Responsibilities
- Define and lead the long-term security architecture vision and multi-year strategy, balancing risk mitigation with business goals, and communicate trade-offs to executive leadership.
- Conduct comprehensive enterprise architecture evaluations across diverse environments, with emphasis on cloud platforms such as Azure, including network design and Kubernetes infrastructure.
- Evaluate enterprise systems with a focus on identity and access management, including zero trust frameworks, conditional access policies, and privileged access management.
- Assess architecture across environments to strengthen security within CI/CD pipelines and software development lifecycle practices.
- Lead architectural reviews involving AI and large language model (LLM) systems to ensure secure deployment and operational integrity.
- Collaborate with Cloud Operations and Product Architecture teams to integrate security into platform and product development roadmaps.
- Create standardized security reference architectures and design patterns consistent with organizational security objectives.
- Design and deploy layered security controls across enterprise systems to ensure defense-in-depth and resilience across digital assets.
- Serve as the primary security architecture authority across internal teams, offering expert guidance on security principles, technologies, and design patterns.
- Ensure all architectural decisions comply with regulatory, customer, and audit standards through documented patterns and formal architecture reviews.
- Work closely with Product, Engineering, Enterprise Architecture, and CloudOps teams to integrate security controls and align technology choices with security strategy.
- Engage senior leadership to influence cybersecurity direction and maintain architectural consistency across departments.
- Design secure enterprise architectures for multi-cloud environments, primarily Azure, covering networking, compute, data, containers, and serverless technologies.
- Collaborate on security design and implementation within Microsoft 365 and Entra ID ecosystems.
- Provide expert consultation on Microsoft security solutions such as Defender XDR, Defender for Cloud, Azure Policy, endpoint protection, network security, and conditional access.
- Assess emerging cloud services to identify potential risks and implement mitigation strategies prior to adoption.
- Support security design for cloud-deployed workloads across IaaS, PaaS, and serverless models, ensuring compliance with corporate and regulatory standards.
- Build secure reference architectures for Azure container platforms like AKS, including cluster governance, baseline policies, workload identity, secrets management, threat detection, isolation, and cost controls.
- Develop secure reference designs for Azure compute services, including virtual machines, scale sets, and serverless workloads.
- Create secure architectures for Azure storage and data services, covering storage accounts, Azure SQL, managed databases, key management, and data loss prevention.
- Advance security-by-design practices in product development, including pipeline compliance checks and architecture reviews for deviations.
- Contribute security-related nonfunctional requirements, threat models, and reference patterns to product roadmaps; review high-impact designs and ensure alignment with enterprise standards.
- Develop enterprise-level architectural assets such as blueprints, playbooks, and technical whitepapers to strengthen security practices.
- Support the growth of a security-conscious culture by enhancing security literacy across technical teams.
- Act as a trusted security advisor, clearly communicating complex technical risks and concepts to both technical and business stakeholders.