Lead - Enterprise Security Architect

📁
Operational Technology & Cyber Security Engineer
📅
091750 Requisition #

ROLE PURPOSE

The Enterprise Security Architect defines and governs the organisation’s security
architecture strategy, ensuring that all enterprise and solution designs are secure,
compliant, and resilient by design.
The role provides both strategic leadership and hands-on architectural guidance,
embedding security principles, controls, and automation into every aspect of
Petrofac’s hybrid and multi-cloud environment — covering applications, data,
infrastructure, and integration layers.
Acting as the bridge between cybersecurity governance and technology delivery,
the Security Architect defines security reference architectures, policies, and
standards, ensuring these are implemented through modern DevSecOps practices,
zero-trust models, and continuous compliance automation.
Working closely with Cloud, Data, and Integration Architects to design secure
platforms and data flows — and with Solution and Technical Architects to embed
secure patterns into projects — the Security Architect ensures consistent and
measurable security across the enterprise technology landscape.
This role combines enterprise governance (standards, frameworks, and compliance)
with solution-level delivery support, enabling secure-by-design outcomes across
projects while ensuring all security architecture decisions deliver tangible business
value through risk reduction, compliance assurance, and operational resilience.

• Define and maintain the enterprise security architecture, including reference architectures,
control frameworks, and technology standards across applications, infrastructure, integration,
and data domains.
• Establish and enforce secure-by-design principles and reusable security patterns for new
systems, platforms, and integrations.
• Embed security into the delivery lifecycle, ensuring DevSecOps adoption (automated testing,
policy-as-code, CI/CD integration).
• Lead implementation of the Zero-Trust model, covering identity, device, network, application,
and data layers.

• Collaborate with Cloud & Infrastructure Architects to ensure secure configurations, network
segmentation, and identity management across hybrid and multi-cloud environments (Azure,
OCI, on-prem).
• Partner with Data and Integration Architects to secure data flows, APIs, and event-driven
architectures.
• Define and maintain security baselines — encryption, secrets management, access control,
and key rotation policies.
• Conduct architecture and design reviews for major projects, ensuring alignment with
enterprise guardrails and regulatory obligations.
• Establish and track security metrics and KPIs, including control coverage, vulnerability
remediation rates, and compliance posture.
• Provide leadership for incident-response architecture, ensuring resilience, containment, and
recovery capabilities are built into designs.
• Engage with business stakeholders to balance risk appetite with operational needs, ensuring
that security remains an enabler of business agility.

Qualifications:

• Bachelor’s degree in Cybersecurity, Computer Science, or related discipline.
• 8–10 years’ experience in enterprise or solution security architecture,
preferably within large, regulated, or asset-heavy environments (oil & gas,
energy, or engineering).
• Strong understanding of security architecture frameworks and standards,
including:
o NIST CSF, ISO 27001, CIS Benchmarks, SABSA, TOGAF Security, or
Zero-Trust Architecture (ZTA).
• Certified in one or more of:
o CISSP (Certified Information Systems Security Professional)
o SABSA Chartered Security Architect
o Microsoft Certified: Cybersecurity Architect Expert
o Certified Cloud Security Professional (CCSP)
o GIAC Cloud Security Automation (GCSA) (desirable)
• Hands-on experience securing Microsoft Azure and Oracle Cloud
Infrastructure (OCI) environments, including identity, networking, and
workload protection.
• Experience implementing DevSecOps pipelines and automation, using:
o SAST/DAST/IAST/SCA tools (e.g., SonarQube, Checkmarx, OWASP
ZAP, Fortify)
o IaC security scanning (Terraform Sentinel, Checkov, Azure Policy,
Defender for Cloud)
o Container and pipeline security (Aqua, Prisma, GitHub Advanced
Security, Defender for Containers)
• Strong understanding of Identity & Access Management (Entra ID, MFA,
Conditional Access, PAM) and encryption/key management (Azure Key
Vault, OCI Vault).
• Knowledge of SIEM, SOAR, and XDR platforms (Sentinel, Splunk, Defender
XDR) and how architecture supports detection and response.
• Experience using Enterprise Architecture repositories (Orbus Infinity, LeanIX,
Sparx EA) and proficiency with ArchiMate or UML for documenting security
models and dependencies.
• Familiarity with compliance and regulatory frameworks (GDPR, NCA,
ADHICS, ISO 27001 certification) and their application to cloud and
enterprise systems.

#LI-HS1

Previous Job Searches

My Profile

Create and manage profiles for future opportunities.

Go to Profile

My Submissions

Track your opportunities.

My Submissions