IT service delivery

SmartSuite for the Security Architect

The Security Architect designs the security controls, patterns and reference architectures that systems must follow, reviews solutions and changes against them, and advises on risk treatment. They translate policy and framework requirements into technical standards engineers can build to.

What you own

  • Define security architecture principles, patterns and reference designs
  • Review solution designs, changes and vendors against security standards
  • Translate framework and policy requirements into technical controls
  • Lead threat modelling and architecture risk assessments
  • Advise on identity, network, cloud and data protection design
  • Track architecture exceptions and remediation roadmaps
  • Keep standards current with emerging threats and technologies

Where the role sits

Each name opens that role's page.

Reports to

Chief Information Security Officer

Chief Information Security Officer

See the role
Chief Technology Officer

Chief Technology Officer

See the role

Direct reports

Works closely with

Security Analyst

Security Analyst

See the role
IT Compliance Manager

IT Compliance Manager

See the role
IT Risk Manager

IT Risk Manager

See the role
Engineering Manager

Engineering Manager

See the role
Change and Release Manager

Change and Release Manager

See the role
DevOps Engineer

DevOps Engineer

See the role

GRC processes

The shared GRC process map, highlighted for this role.

Owns

accountable for the process

Touches

contributes or approves

Depends on

consumes its output

How SmartSuite helps, suite by suite

Each card is the persona record from that suite's Users tab.

How they use SmartSuite

Suites that serve this role

How SmartSuite supports this role

Security. Holds the security standards and reference patterns and tracks architecture exceptions with owners, expiry dates and remediation roadmaps.

Change. Routes solution designs and significant changes through security review with findings recorded against the change.

Asset config. Uses the CMDB and asset register to scope reviews and map controls to systems.

Monitoring event. Links threat modelling outputs to the vulnerabilities and detections that monitor them.

Reporting. Reports review throughput, open exceptions and control coverage by system to the CISO.

Industry reference

NIST SP 800-160 Vol. 1 (systems security engineering), SABSA and the (ISC)2 CISSP architecture domain describe the discipline; ISO/IEC 27001:2022 Annex A 8.27 requires secure system architecture and engineering principles. NIST SP 800-207 defines zero trust architecture, now expected across US federal systems. Sector frameworks set the control baselines the architect designs to: NIST SP 800-53 and FedRAMP, PCI DSS network segmentation, HIPAA technical safeguards, NYDFS and FFIEC requirements in financial services, and DORA and NIS2 in the EU.

In their words

Related roles

Chief Information Security Officer

Chief Information Security Officer

See the role
Chief Technology Officer

Chief Technology Officer

See the role

See SmartSuite for your role

Start a free trial, or book a demo and we will walk through your role's workflows in SmartSuite.