Senior Cybersecurity Architect

Il y a 10 heures

Laeken, Brussels, Belgique Keystone Solutions Temps plein

Mission Overview:


As a Senior Cybersecurity Architect, you will play a pivotal role in designing, evolving, and challenging the cybersecurity architecture for our client, ensuring that security, risk, and compliance requirements are translated into robust, realistic, and maintainable technical solutions. This position is a consultancy mission at the client site, representing Keystone Solutions, where you will collaborate directly with the client's IT teams in a consulting capacity, focusing on co-construction, skills transfer, and client orientation.


Key Responsibilities:


  • Analyze the existing cybersecurity architecture and formulate recommendations for evolution in line with the overall IT architecture and defined requirements.
  • Identify and document risks, dependencies, vulnerabilities, and points of fragility, proposing prioritized improvement paths for decision-making.
  • Conduct or contribute to security architecture reviews for new projects, migrations, or significant changes, providing findings, risks, and associated recommendations.
  • Propose and document, in collaboration with the client's IT teams, principles of segmentation, flow control, access, resilience, and defense in depth, subject to client validation.
  • Analyze identity, access, authentication, privileged accounts, and trust mechanisms, formulating corresponding architectural recommendations.
  • Advise relevant teams on logging, monitoring, detection, traceability needs, and integration with security monitoring capabilities.
  • Propose and formalize standards, security patterns, hardening principles, and reusable technical requirements with the client's IT teams, subject to prior validation.
  • Constructively challenge technical proposals from vendors, integrators, or partners, identifying impacts, dependencies, risks, and alternatives, advising the client in decision-making.
  • Provide expertise during technical analyses related to major incidents, resilience, continuity, or recovery, under the coordination and decisions of the client.
  • Ensure technological and regulatory monitoring, presenting potential value-adding evolutions to the client, along with justifications, benefits, risks, and impacts.
  • Support the client's IT teams in analyzing, understanding, and preparing for the implementation of approved recommendations.
  • Actively share knowledge and expertise with internal teams to foster autonomy and avoid excessive dependency on the consultant or a vendor.

Profile and Experience:


  • Minimum 10 years of experience in complex enterprise IT environments, with at least 7 years in cybersecurity and 5 years in a Security Architect or Cybersecurity Architect role.
  • Proven experience in designing, reviewing, and evolving security architectures across multiple domains: network and connectivity, datacenter, identity and access, perimeter security, remote access, cloud/hybrid, and security monitoring.
  • Ability to produce and maintain high-level and detailed architectures, flow diagrams, communication matrices, segmentation principles, architectural decisions, and security requirements.
  • Excellent understanding of enterprise security technologies and the ability to reason independently of vendors.
  • Good mastery of identity and access architectures: IAM, MFA, privileged accounts, PKI, certificates, strong authentication, and PAM principles.
  • Good understanding of network architectures, segmentation, routing, high availability, interconnections, remote access, and flow control mechanisms.
  • Good understanding of systems environments, virtualization, datacenter, cloud/hybrid, and continuity and resilience issues.
  • Experience with logging architectures, SIEM/SOC, and security monitoring: collection, correlation, detection, retention, and traceability.
  • Ability to conduct technical risk analyses, challenge vendor proposals, and formulate proportionate, actionable, and documented recommendations.
  • Ability to translate regulatory, governance, and risk requirements into concrete architectural controls and decisions.

Standards, Frameworks, and Certifications:


  • Mastery of ISO/IEC 27001:2022 requirements and principles, translating them into architectural requirements and technical controls.
  • Good knowledge of ISO/IEC 27002:2022 and ISO/IEC 27005:2022, particularly for selecting security measures and managing risks related to architectural choices.
  • Good knowledge of NIS2, GDPR, and key cybersecurity frameworks applicable to a public or regulated environment.
  • Mastery of the CyberFundamentals (CyFun) Framework from the Centre for Cybersecurity Belgium (CCB), in its current version, including assurance levels and associated requirements.
  • Practi