Job Responsibilities:
1- Security Architecture Design Ownership:
- Assist in the development and maintenance of security reference architectures, design patterns, standards, and technical baselines for applications, infrastructure, networks, and cloud services.
- Support security architecture reviews of new and changing systems, documenting risks, control gaps, and recommended mitigations.
- Contribute to the selection and specifications of security controls, ensuring alignment with the principles of defence-in-depth, least privilege, and zero trust.
- Prepare secure design documentation, architecture diagrams, data-flow diagrams, and control matrices for review by senior architects.
2- Threat Modelling & Security Risk Assessment:
- Participate in threat modelling exercises for applications and platforms, identifying attack surfaces, trust boundaries, and abuse cases.
- Support the assessment of design-level risks and map identified risks to appropriate treatment options and controls.
- Assist in evaluating the security implications of new technologies, integrations, and third-party services prior to adoption.
3- Regulatory, Standards & Assurance:
- Help ensure that solution designs comply with the CBE Cybersecurity Framework (EGY-FIN CSF), ISO/IEC 27001:2022, PCI DSS v4.0, and the Egyptian Personal Data Protection Law (Law 151/2020).
- Maintain traceability between security controls in designs and applicable regulatory and internal policy requirements.
- Support internal and external audit and assessment activities by providing architecture evidence and control documentation.
4- Engineering Enablement, Implementation & Mentoring:
- Work with engineering and infrastructure teams to translate approved security designs into implementable configurations and standards.
- Support proof-of-concept activities, secure configuration reviews, and validation testing of security controls.
- Assist in the evaluation of security tooling and platforms, contributing to technical assessments and vendor comparisons.
- Provide security advisory input to project teams throughout the technology delivery lifecycle.
Job Requirements:
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field from a reputable university.
- Minimum 6 years of relevant experience.
- Excellent communication skills.
- Good command of English.
Work Location: In person