Expert knowledge of cybersecurity architecture frameworks, control frameworks, and security standards such as NIST CSF, NIST 800-53, ISO 27001, CIS Controls, SABSA, zero trust, secure SDLC, threat modeling, and risk-based architecture decisioning.
Expert knowledge of modern security architecture patterns across AWS cloud services, SaaS, IaaS, PaaS, microservices, APIs, identity and access management, privileged access, encryption, key management, secrets management, event-driven architecture, data protection, and security analytics; relevant certifications may include CISSP, CCSP, CISM, SABSA, TOGAF, AWS/Azure security certifications, or similar credentials.
Expert knowledge of business, operating, risk, and financial models—including cost-benefit analysis, cyber risk quantification, and risk management—with proven ability to set cybersecurity architecture direction, create security roadmaps, and govern current and target state at the enterprise level.
Proven ability to assess cyber threat trends, attack surface exposure, emerging technologies, and regulatory drivers; author executive position papers identifying strategic cyber risks, opportunities, and recommended investments.
Proven ability to lead cross-functional teams across cybersecurity, infrastructure, engineering, applications, cloud, data, risk, privacy, and compliance; develop and mentor architects at all levels through coaching and delegation.
Recognized thought leader in cybersecurity architecture with a track record of influencing enterprise security strategy, reducing systemic cyber risk, enabling secure business transformation, and advising C-suite stakeholders on cybersecurity investment decisions.
Experience in DevSecOps, Agile technology environments, threat modeling, secure SDLC, cloud security architecture, AI/GenAI security, cyber risk quantification, and related advanced security practices preferred.