The Manager, Security Architecture & Assurance plays a critical role in overseeing the security architecture review and assurance processes across various technology projects, platforms, and strategic initiatives. This position ensures that security risks are identified and mitigated early in the solution lifecycle, aligning all technology investments with the organization’s security policies, architectural standards, regulatory requirements, and risk appetite. The role involves managing the end-to-end security review and approval process for cloud, applications, infrastructure, data, and third-party solutions. Acting as a trusted advisor, the Manager collaborates closely with technology and business stakeholders, providing security oversight, defining security requirements, and leading a team of security architects and analysts responsible for assessments and design reviews.
Key Responsibilities
- Lead security architecture reviews for projects, programs, and technology initiatives, ensuring security requirements are embedded from inception through implementation.
- Establish and maintain security architecture standards, reference architectures, and secure design principles.
- Provide formal security approval and sign-off for projects that meet the required security standards.
- Oversee security risk assessments across cloud, data center, network, application, and digital environments.
- Review and challenge technology designs to identify security risks, vulnerabilities, and control gaps.
- Evaluate risk mitigation plans and determine residual risk exposure, supporting risk acceptance decisions.
- Present security recommendations to governance forums and escalate significant risks to senior management when necessary.
- Manage and mentor a team of Security Architects and Security Assurance professionals, defining team objectives, performance measures, and development plans.
- Build team capability in cloud security, application security, threat modeling, and security architecture disciplines.
- Foster a collaborative, security-by-design culture throughout the organization.
- Define and manage the project security review methodology, participating in Architecture Review Boards, Design Authorities, and Change Advisory Boards.
- Ensure consistent application of security controls, security patterns, and design standards.
- Track security findings and ensure remediation activities are completed prior to production deployment.
- Partner with IT Architecture, Infrastructure, Data, Development, Engineering, and Delivery teams to provide expert security advice.
- Influence technical and business decisions through risk-based recommendations.
- Ensure compliance with frameworks and standards such as ISO 27001, NIST Cybersecurity Framework, NIST SP 800-53, CIS Controls, SABSA, OWASP, and COBIT.
- Support internal and external audit activities and maintain evidence of security review and approval processes.
Required Qualifications
- Over 10 years of experience in information security, technology architecture, or cybersecurity.
- At least 5 years of experience leading security architecture, security assurance, or technology risk functions.
- Proven experience managing security reviews for large-scale projects and technology transformations.
- Hands-on experience with cloud security across AWS, Azure, and Google Cloud Platform environments.
- Strong understanding of Artificial Intelligence security, network, infrastructure, data, application, and identity security.
Preferred Qualifications
- Professional certifications such as CISSP, CISM, CCSP, SABSA, TOGAF, CRISC, or ISO 27001 Lead Implementer/Lead Auditor are highly desirable.
This role offers the opportunity to lead security architecture governance in a dynamic environment, working alongside diverse teams to embed security best practices and drive risk-aware decision-making across the organization.