Enterprise Security Architect

Pink Immigration Pty Ltd
PERTH WA 6000Full time

Above Award

Listed 10 Sep 2026

Closes 12 Oct 2026

ENTERPRISE SECURITY ARCHITECT Location: Perth, Western Australia (hybrid; some interstate travel) Engagement: Full-time permanent, or fixed-term contract Reports to: Chief Information Security Officer / Head of Technology Role Type: Fulltime Accelerate Workforce Solutions is looking for a senior Enterprise Security Architect. Purpose of the role The Enterprise Security Architect owns the target-state security design for the organisation's technology estate and holds design authority over the changes that move it there. The role sits between the security function and delivery: translating risk appetite and regulatory obligation into buildable patterns, and translating technical exposure into terms the CIO, CFO and board can act on. This is a hands-on architecture role with governance weight, not a review-and-comment position. The successful candidate will produce designs, defend them at architecture boards, and stay engaged through delivery. KEY RESPONSIBILITIES Architecture and design authority • Define and maintain the enterprise security architecture across on-premise, cloud (AWS and Azure) and operational technology environments • Act as security design authority for major programs — approving designs, setting review gates, and holding delivery teams to the agreed pattern • Produce reusable security patterns rather than one-off designs, and drive their adoption across delivery teams OT/IT convergence • Design and govern the OT/IT boundary for industrial, utility and building systems • Set security requirements for OT vendors and hold them to contract, including where product-level security uplift is not contractually guaranteed • Establish monitoring and segmentation approaches appropriate to availability-critical environments Cloud and platform security • Own cloud security architecture, control alignment and SIEM-integrated compliance reporting • Build secured release approval into delivery processes so that assurance is evidenced rather than asserted • Review third-party and SaaS deployments for control gaps against internal and regulatory obligations Identity and privileged access • Set IAM and PAM strategy: standing-privilege reduction, non-human and machine identity, RBAC/ABAC modelling, federation • Govern remediation of legacy directory estates and brokered production access Governance, risk and regulatory • Align the control framework to recognised standards and map it against applicable obligations — SOCI, CPS 230, ISO 27001, Essential Eight, PCI DSS, and privacy legislation • Support operational resilience work: business impact analysis, business-aligned RTO/RPO setting, and BCP/DR design • Prepare architecture evidence for internal audit and regulator engagement Emerging risk • Establish AI governance and security-for-AI controls folded into existing governance structures rather than run in parallel, including agentic and non-human identity exposure • Lead post-quantum readiness: cryptographic bill of materials, harvest-now-decrypt-later channel prioritisation, and cryptographic agility as the target state Stakeholder and uplift • Present architecture positions and risk trade-offs to executive and board audiences • Mentor security engineers and consultants toward trusted-advisor standing with business stakeholders ESSENTIAL SKILL AND EXPERIENCE • Substantial enterprise security architecture experience across large, complex or regulated estates, including at least one critical-infrastructure, utility, financial services or equivalent environment • Demonstrated design authority over a major program — able to evidence designs owned end to end, not contributed to • Practical OT security experience and a working understanding of why availability-first environments resist IT security patterns • Cloud security architecture across at least one major hyperscaler, with control mapping and automated compliance reporting • Identity and privileged access design at enterprise scale (CyberArk, SailPoint or comparable) • Fluency in translating between technical control detail and executive risk language, with board or regulator exposure • Working knowledge of the Australian regulatory environment — SOCI, CPS 230, Essential Eight — and ideally comparative experience of an equivalent overseas regime CERTIFICATIONS Required: CISSP or equivalent senior security certification Desirable: CCSP, SABSA, TOGAF, cloud-native security certifications, AI governance credentials such as TAISE DESIRABLE • CISO or interim CISO experience, or having stood up a security function from low maturity • Operational resilience methodology design (DORA, PRA/FCA, or CPS 230 response) • Incident leadership at P1 severity • Consulting or client-facing delivery b AWS is only looking for very experienced people with over 15+ years' experience, Please only apply if you can meet all selection criteria in skills and experience. No time wasters please.