As a Security Cloud Architect within the CISO Office, you will join the Security Architecture team and play a key role in securing the organisation's cloud transformation initiatives. You will act as a technical authority on cloud security topics, providing practical guidance, reviewing architecture decisions, challenging technical designs when required, and ensuring that identified risks are appropriately addressed through security controls or formal risk acceptance processes.
Missions
Define cloud security policies, standards, guardrails, design patterns, and reference architectures for AWS and Azure environments.
Develop and maintain reusable security blueprints and architectural building blocks for AWS, Azure, and cloud-native technologies.
Ensure alignment with business, regulatory, and security requirements.
Contribute to the continuous improvement of the cloud security control framework.
Define security requirements for cloud platforms and services.
Design secure patterns for IAM, networking, encryption & key management, logging & monitoring, container and Kubernetes security, and DevSecOps.
Promote security by design and zero-trust principles.
Provide hands-on technical expertise during design workshops, proof-of-concepts, and implementation activities.
Review solution designs and cloud projects.
Identify security risks, weaknesses, and control gaps.
Assess the security implications of emerging cloud technologies and AI services.
Conduct threat modelling exercises for cloud-based solutions to identify potential attack paths, security weaknesses, and required mitigating controls.
Define remediation measures and support risk acceptance processes.
Review and challenge security exception requests.
Participate in architecture governance and review boards.
Collaborate with Security Risk Managers to ensure identified risks are properly documented, assessed, and tracked through the risk management process.
Collaborate with operational security teams to ensure security controls can be effectively monitored and operated.
Improve detection, monitoring, and response capabilities in the cloud.
Promote cloud security best practices across engineering teams.
Increase awareness of security-by-design principles.
Support teams in adopting secure cloud patterns and controls.