Enterprise Security Architect
Pink Immigration Pty LtdAbove Award
Listed 10 Sep 2026
Closes 12 Oct 2026
ENTERPRISE SECURITY ARCHITECT
Location: Perth, Western Australia (hybrid; some interstate travel)
Engagement: Full-time permanent, or fixed-term contract
Reports to: Chief Information Security Officer / Head of Technology
Role Type: Fulltime
Accelerate Workforce Solutions is looking for a senior Enterprise Security Architect.
Purpose of the role
The Enterprise Security Architect owns the target-state security design for the organisation's technology estate and holds design authority over the changes that move it there. The role sits between the security function and delivery: translating risk appetite and regulatory obligation into buildable patterns, and translating technical exposure into terms the CIO, CFO and board can act on.
This is a hands-on architecture role with governance weight, not a review-and-comment position. The successful candidate will produce designs, defend them at architecture boards, and stay engaged through delivery.
KEY RESPONSIBILITIES
Architecture and design authority
• Define and maintain the enterprise security architecture across on-premise, cloud (AWS and Azure) and operational technology environments
• Act as security design authority for major programs — approving designs, setting review gates, and holding delivery teams to the agreed pattern
• Produce reusable security patterns rather than one-off designs, and drive their adoption across delivery teams
OT/IT convergence
• Design and govern the OT/IT boundary for industrial, utility and building systems
• Set security requirements for OT vendors and hold them to contract, including where product-level security uplift is not contractually guaranteed
• Establish monitoring and segmentation approaches appropriate to availability-critical environments
Cloud and platform security
• Own cloud security architecture, control alignment and SIEM-integrated compliance reporting
• Build secured release approval into delivery processes so that assurance is evidenced rather than asserted
• Review third-party and SaaS deployments for control gaps against internal and regulatory obligations
Identity and privileged access
• Set IAM and PAM strategy: standing-privilege reduction, non-human and machine identity, RBAC/ABAC modelling, federation
• Govern remediation of legacy directory estates and brokered production access
Governance, risk and regulatory
• Align the control framework to recognised standards and map it against applicable obligations — SOCI, CPS 230, ISO 27001, Essential Eight, PCI DSS, and privacy legislation
• Support operational resilience work: business impact analysis, business-aligned RTO/RPO setting, and BCP/DR design
• Prepare architecture evidence for internal audit and regulator engagement
Emerging risk
• Establish AI governance and security-for-AI controls folded into existing governance structures rather than run in parallel, including agentic and non-human identity exposure
• Lead post-quantum readiness: cryptographic bill of materials, harvest-now-decrypt-later channel prioritisation, and cryptographic agility as the target state
Stakeholder and uplift
• Present architecture positions and risk trade-offs to executive and board audiences
• Mentor security engineers and consultants toward trusted-advisor standing with business stakeholders
ESSENTIAL SKILL AND EXPERIENCE
• Substantial enterprise security architecture experience across large, complex or regulated estates, including at least one critical-infrastructure, utility, financial services or equivalent environment
• Demonstrated design authority over a major program — able to evidence designs owned end to end, not contributed to
• Practical OT security experience and a working understanding of why availability-first environments resist IT security patterns
• Cloud security architecture across at least one major hyperscaler, with control mapping and automated compliance reporting
• Identity and privileged access design at enterprise scale (CyberArk, SailPoint or comparable)
• Fluency in translating between technical control detail and executive risk language, with board or regulator exposure
• Working knowledge of the Australian regulatory environment — SOCI, CPS 230, Essential Eight — and ideally comparative experience of an equivalent overseas regime
CERTIFICATIONS
Required: CISSP or equivalent senior security certification
Desirable: CCSP, SABSA, TOGAF, cloud-native security certifications, AI governance credentials such as TAISE
DESIRABLE
• CISO or interim CISO experience, or having stood up a security function from low maturity
• Operational resilience methodology design (DORA, PRA/FCA, or CPS 230 response)
• Incident leadership at P1 severity
• Consulting or client-facing delivery b
AWS is only looking for very experienced people with over 15+ years' experience, Please only apply if you can meet all selection criteria in skills and experience. No time wasters please.