Petrofac
ROLE PURPOSE The Enterprise Security Architect defines and governs the organisation’s security architecture strategy, ensuring that all enterprise and solution designs are secure, compliant, and resilient by design. The role provides both strategic leadership and hands-on architectural guidance, embedding security principles, controls, and automation into every aspect of Petrofac’s hybrid and multi-cloud environment — covering applications, data, infrastructure, and integration layers. Acting as the bridge between cybersecurity governance and technology delivery, the Security Architect defines security reference architectures, policies, and standards, ensuring these are implemented through modern DevSecOps practices, zero-trust models, and continuous compliance automation. Working closely with Cloud, Data, and Integration Architects to design secure platforms and data flows — and with Solution and Technical Architects to embed secure patterns into projects — the Security Architect ensures consistent and measurable security across the enterprise technology landscape. This role combines enterprise governance (standards, frameworks, and compliance) with solution-level delivery support, enabling secure-by-design outcomes across projects while ensuring all security architecture decisions deliver tangible business value through risk reduction, compliance assurance, and operational resilience. • Define and maintain the enterprise security architecture, including reference architectures, control frameworks, and technology standards across applications, infrastructure, integration, and data domains. • Establish and enforce secure-by-design principles and reusable security patterns for new systems, platforms, and integrations. • Embed security into the delivery lifecycle, ensuring DevSecOps adoption (automated testing, policy-as-code, CI/CD integration). • Lead implementation of the Zero-Trust model, covering identity, device, network, application, and data layers. • Collaborate with Cloud & Infrastructure Architects to ensure secure configurations, network segmentation, and identity management across hybrid and multi-cloud environments (Azure, OCI, on-prem). • Partner with Data and Integration Architects to secure data flows, APIs, and event-driven architectures. • Define and maintain security baselines — encryption, secrets management, access control, and key rotation policies. • Conduct architecture and design reviews for major projects, ensuring alignment with enterprise guardrails and regulatory obligations. • Establish and track security metrics and KPIs, including control coverage, vulnerability remediation rates, and compliance posture. • Provide leadership for incident-response architecture, ensuring resilience, containment, and recovery capabilities are built into designs. • Engage with business stakeholders to balance risk appetite with operational needs, ensuring that security remains an enabler of business agility. Qualifications • Bachelor’s degree in Cybersecurity, Computer Science, or related discipline. • 8–10 years’ experience in enterprise or solution security architecture, preferably within large, regulated, or asset-heavy environments (oil & gas, energy, or engineering). • Strong understanding of security architecture frameworks and standards, Including • NIST CSF, ISO 27001, CIS Benchmarks, SABSA, TOGAF Security, or Zero-Trust Architecture (ZTA). • Certified in one or more of: • CISSP (Certified Information Systems Security Professional) • SABSA Chartered Security Architect • Microsoft Certified: Cybersecurity Architect Expert • Certified Cloud Security Professional (CCSP) • GIAC Cloud Security Automation (GCSA) (desirable) • Hands-on experience securing Microsoft Azure and Oracle Cloud Infrastructure (OCI) environments, including identity, networking, and workload protection. • Experience implementing DevSecOps pipelines and automation, using: • SAST/DAST/IAST/SCA tools (e.g., SonarQube, Checkmarx, OWASP ZAP, Fortify) • IaC security scanning (Terraform Sentinel, Checkov, Azure Policy, Defender for Cloud) • Container and pipeline security (Aqua, Prisma, GitHub Advanced Security, Defender for Containers) • Strong understanding of Identity & Access Management (Entra ID, MFA, Conditional Access, PAM) and encryption/key management (Azure Key Vault, OCI Vault). • Knowledge of SIEM, SOAR, and XDR platforms (Sentinel, Splunk, Defender XDR) and how architecture supports detection and response. • Experience using Enterprise Architecture repositories (Orbus Infinity, LeanIX, Sparx EA) and proficiency with ArchiMate or UML for documenting security models and dependencies. • Familiarity with compliance and regulatory frameworks (GDPR, NCA, ADHICS, ISO 27001 certification) and their application to cloud and enterprise systems. Additional Information Show more Show less
Bachelor’s degree in Cybersecurity, Computer Science, or related discipline. 8–10 years’ experience in enterprise or solution security architecture, preferably within large, regulated, or asset-heavy environments (oil & gas, energy, or engineering). Strong understanding of security architecture frameworks and standards, including NIST CSF, ISO 27001, CIS Benchmarks, SABSA, TOGAF Security, or Zero-Trust Architecture (ZTA). Certifications such as CISSP, SABSA Chartered Security Architect, Microsoft Certified: Cybersecurity Architect Expert, CCSP, or GIAC Cloud Security Automation (desirable). Hands-on experience securing Microsoft Azure and Oracle Cloud Infrastructure (OCI) environments, including identity, networking, and workload protection.
Define and maintain the enterprise security architecture, including reference architectures, control frameworks, and technology standards across applications, infrastructure, integration, and data domains. Establish and enforce secure-by-design principles and reusable security patterns for new systems, platforms, and integrations. Embed security into the delivery lifecycle, ensuring DevSecOps adoption (automated testing, policy-as-code, CI/CD integration). Lead implementation of the Zero-Trust model, covering identity, device, network, application, and data layers. Collaborate with Cloud & Infrastructure Architects to ensure secure configurations, network segmentation, and identity management across hybrid and multi-cloud environments (Azure, OCI, on-prem). Partner with Data and Integration Architects to secure data flows, APIs, and event-driven architectures. Define and maintain security baselines — encryption, secrets management, access control, and key rotation policies. Conduct architecture and design reviews for major projects, ensuring alignment with enterprise guardrails and regulatory obligations. Establish and track security metrics and KPIs, including control coverage, vulnerability remediation rates, and compliance posture. Provide leadership for incident-response architecture, ensuring resilience, containment, and recovery capabilities are built into designs. Engage with business stakeholders to balance risk appetite with operational needs, ensuring that security remains an enabler of business agility.
What does a Lead - Enterprise Security Architect earn in the UAE?
See the full Michael Page salary benchmark — ranges, skills, and career progression.
Security Architect
iConnect IT Business Solutions DMCCDubai, UAE
AED 42,000 – 70,000/mo
Senior Architect - Information Security
Roads and Transport AuthorityDubai, UAE
AED 38,000 – 60,000/mo
Integration Solution Architect
PetrofacSharjah, UAE
AED 40,000 – 60,000/mo
Cloud Security Architect Lead
ENEC Operations
AED 30,000 – 60,000/mo