In this article I will share my experience and thoughts about Security Architect career path. I will outline skills required to enjoy and perform that job well.
My path
About 15 years ago I faced a road fork in my career, where I had multiple opportunities open for me. I already had established strong reputation and built broad range of IT skills – solid foundation for the next step. Which path to take though?
After some structured soul searching I realised that 2 things are important for me: being involved in creation of new things and having big impact. Mapping these “high-level requirements” onto the IT opportunities yielded 3 titles: general manager, project manager or architect.
I had a room to play the role outside of my job title, and tried all three. I like the organisation aspect of being a project manager, but I hate “chasing people” part of it. General manager gives good opportunities to make impact, but that role did not excite me.
The architect role – that is something I really liked. Designing new systems, design decisions with big impact, exposure to broad range of tools and technologies and holistic outlook – that is my cup of tea!
I was a security engineer at the time and there was no direct path into Architecture, but there was a Security Architecture team in our business unit though. Good stepping stone, I thought. I gathered all my courage and charisma and approached the team manager – “Can I do a 2 weeks secondment in your team?” As I did not have architecture experience, the manager had his reservations, but with some persistence and persuasion he has agreed.
Till this day I am so grateful to that manager for his trust and opportunity. He is very security-conscious and does not want to be mentioned, but thanks a lot, K!
I took on a project for security risk assessment, then another one, and another one, and soon enough I was doing sizeable amount of work and was considered to be a part of the team. Most of my current knowledge is what I absorbed from that team, and I am so grateful to my colleagues for sharing it with me!
From the day 1 I knew that is the job I love doing, so the rest was formalities. I have persuaded my current manager to let me go, and K made me a permanent staff of the Security Architecture team. Whoo-hoo!
What about traditional IT Architecture? Security Architects have advantage of being exposed to greater number of projects, in my opinion. At least in that organisation IT Architects were doing 2-3 projects in parallel for several months, while as a Security Architects I could easily go through as much as 50 a year. You can tell you love you job if 50 engagements a year is not enough for you and you still want more 🙂
So I stayed.
My friend’s path
Here is my friend and colleague Stuart Robins journey to Security Architecture.
Your path
I can think of 4 roles leading to Security Architecture:
- Penetration Tester – these have great practical knowledge of attack methods. Excellent choice for the security architect role. They may lack holistic, high-level thinking, but that skill can be developed. Working at higher levels, closer to people and further away from command line interface may be uncomfortable for them.
- IT Engineers, especially Security Engineers – these have solid technical background and some threat modelling mindset. The obstacle may be unwillingness to deal with broad range of projects and ambiguity. Like penetration testers, they may dislike working too far from tools.
- Security Auditors or Analysts – these are used to check things for compliance and well familiar with security requirements. They may lack technical background but they are naturally aligned with Assessing Security Architect role.
- General IT Architects – the easiest transition, in my opinion. Security is always a part of overall IT design, switching to Security Architecture means more focus on security and much, much more security assurance, which they may dislike.
You can land the role via secondment, as I did, or via conventional job application process. I have prepared the Security Architect Interview Preparation Course to help you do well on the interview. I have also developed the Security Architecture Training Course to show you the ropes of the profession.
Required skills and experience
Solid IT knowledge
is a must. Security is about understanding how thing may go wrong, but before that you need to know how things go right. You need to understand “expected” system behaviour, before you can model “unexpected” threats.
How much? More is better. I had 11 years experience in IT before I become a Security Architect. You don’t necessarily need that much, but I would say 5 is the minimum.
There is no easy way to build it. Junior assessors may struggle in this area.
Threat modelling mindset
could be developed on the top of the solid IT knowledge. This skill is close to natural human threat awareness and risk assessment. Some people have more, some people have less of it. There is a known joke in security: “If you are paranoid – are you paranoid enough?”
General IT engineers are not used to that – they are focused on making things work, rather than on the ways to make things break.
It develops quickly with practice.
Security controls knowledge
is essential. You can enumerate attacks via threats modelling, but you need to know practical existing security controls to defend against them.
You can learn them from that knowledge from security publications like NIST 800-53, ISO 27001, your organisation security standards, and I can help you with Pocket Guide and Security Controls Navigator course.
Strong interpersonal skills
is a must. You have that requirement in every job description, but Security Architecture really puts it to the test. That is a secret sauce, biggest challenge, biggest factor of the profession. It will make or break you. It will define the difference between good and bad security architects, between enjoying and loathing the job.
It is just a fraction of the job to find a design vulnerability or identify the best security solution in a scenario. The lion’s share of the job will be the facilitation of remediation and implementation, effective security operations, which requires establishing trust, building good working relationships, being a good listener, and a role model.
In my training course I focus a lot on soft skills, because even hard skills are hard to get, soft interpersonal skills are even harder.
Architectural mindset
is not natural to some people, as I found. Abstract thinking, finding patterns, building holistic view of the solution and organisation capabilities, building a complete multi-dimenional view. The view will include people, processes and tools. Architects don’t think “we need TLS on this flow”, they think “we need to protect confidentiality”. Architects don’t think “we need Prisma Cloud there”, they think “we are lacking CSPM capability, people and process to make it effective”. They think much more strategically, than tactically.
SABSA training helped me a lot with that, but it is expensive. Another way to train the skill is to get exposed to as many solution designs as possible, which stimulates holistic architectural thinking.