance sectors. Lead risk assessment, threat modelling, and Zero Trust strategy across industrial control systems (ICS), cloud, and hybrid deployments while ensuring compliance with global standards.
**Expectations**
- Deliver secure, scalable solutions that protect industrial networks and data integrity.
- Communicate complex security concepts to technical and non‑technical stakeholders.
- Stay current with evolving threats, industry standards, and regulatory requirements.
**Key Responsibilities**
- Conduct risk assessments using STRIDE, DREAD, and MITRE ATT&CK; develop mitigation plans.
- Design and enforce Zero Trust architectures for IT/OT integration.
- Build and maintain cloud security controls on Azure, AWS, and GCP (VM, networking, IAM, encryption).
- Configure and integrate SIEM tools (Azure Sentinel, Splunk, ElasticSIEM).
- Manage IAM/PAM solutions (Azure AD PIM, CyberArk, BeyondTrust).
- Lead penetration testing and vulnerability scans (Kali, Nessus, Burp, Metasploit).
- Draft policy, procedures, and compliance reports for NIST, IEC 62443, ISO 27001, GDPR, PCI DSS, and COBIT.
- Mentor cross‑functional teams and drive secure digital transformation initiatives.
**Required Skills**
- Security frameworks: NIST CSF, Zero Trust, STRIDE, DREAD.
- SIEM: Azure Sentinel, Splunk, LogRhythm, ElasticSIEM.
- IAM/PAM: Azure AD PIM, CyberArk, BeyondTrust.
- Cloud platforms: Azure, AWS, GCP; networking (VPC, VPN, Route53, ELB, ExpressRoute).
- Threat modelling, penetration testing, vulnerability assessment tools.
- Network & datacenter knowledge (IP, NGFW, DMVPN, MPLS, BGP, OSPF).
- DevSecOps tools: Tenable.io, Veracode, AppScan; configuration management (Chef, Ansible).
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Security, or related field.
- Preferred certifications: CISSP, GRC, CCSP, CXO, or equivalent.
- Cloud security certifications (e.g., Microsoft Certified: Azure Security Engineer Associate, AWS Certified Security – Specialty, Google Professional Cloud Security Engineer).
---