- Company Name
- Project Brains
- Job Title
- Information Security Architect
- Job Description
-
**Job Title:**
Information Security Architect
**Role Summary:**
Design and implement enterprise security architecture, ensuring application, network, and data protection. Collaborate with cross‑functional teams to embed security into product lifecycles, assess risks, and maintain compliance with regulatory frameworks.
**Expectations:**
- Deliver robust, scalable security solutions that meet business and regulatory requirements.
- Proactively identify and mitigate threats across all technical layers.
- Drive continuous improvement of security policies, controls, and incident response processes.
**Key Responsibilities:**
- Architect and document security frameworks for cloud, on‑premise, and hybrid environments.
- Conduct threat modeling, risk assessments, and security gap analyses.
- Define and enforce security controls, penetration testing plans, and vulnerability remediation policies.
- Collaborate with development, operations, and compliance teams to integrate security into CI/CD pipelines and dev‑ops practices.
- Stay current with evolving threats, vulnerabilities, and industry best practices.
- Provide guidance on secure architecture patterns and design reviews.
- Lead security audits, technical assessments, and compliance evaluations.
**Required Skills:**
- Strong expertise in application security, secure coding, and threat modeling.
- Proficiency with network security concepts, firewalls, IDS/IPS, VPN, and secure network design.
- Knowledge of industry standards (e.g., NIST, ISO 27001/27018, SOC 2, GDPR, PCI‑DSS).
- Experience with cloud security services (AWS, Azure, GCP) and secure cloud architecture.
- Ability to analyze and mitigate risk, conduct vulnerability assessments, and perform penetration testing.
- Excellent communication, documentation, and stakeholder‑management skills.
- Problem‑solving mindset and capacity to work autonomously and collaboratively.
**Required Education & Certifications:**
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field (or equivalent experience).
- Relevant certifications such as CISSP, CISM, CCSP, CEH, or equivalent are highly preferred.