A Security Architect is responsible for evaluating vendors' cybersecurity practices to identify risks, ensure compliance with standards, review security documentation, and recommend mitigations. They collaborate with stakeholders, monitor third-party activities, and report on risk status.
The ideal candidate must have experience in third-party risk management, cloud security (AWS, Azure, GCP), and on-premise software security, along with strong knowledge of security frameworks, vendor risk assessment methodologies, IAM, data protection, and secure software integration.
* Conduct security assessments, including vendor risk management and due diligence.
* Assess third-party cloud services and on-premise software for security risks and compliance.
* Provide security recommendations for selection, implementation, and management of third-party solutions.
* Collaborate with procurement, IT, and security teams to enforce security policies in third party contracts
* Monitor and respond to emerging threats in third-party integrations.
* Align security practices with industry frameworks (NIST, ISO 27001, SOC 2, etc.).
1. 5+ years of experience in cyber security
2. Knowledge of security frameworks(ISO 27001, SOC2, PCI DSS, NIST, etc)
3.Cloud Security(AWS, Azure, GCP)
4. Relevant certifications (CISSP, CISM, CCSP, CTPRP)