About Citco:
Armed with superior services, smart people, and strong technology, we tackle our customers’ complicated challenges by developing sophisticated solutions driven directly by their demands. The result? Innovation that generates tangible value and makes a real difference for our clients and their companies.
I. POSITION DESCRIPTION:
This position calls for an IT Security Architect with extensive experience in enterprise security architecture, secure solution design, and strategic technology planning. As a key member of Citco's IT Security organization, the IT Security Architect is responsible for translating business, regulatory, and risk requirements into secure, scalable, and technology-agnostic architecture designs that support the firm's global business objectives.
The IT Security Architect serves as the technical authority for security architecture, developing enterprise security standards, reference architectures, and design patterns while providing strategic guidance to technology teams throughout the solution lifecycle. This role collaborates closely with Enterprise Architecture, Infrastructure, Cloud Services, Application Development, and Security Operations to ensure security is embedded into technology initiatives and aligned with Citco's overall security strategy.
II. ORGANIZATIONAL RELATIONS:
This position is part of the IT Security group, which oversees global cybersecurity strategy, governance, architecture, engineering, and operational security capabilities across Citco's technology environment.
III. PRINCIPAL ACCOUNTABILITIES:
Develop, maintain, and evolve the enterprise security architecture roadmap aligned with business objectives, technology strategy, and risk management priorities.
Define target-state security architectures that support enterprise transformation, cloud adoption, and digital modernization initiatives.
Produce high-level and conceptual security architecture designs for major technology initiatives, ensuring security requirements are incorporated from project inception.
Develop and maintain enterprise security reference architectures, design standards, and reusable security patterns across network, cloud, application, data, endpoint, and identity domains.
Define security control requirements, integration patterns, and architectural principles that promote consistency and scalability across the enterprise.
Review proposed technology solutions and participate in architecture review boards to ensure alignment with enterprise security standards and regulatory requirements.
Provide architectural guidance and technical consultation to project teams, solution architects, and engineering teams throughout the project lifecycle.
Evaluate emerging technologies, industry trends, and evolving cyber threats to recommend improvements to Citco's security architecture and technology strategy.
Assess new security technologies and provide technical recommendations to support vendor selection and strategic investment decisions.
Collaborate with Enterprise Architecture, Infrastructure, Cloud Services, Application Development, Risk, and Security Operations teams to ensure secure solution delivery.
Provide architectural oversight during solution implementation to ensure adherence to approved security designs, standards, and governance requirements.
Participate in major security incidents by providing architectural expertise, assessing enterprise impacts, and recommending strategic remediation approaches.
Conduct post-implementation architecture reviews and identify opportunities for continuous improvement and architectural optimization.
Develop and maintain key security architecture deliverables, including enterprise security blueprints, reference architecture, design standards, technology roadmaps, and architecture decision records.
Stay current with industry best practices, emerging technologies, regulatory requirements, and evolving security frameworks to continuously enhance Citco's security architecture capability.
IV. EDUCATION, EXPERIENCE & SKILLS:
8+ years of experience in information security, enterprise architecture, security engineering, or related technology disciplines, including significant experience in security architecture.
Demonstrated experience designing enterprise security architectures across hybrid infrastructure, cloud, network, application, identity, and data security domains.
Strong understanding of enterprise architecture principles, secure design methodologies, and security-by-design concepts.
Experience developing security reference architectures, architecture standards, technology roadmaps, and design governance processes.
Strong knowledge of cloud security architecture, zero trust principles, identity and access management, network security, application security, data protection, and infrastructure security.
Experience integrating security requirements into enterprise technology projects and collaborating with cross-functional architecture and engineering teams.
Knowledge of security risk management, regulatory compliance, and industry security frameworks such as NIST Cybersecurity Framework, ISO 27001, CIS Controls, and Zero Trust Architecture principles.
Ability to evaluate emerging technologies and assess their security implications within complex enterprise environments.
Excellent analytical, strategic thinking, and problem-solving skills with the ability to balance business objectives, security requirements, and operational considerations.
Strong verbal and written communication skills with the ability to present architectural concepts to both technical and executive stakeholders.
Demonstrated ability to influence architectural decisions and build consensus across multiple technology and business teams.
Preferred certifications include CISSP, Certified Cloud Security Professional (CCSP), SABSA Chartered Foundation or Practitioner, TOGAF, GIAC certifications, Microsoft Cybersecurity Architect Expert, or equivalent industry certifications.