Area(s) of responsibility
- Define and own the Enterprise Security Architecture roadmap, ensuring alignment with business strategy, and regulatory requirements across IT, OT, and cloud environments.
- Develop and maintain a comprehensive security reference architecture covering infrastructure, applications, identity, data, and operations, aligned with frameworks such as NIST CSF, ISO 27001, SOX.
- Drive architectural governance and security design reviews across business initiatives, transformation programs, and innovation streams including AI / ML workloads, ensuring risk-informed decisions and alignment with enterprise architecture standards.
- Establish enterprise-wide visibility and telemetry strategy, integrating cloud-native and on-prem security telemetry into centralized SIEM / SOAR platforms to enhance threat detection, response, and performance optimization.
- Lead implementation and governance of Privileged Access Management (PAM) solutions like BeyondTrust, enabling just-in-time (JIT) access, session monitoring, and least privilege enforcement across all environments.
- Define and drive the vulnerability and configuration management strategy, ensuring full-stack coverage (applications, OS, cloud, containers, OT) through tools like Tenable, Qualys, and Defender, with clear remediation SLAs.
- Oversee Security Operations Center (SOC) strategy and operational excellence, ensuring proactive threat hunting, automation of response, escalation matrix, SLA / KPI tracking, and strategic incident reporting to business stakeholders.
Skills Required
Ml, SOAR, Ai, Configuration Management, Iso 27001, Siem, Sox, Qualys