Lead – Enterprise Security Architect

Full Time
  • Full Time
  • Sharjah - United Arab Emirates
  • 8–10 years’ experience in enterprise or solution security architecture, preferably within large, regulated, or asset-heavy environments (oil & gas, energy, or engineering).

Website Petrofac

Petrofac is a provider of oilfield services to the international oil and gas industry. It is registered in Jersey (number 81792), with its main corporate office on Jermyn Street, London. It has operational centres in Aberdeen, Sharjah, Woking, Chennai, Mumbai, Delhi, Abu Dhabi, Saudi Arabia and Kuala Lumpur. There are another 24 offices in various countries. It is quoted on the London Stock Exchange, and is a constituent of the FTSE 250 Index.

Lead – Enterprise Security Architect

Full – Job Description

ROLE PURPOSE

The Enterprise Security Architect defines and governs the organisation’s security
architecture strategy, ensuring that all enterprise and solution designs are secure,
compliant, and resilient by design.
The role provides both strategic leadership and hands-on architectural guidance,
embedding security principles, controls, and automation into every aspect of
Petrofac’s hybrid and multi-cloud environment — covering applications, data,
infrastructure, and integration layers.
Acting as the bridge between cybersecurity governance and technology delivery,
the Security Architect defines security reference architectures, policies, and
standards, ensuring these are implemented through modern DevSecOps practices,
zero-trust models, and continuous compliance automation.
Working closely with Cloud, Data, and Integration Architects to design secure
platforms and data flows — and with Solution and Technical Architects to embed
secure patterns into projects — the Security Architect ensures consistent and
measurable security across the enterprise technology landscape.
This role combines enterprise governance (standards, frameworks, and compliance)
with solution-level delivery support, enabling secure-by-design outcomes across
projects while ensuring all security architecture decisions deliver tangible business
value through risk reduction, compliance assurance, and operational resilience.

  • Define and maintain the enterprise security architecture, including reference architectures,
    control frameworks, and technology standards across applications, infrastructure, integration,
    and data domains.
    • Establish and enforce secure-by-design principles and reusable security patterns for new
    systems, platforms, and integrations.
    • Embed security into the delivery lifecycle, ensuring DevSecOps adoption (automated testing,
    policy-as-code, CI/CD integration).
    • Lead implementation of the Zero-Trust model, covering identity, device, network, application,
    and data layers.
  • Collaborate with Cloud & Infrastructure Architects to ensure secure configurations, network
    segmentation, and identity management across hybrid and multi-cloud environments (Azure,
    OCI, on-prem).
    • Partner with Data and Integration Architects to secure data flows, APIs, and event-driven
    architectures.
    • Define and maintain security baselines — encryption, secrets management, access control,
    and key rotation policies.
    • Conduct architecture and design reviews for major projects, ensuring alignment with
    enterprise guardrails and regulatory obligations.
    • Establish and track security metrics and KPIs, including control coverage, vulnerability
    remediation rates, and compliance posture.
    • Provide leadership for incident-response architecture, ensuring resilience, containment, and
    recovery capabilities are built into designs.
    • Engage with business stakeholders to balance risk appetite with operational needs, ensuring
    that security remains an enabler of business agility.

Qualifications:

  • Bachelor’s degree in Cybersecurity, Computer Science, or related discipline.
    • 8–10 years’ experience in enterprise or solution security architecture,
    preferably within large, regulated, or asset-heavy environments (oil & gas,
    energy, or engineering).
    • Strong understanding of security architecture frameworks and standards,
    including:
    o NIST CSF, ISO 27001, CIS Benchmarks, SABSA, TOGAF Security, or
    Zero-Trust Architecture (ZTA).
    • Certified in one or more of:
    o CISSP (Certified Information Systems Security Professional)
    o SABSA Chartered Security Architect
    o Microsoft Certified: Cybersecurity Architect Expert
    o Certified Cloud Security Professional (CCSP)
    o GIAC Cloud Security Automation (GCSA) (desirable)
    • Hands-on experience securing Microsoft Azure and Oracle Cloud
    Infrastructure (OCI) environments, including identity, networking, and
    workload protection.
    • Experience implementing DevSecOps pipelines and automation, using:
    o SAST/DAST/IAST/SCA tools (e.g., SonarQube, Checkmarx, OWASP
    ZAP, Fortify)
    o IaC security scanning (Terraform Sentinel, Checkov, Azure Policy,
    Defender for Cloud)
    o Container and pipeline security (Aqua, Prisma, GitHub Advanced
    Security, Defender for Containers)
    • Strong understanding of Identity & Access Management (Entra ID, MFA,
    Conditional Access, PAM) and encryption/key management (Azure Key
    Vault, OCI Vault).
    • Knowledge of SIEM, SOAR, and XDR platforms (Sentinel, Splunk, Defender
    XDR) and how architecture supports detection and response.
    • Experience using Enterprise Architecture repositories (Orbus Infinity, LeanIX,
    Sparx EA) and proficiency with ArchiMate or UML for documenting security
    models and dependencies.
    • Familiarity with compliance and regulatory frameworks (GDPR, NCA,
    ADHICS, ISO 27001 certification) and their application to cloud and
    enterprise systems.

#LI-HS1

To apply for this job please visit petrofac.referrals.selectminds.com.