About the job
Job Title: Information Security Architect
Contract Duration: Initial 6-month contract
Preferred Candidates: EEE candidates
The Head of Security Architecture at Infystrat is tasked with architecting, implementing, and maintaining security frameworks that safeguard sensitive data while adhering to regulations such as POPIA and GDPR. This pivotal role is essential for ensuring the confidentiality, integrity, and availability of electronic health records (EHR), as well as safeguarding patient and employee information, medical devices, and cloud-based healthcare services. The focus will be on creating and evolving security architectures that align with both business objectives and corporate security strategies. You will work collaboratively with Security Architects, IT teams, and Engineers to develop security controls and solutions that comply with established enterprise architecture frameworks and standards.
Key Responsibilities:
- Develop and design intricate security architectures for systems, applications, and infrastructure considering both present and future requirements.
- Collaborate with stakeholders, including developers, engineers, and project managers, to incorporate security needs into the system design and development lifecycle.
- Provide guidance on secure coding practices, network security, identity and access management, data protection, and other security domains.
- Model potential threats and risks, designing controls to mitigate them at both organizational and technical levels, employing an attacker's mindset to anticipate possible hacking strategies.
- Conduct architecture analysis through research, validation, and evaluation of new initiatives, presenting phase gate reviews to stakeholders during key forums, including discussions on current trends like AI and LLMS.
- Assess and choose security technologies, tools, and frameworks to enhance the organization’s security posture.
- Define a portfolio vision and reusable security patterns in alignment with the enterprise architecture strategy.
- Lead architecture reviews for high-risk projects, driving recommendations to resolution.
- Advise on security controls for hybrid and cloud environments, balancing usability, cost, and compliance.
- Establish and apply security policies, standards, and procedures to ensure compliance with industry regulations and best practices.
- Oversee incident response activities, including identification, containment, eradication, and recovery, in partnership with the incident response team.
- Experience with cloud security platforms and technologies such as Azure and AWS.
- Supervise security architects and mentor engineers to foster their growth and development.

