Job Summary
The Enterprise Security Architecture Reviewer (ESAR) is a governance-focused role responsible for evaluating and validating security architecture designs across enterprise IT initiatives. This position ensures alignment with organizational security standards, regulatory frameworks, and strategic goals by participating in the Security Architecture Review Board (SARB) and conducting detailed assessments of proposed solutions.
Key Responsibilities
- Architecture Review & Validation: Evaluate solution architectures submitted for review, ensuring they meet enterprise security standards, regulatory compliance, and SARB guidelines. - Governance Participation: Actively contribute to SARB proceedings, offering technical recommendations and risk assessments for new applications, infrastructure, and integrations. - Documentation & Reporting: Maintain detailed records of review outcomes, including approval status, conditional recommendations, and follow-up actions. Ensure traceability of decisions and alignment with ESA process qualifiers. - Stakeholder Engagement: Collaborate with business owners, solution architects, and SMEs to clarify requirements, assess risks, and guide remediation efforts. Provide feedback on architecture submissions and ensure completeness of review artifacts. - Security Controls Assessment: Review and validate implementation of security controls such as encryption, authentication, access management, logging, and incident response mechanisms. - Tool & Platform Evaluation: Assess third-party tools and platforms for compliance with enterprise
Skill Requirements
- Bachelor's or Master's degree in Information Security, Computer Science, or related field. - Certifications such as CISSP, CISM, TOGAF, or CCSK preferred. - Strong understanding of enterprise security architecture frameworks, SARB processes, and regulatory standards (e.g., SOC2, ISO 27017). - Experience with architecture review workflows, technical risk assessments, and secure design principles. - Familiarity with cloud platforms (Azure, AWS), Power Apps, and integration mechanisms (API, AD, MFA). - Excellent communication and documentation skills. PREFERRED EXPERIENCE - Prior participation in SARB or similar architecture governance bodies. - Experience reviewing architecture for internal portals, SaaS platforms, and enterprise applications.