Title: Security Architect - L1
Job Description
Role Purpose
The purpose of this role is to design the organisation’s computer and network security infrastructure and protect its systems and sensitive information from cyber threats
͏
Do
1. Design and develop enterprise cyber security strategy and architecture
a. Understand security requirements by evaluating business strategies and conducting system security vulnerability and risk analyses
b. Identify risks associated with business processes, operations,
information security programs and technology projects
c. Identify and communicate current and emerging security threats and design security architecture elements to mitigate threats as they emerge
d. Identify security design gaps in existing and proposed architectures and recommend changes or enhancements
e. Provide product best fit analysis to ensure end to end security covering different faucets of architecture e.g. Layered security, Zoning, Integration aspects, API, Endpoint security, Data security, Compliance and regulations
f. Demonstrate experience in doing security assessment against NIST Frameworks, SANS, CIS, etc.
g. Provide support during technical deployment, configuration, integration and administration of security technologies
h. Demonstrate experience around ITIL or Key process-oriented domains like incident management, configuration management, change management, problem management etc.
i. Provide assistance for disaster recovery in the event of any security breaches, attacks, intrusions and unusual, unauthorized or illegal activity
j. Provide solution of RFP’s received from clients and ensure overall design assurance
͏
i. Develop a direction to manage the portfolio of to-be-solutions including systems, shared infrastructure services, applications, hardware related to cyber risk security in order to better match business outcome objectives
ii. Analyse technology environment, enterprise specifics, client requirements to set a collaboration design framework/ architecture
iii. Depending on the client’s need with particular standards and technology stacks create complete RFPs
iv. Provide technical leadership to the design, development and implementation of custom solutions through thoughtful use of modern technology
v. Define and understand current state solutions and identify improvements, options & tradeoffs to define target state solutions
vi. Clearly articulate and sell architectural targets, recommendations and reusable patterns and accordingly propose investment roadmaps
vii. Evaluate and recommend solutions to integrate with overall technology ecosystem
viii. Tracks industry and application trends and relates these to planning current and future IT needs
͏
2. Stakeholder coordination & audit assistance
a. Liaise with stakeholders in relation to cyber security issues and provide timely support and future recommendations
b. Provide assistance in maintaining an information security risk register and help with internal and external audits relating to information security
c. Support audit of security best practices and implementation of security principles across the organization, to meet business goals along with customer and regulatory requirements
d. Assist with the creation, maintenance and delivery of cyber security awareness training to team members and customers
e. Provide training to employees on issues such as spam and unwanted or malicious emails
͏
Deliver
No | Performance Parameter | Measure |
1 | Customer centricity | Timely security breach solutioning to end users, Internal stakeholders & external customers experience, CSAT, educating and suggesting right control to the customers. |
2 | Support sales team to create wins | % of proposals with Quality Index >7, timely support of the proposals, identifying opportunities/ leads to sell services within/ outside account (lead generation), no. of proposals led |
Job Title - Azure Security Architect
Experience - 12-15 years
Technical Qualification/ Knowledge:
- Hands-on knowledge on Azure security technologies and associated components and variations
- Azure Security Center, Azure Monitor, Log Analytics, Sentinel or any other SIEM integration
- Azure Networking: VNET, Network Security Group (NSG), VNet peering, Azure Firewall
- Azure Storage Security: storage accounts, managed disks, blobs, encryption at rest and in-transit, Azure KeyVault,
- Azure Active Directory, RBAC, MFA, SAML, Conditional Access, Managed Identity.
- Azure Load Balancers, WAF, Application Gateway, Availability Sets/Scale Sets
- Knowledgeable about Windows Operating System, Server hardening, Group Policies, event and log management
- Design, implement and support Microsoft Defender for O365 with Azure Information Protection and MS DLP for O365 and Endpoint
- Experience in deploying MDATP for Servers
- Experience with multiple security tools and technologies including Next-Gen Firewalls (Palo Alto), McAfee ePO, DLP, CrowdStrike, ZScaler, Vulnerability Assessment (Tenable.io)
- Ability to lead to troubleshooting of cloud security issues, detect and confirm anomalies, identify risks, perform root cause analysis
- Skilled in Graph API, Azure CLI / PowerShell automation experience
- Should be able to create, update, retry and delete Azure AD objects via PowerShell, Azure CLI
- Understanding of the Azure Subscription and Migration activities will be added advantages.
Additional Qualifications and Experience:
- Cloud Security certifications
- Microsoft certifications: AZ-900, AZ-500, MS-900, MS-500, AZ-30X, SC200 – 300.
- Familiarity with Zero Trust principles