What does a Cyber Security Architect do and how to become one?
Cyber Security Architect role is a bit mysterious and has different definitions. However, my 9 years experience in this role has been very consistent in terms of duties and responsibilities across different organisations.
Here is what my colleagues and I do:
Main activities:
First of all, I would like to distinguish these types of Security Architect roles:
- “Solutioning” Security Architect is close to a traditional IT Solution Architect role, but with security flavour. They deliver designs for security products and capabilities.
- “Enterprise” Security Architect, whose main responsibility is business alignment, security strategy, roadmaps, cyber capabilities and patterns.
- “Assessing” Security Architect – in my experience is what typically expected from a Cyber Security Architect. Design assessments is the main deliverable.
The role can be a combination of all three types, but in my experience the spread of activities is approximately:

Security design assessments
We review project designs created by others (the creator and assessor should be different roles), model threats, identify security vulnerabilities at the design level, prescribe additional security controls, if required.
This includes checking for compliance with security standards and early design consultations.
Risk management
For each design security flaw found, we perform risk assessment and rating to understand the priority of remediation. Some vulnerabilities require immediate treatment, some vulnerabilities could be left untreated.
Risk rating is not an exact science, as it involves subjective assessments of likelihood and impact. Subjective risk interpretations are often challenged. That is why good stakeholder management skills are required to “defend” and “advocate” for security improvements in already tight project budget and timelines.
Security assurance
This is the build-time activities to verify that security requirements have been met:
- Configuration review.
- Firewall rules review.
- Source code pull requests (PR) approvals.
- Penetration testing and vulnerability scanning reports review and exceptions management.
- Evidence collection.
Security design and patterns
Creation of security patterns and anti-patterns for solution designs. These are typically tailored to organisations existing capabilities and practices.
Solution/vendor selection and comparison. May also include review of security clauses in vendor contracts.
Security capability management – lifecycling and gap analysis.
Enterprise security standards, policies and implementation guides.
Security strategy and roadmaps
This includes delivering an enterprise cybersecurity strategy, maintaining business alignment, identifying priorities and key activities, setting goals and metrics, and managing the security budget and roadmaps.
Professional perks
Exposure to a large number of different solutions is what I love the most about being Security Architect. From hyper-modern Cloud-native applications, to highly specialised or legacy solutions – I have seen so much!
This leads to personal knowledge growth and improved marketability. I don’t know where else you can get so much exposure to variety of IT implementations. I feel like a kid in a toy store. Only the toys are serious now, and I am allowed to touch all of them 🙂
Challenges
Lack of creative activities. We review project designs created by someone else. However, there is still room for creativity in security patterns, strategy and control design.
Negotiation of the implementation of the security improvements can be stressful. Advocating for security can be stressful. I don’t mind, as I love to make impact, but some people don’t like constant pressure.
Lack of visible impact. If we do our security job well – nothing happens. Nothing bad happens. It is hard to explain what good have you done today, if you haven’t written or delivered something tangible. I got used to that from being sysadmin. Lack of fulfilment is not to be underestimated. There is no instant gratification in this type of job.
Required skills and qualities
This could be another article, but I will summarise in these points:
- Broad IT knowledge
- Security controls knowledge
- Threat modelling mindset
- Strong interpersonal skills