Company description See more offers
   
 

Information Security Architect

Role Purpose

 

The Head of Information Security is responsible for defining, implementing, and governing the organization's information security strategy during a business carve-out and Azure tenant separation program. This role ensures that security is embedded into all transformation activities, establishing an independent security operating model, governance framework, and security architecture that supports regulatory compliance, business objectives, and risk management requirements from Day 1.

 

Key Responsibilities

 

Information Security Strategy & Governance

  • Define, maintain, and communicate the organization's information security strategy, policies, standards, and control framework.
  • Establish and lead the Information Security Program, ensuring alignment with business objectives, regulatory obligations, and industry best practices.
  • Obtain executive leadership approval for security initiatives and ensure ongoing alignment with Board-approved risk appetite.
  • Develop and maintain security governance structures, reporting mechanisms, and decision-making forums.
  • Create and manage security policies, standards, procedures, and governance documentation.

Security Architecture & Azure Tenant Design

  • Own the security architecture and design for the new Azure tenant environment.
  • Define and implement identity and access management controls, conditional access policies, privileged access management, and Zero Trust security principles.
  • Ensure security requirements are embedded into the design and deployment of all new platforms and services.
  • Establish tenant security boundaries and governance controls to support secure business separation.
  • Deliver a Day-1-ready security architecture that supports business operations immediately upon transition.

Carve-out & Transformation Security

  • Ensure security-by-design principles are applied throughout the carve-out and migration lifecycle.
  • Review, challenge, and approve migration and transformation initiatives from a security risk perspective.
  • Identify and remove inherited security dependencies on the source organization.
  • Provide security oversight and assurance across all technology workstreams involved in the separation program.
  • Validate security controls before, during, and after migration activities.

Identity, Access & Tenant Security Governance

  • Maintain governance over identity services, authentication mechanisms, access controls, and tenant security boundaries.
  • Ensure appropriate segregation of duties and least-privilege access principles are implemented.
  • Oversee the establishment of secure identity management processes and privileged access controls.
  • Govern user lifecycle management and access certification processes.

Security Operations & Incident Management

  • Lead Security Operations Center (SOC) onboarding and operationalization activities.
  • Establish security monitoring, detection, alerting, and response capabilities.
  • Define and implement incident response procedures, escalation paths, and crisis management processes.
  • Ensure effective integration of security operations with business and IT support functions.
  • Coordinate security incident investigations and post-incident reviews.

Risk Management & Compliance

  • Establish and maintain the organization's security risk register.
  • Define the compliance baseline and security control requirements applicable to the new organization.
  • Conduct risk assessments for technology, business, and transformation initiatives.
  • Monitor compliance with regulatory, contractual, and internal security requirements.
  • Report security risks, compliance status, and remediation activities to executive stakeholders.

Key Deliverables

  • Information Security Strategy and Roadmap
  • Security Policies, Standards, and Governance Framework
  • Azure Tenant Security Architecture (Day 1 Ready)
  • Identity and Access Management Governance Model
  • Security Risk Register and Compliance Baseline
  • Security Operations Center (SOC) Operating Model
  • Incident Response and Escalation Framework
  • Security Assurance and Risk Assessments for Migration Activities
  • Tenant Separation Security Controls and Governance

Required Experience

  • Extensive experience leading enterprise information security programs.
  • Strong expertise in Microsoft Azure security architecture, identity management, and Zero Trust principles.
  • Proven experience supporting mergers, acquisitions, divestitures, carve-outs, or tenant separation initiatives.
  • Experience establishing security governance, risk management, and compliance frameworks.
  • Strong understanding of SOC operations, incident response, and cyber security monitoring.
  • Experience engaging with executive leadership, boards, regulators, and external auditors.

Key Skills

  • Information Security Governance
  • Security Architecture
  • Azure Security & Cloud Security
  • Identity & Access Management (IAM)
  • Zero Trust Architecture
  • Risk Management
  • Regulatory Compliance
  • Security Operations (SOC)
  • Incident Response
  • Stakeholder Management
  • Program Leadership
  • Security-by-Design

Company description

ATCON is a Belgium-based IT consulting firm established with a vision to empower businesses using the latest technologies and provide best-in-class services to our clients.
We support as an end-to-end IT solutions partner for digitalizing business processes and making the data meaningful.
Our approach is more solution-driven than technology one, focused to solve business challenges and deliver results. We do what is right for our clients and charge based on what we deliver not on billing hours.
Our team consists of self-motivated consultants with an agile mindset, global work exposure, and commitment to deliver the best services.

Show full description
Information Security Architect
Atcon Global
Similar offers