A Great Opportunity for ...
Job Overview:
The Security Architect will shape security architecture across ATOM’s enterprise, telecom, digital, and customer-facing environments. The role may be appointed at Senior Manager or Manager level, depending on experience and capability. This senior role combines technical expertise with leadership, business judgment, financial understanding, and organizational influence. The Security Architect will define security strategies, principles, standards, target architectures, roadmaps, and operating models. The role will guide major investments and lead transformation from assessment through implementation and operational adoption. Key priorities include modernizing secure enterprise access; strengthening privileged and administrative access; improving certificate lifecycle management; enhancing Domain Name System security; and evaluating cloud-delivered, locally operated, managed, and hybrid security capabilities. The role will also assess managed security services and customer-facing offerings aligned with sovereignty, resilience, regulatory, operational, and commercial requirements.
Enterprise Security Architecture
- Define and maintain ATOM’s enterprise security architecture, principles, standards, reference designs, and multi-year roadmap.
- Develop target and transition architectures across identity, endpoint, network, infrastructure, cloud, applications, data, telecommunications, and customer services.
- Align decisions with business priorities, operational needs, regulatory obligations, technology strategy, availability, and customer impact.
- Review major initiatives and issue clear architecture decisions, requirements, risks, assumptions, and recommendations.
- Retain architecture accountability through implementation and operational handover.
Secure Enterprise Access
- Modernize access to enterprise applications, infrastructure, cloud services, telecommunications platforms, and administrative environments.
- Define coherent architecture for workforce, privileged, third-party, remote, and administrative access.
- Apply identity verification, device security, least privilege, contextual risk, session control, segmentation, and continuous policy enforcement.
- Evaluate cloud-delivered, locally operated, managed, and hybrid approaches without dependence on a specific vendor.
- Develop phased transitions that protect availability and continuity while improving user experience, resilience, sovereignty, efficiency, and cost.
Privileged and Administrative Access
- Define architecture for privileged identities, separate administrative accounts, controlled administration environments, session management, credential protection, and time-bound access.
- Establish secure access patterns for infrastructure, network, cloud, database, application, telecommunications, and third-party administrators.
- Promote approval-based elevation, credential rotation, session monitoring, emergency access, and protection of service and machine identities.
- Ensure controls are usable, resilient, supportable, auditable, and proportionate to criticality.
Certificate Lifecycle Management
- Define architecture and operating models for discovering, issuing, renewing, rotating, revoking, monitoring, and retiring digital certificates.
- Establish ownership and inventory across applications, websites, cloud workloads, network devices, telecommunications platforms, and machine identities.
- Reduce certificate-related outages and exposure through automation, monitoring, policy enforcement, and accountability.
- Define standards for certificate authorities, cryptography, key protection, validity, renewal, revocation, and emergency replacement.
Domain Name System Security
- Define security architecture for internal, external, authoritative, recursive, and cloud-hosted Domain Name System services.
- Establish controls for domain ownership, administrative access, unauthorized changes, abandoned records, misconfiguration, malicious resolution, tunneling, and abuse.
- Improve visibility and accountability for domain and subdomain changes across enterprise, digital, cloud, and telecommunications environments.
- Define resilience, recovery, monitoring, logging, segregation, and change-control requirements.
- Integrate Domain Name System security with asset management, threat monitoring, vulnerability management, and incident response.
- Assess Domain Name System protection as an internal capability and potential customer service.
Sovereign and Customer Security Services
- Assess locally operated managed security services aligned with sovereignty, resilience, regulatory, and customer requirements.
- Evaluate secure connectivity, internet protection, Domain Name System protection, and Home and Family Security services.
- Work across Product, Enterprise Business, Consumer Business, Network, Technology, Finance, Legal, Regulatory, Procurement, and Operations.
- Define service architecture, operating model, boundaries, responsibilities, support, service levels, and data-handling requirements.
- Determine which capabilities should operate locally and which may use strategic partners.
- Develop business cases covering demand, investment, operating cost, scalability, pricing, margin, partner dependency, and exit options.
- Lead controlled pilots before wider adoption or commercial launch.
Financial and Commercial Leadership
- Develop business cases for major security investments, including costs, resources, benefits, risks, and assumptions.
- Evaluate total cost of ownership across licensing, infrastructure, integration, migration, support, renewal, staffing, and exit costs.
- Compare options based on security, resilience, operational impact, financial value, sovereignty, and strategic flexibility.
- Support budgeting, investment prioritization, sourcing, vendor evaluation, negotiation, and contract review.
- Challenge proposals that do not align with ATOM’s architecture or long-term interests.
- Track whether investments deliver intended business, security, operational, and financial outcomes.
Stakeholder Engagement and Transformation
- Advise executives, business units, technology teams, and governance functions on security architecture.
- Build alignment among stakeholders with different priorities, budgets, accountabilities, and risk tolerances.
- Translate technical risks and decisions into clear business, financial, and operational language.
- Challenge assumptions respectfully, resolve disagreements constructively, and escalate significant decisions with clear options and impacts.
- Lead initiatives from assessment and business case through design, sourcing, implementation, migration, and operational acceptance.
- Define scope, responsibilities, dependencies, risks, milestones, outcomes, and success measures.
- Validate designs through technical assessment, testing, pilots, failure scenarios, and operational-readiness reviews.
- Ensure implemented capabilities have ownership, support, monitoring, documentation, lifecycle management, and funding.
Risk, Governance, and Capability Development
- Translate threats, architecture weaknesses, and technical debt into business and operational consequences.
- Provide risk-based recommendations considering criticality, exposure, data sensitivity, customer impact, and availability.
- Support exceptions with clear ownership, conditions, compensating controls, review dates, and closure requirements.
- Ensure architecture supports applicable legal, regulatory, contractual, and internal governance requirements.
- Use lessons from incidents, testing, assessments, audits, and operational failures to improve priorities.
- Maintain practical architecture governance and document significant decisions.
- Lead, mentor, and develop security architects and senior technical specialists.
- Use specialist partners where needed while retaining internal ownership of strategy and architecture decisions.