Hands-on experience with Enterprise Security Architecture methodologies and modern security technologies, including IAM, SIEM, EDR/XDR, WAF, SASE, Zero Trust, cloud security, and security automation tools.
Strong knowledge of IT infrastructure security, including network security, cloud security, endpoint security, identity security, and secure architecture design principles.
Strong knowledge of application security, including secure SDLC, DevSecOps, API security, secure coding practices, and application threat modeling.
Experience implementing, validating, and reviewing security controls across IT infrastructure, cloud platforms such as AWS, Azure, and GCP, and enterprise applications.
Experience developing, maintaining, and enhancing security control libraries, security patterns, baselines, and architecture standards, while ensuring their integration into security architecture and engineering activities.
Strong understanding of cybersecurity standards, laws, and frameworks, including NIST, ISO/IEC 27001, CIS Controls, GDPR, PCI-DSS, and other relevant regulatory or compliance requirements.
Strong understanding of cybersecurity best practices, including secure network architecture, endpoint protection, identity and access management, cloud security, DevSecOps, and defense-in-depth design.
Experience conducting security design reviews, architecture assessments, threat modeling, technical risk assessments, and security gap assessments.
Ability to support business units, project teams, IT teams, and security stakeholders in selecting, designing, and implementing secure information systems and technology solutions.
Experience with security automation and scripting using tools and languages such as Python, PowerShell, Bash, Terraform, Ansible, or similar technologies.
Ability to support security investigations, incident response activities, forensic analysis, root cause analysis, and post-incident improvement recommendations when required.
Experience providing technical consultation and advisory support on CSEA-related projects, initiatives, and engagements as requested by the CSEA Section Head.
Excellent ability to translate technical cybersecurity concepts, risks, and recommendations into clear business language for both technical and non-technical stakeholders.
Experience participating in cybersecurity committees, technical working groups, architecture review boards, project meetings, and cross-functional security discussions.
Strong problem-solving, analytical, and decision-support skills, with the ability to assess complex technical environments and recommend practical security solutions.
Ability to work independently while also collaborating effectively with security architects, SOC analysts, IT teams, application teams, project managers, and business stakeholders.
Excellent verbal and written communication skills, with the ability to document security findings, architecture recommendations, risks, and remediation actions clearly and professionally.
Ability to mentor and support CSEA team members as needed by transferring knowledge, sharing technical expertise, and contributing to the development of internal cybersecurity engineering and architecture capabilities.