Origen

Position Overview


We are seeking an experienced and pragmatic Security Architect to design and implement secure, scalable, and compliant security architectures for enterprise systems and cloud environments. This role will embed security throughout the technology lifecycle (Security by Design), ensuring solutions meet business, customer, and regulatory requirements.
The ideal candidate combines strong expertise in cloud and application security with practical risk management capabilities, acting as a trusted security advisor to engineering and business teams while enabling the delivery of secure and reliable technology solutions across the UAE and international markets.

Key Responsibilities


1. Design security architecture for medium- and large-scale software systems, embedding security requirements throughout the entire software development lifecycle (Security by Design), and produce security architecture solutions, standards, and technical specifications.
2. Design and manage security architecture for cloud environments, including Identity and Access Management (IAM), network segmentation and isolation, encryption and key management, logging, auditing, and threat detection.
3. Design data security solutions, including data classification, encryption for data in transit and at rest, and compliance for data localization and cross-border data transfers.
4. Conduct threat modeling and security architecture reviews, identify security risks at both architecture and code levels, and develop practical mitigation and hardening solutions.
5. Lead security compliance activities during project delivery by mapping security controls to customer and regulatory requirements, performing gap assessments, and preparing audit documentation.
6. Support vulnerability management and security incident response by establishing related processes and incident response plans.

Candidate Profile


1. Bachelor's degree in Information Security, Computer Science, Cybersecurity, or a related field.
2. Minimum of 5 years of experience in information security, with proven ability to independently design security architectures for medium- to large-scale systems.
3. Strong knowledge of public cloud security architecture and configuration management (Azure preferred; AWS and/or GCP also acceptable), including IAM, Zero Trust, network security, encryption and key management, and cloud-native security monitoring.
4. Solid understanding of common cybersecurity threats and defense mechanisms, with hands-on experience in threat modeling, security design reviews, and OWASP security practices.
5. Familiarity with leading information security standards and compliance frameworks such as ISO/IEC 27001, NIST Cybersecurity Framework (CSF), and CIS Controls, with the ability to translate security controls into practical technical implementations and adapt to regional regulatory and customer compliance requirements.
6. Excellent technical documentation, communication, and stakeholder management skills, with the ability to collaborate effectively across engineering, operations, and customer security teams.
7. Proficiency in English as a working language.

Preferred Qualifications
1. Professional certifications such as CISSP, CISM, CCSP, AZ-500 (Microsoft Azure Security Engineer Associate), or equivalent.
2. Experience delivering security solutions for government, critical infrastructure, or smart city projects.
3. Familiarity with DevSecOps, Infrastructure as Code (IaC) security scanning, and SIEM/SOC operations.
4. Experience working on projects in the Middle East.