Roles & Responsibilities Define and implement enterprise cybersecurity architecture, Strategy across applications, infrastructure, cloud, network, and data domains. Align security policies with business objectives and regulatory requirements. Conduct security architecture reviews for new systems and enhancements to ensure secure-by-design implementation. Lead threat modelling, risk assessments, and security design evaluations for critical business applications. Establish and enforce security standards, policies, and frameworks aligned with ISO 27001, NIST, and industry best practices. Conducted security assessments and audits of cloud platforms. Identify and mitigate risks, vulnerabilities, and threats Design secure cloud infrastructures and applications using best practices (e.g.M365 /Azure Security Best Practices). Architect secure integration between on-premises systems and cloud environments. Implementation of cloud security controls (IAM, encryption, network security) Provide expertise on Data Security, Application security, DevSecOps, API security, and Secure SDLC practices. Oversee identity and access management architecture, including SSO, MFA, privileged access, and Zero Trust principles. Collaborate with internal teams and external vendors to ensure secure integration and compliance. Working effectively with various technology COEs, Technology Heads, and other resolver groups. Advanced Threat Protection & Threat Hunting. Secure Score recommendation Support regulatory compliance, audits, and governance requirements. Provide technical leadership and advisory to stakeholders on cybersecurity risks and mitigation strategies. Must Have Must have hands-on experience in SIEM & SOAR : Splunk , Microsoft Sentinel Must have hands-on experience in XDR & EDR : Cortex XDR , Tanium , Microsoft Defender for Endpoint (MDE) Must have hands-on experience in VMDR (Vulnerability Management, Detection & Response) : Tenable , Qualys Must have hands-on experience in Identity and Access Management (IAM) : Microsoft Entra ID , SailPoint Must have hands-on experience in Privileged Access Management (PAM) : CyberArk Must have hands-on experience in Network Security : Palo Alto Networks , Zscaler Internet Access (ZIA) Must have hands-on experience in Cloud Security : Microsoft Defender for Cloud (Azure Defender for Cloud) , Azure Cloud Security Controls and Monitoring Good to have Good-to-have hands-on experience in Data Loss Prevention (DLP) : Microsoft Purview , FortiGate DLP Good-to-have hands-on experience in Privileged Access Management (PAM) : CyberArk Good-to-have hands-on experience in Web Application Firewall (WAF) : Azure Web Application Firewall (Azure WAF) , Imperva WAF , AWS Shield