Cybersecurity Architect - Cloud
Key Responsibilities
- Provide overall technical direction for cybersecurity strategy and architecture across a hybrid on-premise and cloud landscape.
- Design and maintain the Group’s cloud security reference architecture for AWS and hybrid environments, including landing zones, network security, identity, data protection, and workload security.
- Define cloud security standards, guardrails, and policies aligned with frameworks such as NIST CSF, CIS Benchmarks, ISO 27001, and CSA Cloud Controls Matrix; ensure these are adopted across all cloud deployments.
- Architect identity and access management (IAM) solutions for hybrid environments, including Entra ID, conditional access, privileged identity management (PIM), and zero-trust architecture principles.
- Lead cloud security posture management (CSPM) strategy using tools such as Microsoft Defender for Cloud, AWS Security Hub, or third-party CSPM platforms; drive continuous compliance monitoring and remediation.
- Design secure network architectures for cloud environments, including micro-segmentation, WAF, DDoS protection, private endpoints, service endpoints, and hybrid connectivity security (ExpressRoute / Direct Connect / VPN).
- Provide security architecture guidance for SAP RISE / S/4HANA cloud migration, M365 tenant hardening, and cloud-native application development (containers, serverless, API security).
- Develop an AI agentic-first security review and vulnerability management pipelin