Cyber Security Architect
Job Title: Cyber Security Architect
Location: National Train Control Centre, Heuston Station
Job Type: Permanent
Department: Cybersecurity
Reports to: Head of GRC
Job Summary:
We are seeking a highly skilled Cyber Security Architect to design and implement secure IT and OT infrastructure, ensuring robust protection against cyber threats. The ideal candidate will provide expert guidance in cybersecurity frameworks, collaborating with internal teams to build resilient security architectures.
Key Responsibilities:
- Security Controls and Architecture Design: Design and implement security controls and architectures to protect organisational assets (on premise and cloud). Includes definition of security design principles and patterns
- Technical Risk Assessment: Support the GRC team in technical risk assessments, assess and mitigate security risks, identifying potential vulnerabilities in Irish Rail OT and IT systems and suggesting mitigants to risk
- Define security requirements for IT and OT systems, networks, applications, and cloud environments
- Change Management: Work with various teams (e.g. GRC, PMO and IT) to ensure that cyber security is embedded within change management processes and governance
- Threat Modelling: Assess the potential impact of threats on the organisation's critical assets and systems. Conduct threat modelling exercises to identify vulnerabilities and prioritise mitigation efforts
- Threat Intelligence: Conduct analysis of threat intelligence data from various sources. Develop threat assessments and reports to inform decision-making
- Advanced Support: Offer escalated assistance to security operations in response to complex or unusual incidents
- Support the creation of the DevSecOps function including the SDLC to be applied in IAC and CI-CD deployment pipelines (Ansible, Terraform, Bitbucket, Docker, K8, Jenkins + others) within a Zero Trust + SASE Architecture model
- Supporting and advising various cloud architecture solutions within Azure environment
- Supporting development teams on security best practices for Power App development
- Working with product/project teams and solution architects to develop and incorporate security architecture requirements within HL/LLDs
- Rollout of defender for cloud apps
- Advising product, solution and operation teams on Architecture/security nuances, standards, security architecture principles and requirements across multiple domain and technology areas such as containerization, zero trust architectures, encryption, PKI, database security, web application and web service security, secure development, Infrastructure Security, Cloud Security, IAM
- Design and oversee security solutions, including identity and access management (IAM), endpoint protection, firewalls, SIEM, and encryption mechanisms
- Evaluate emerging cybersecurity technologies and make recommendations for improvements to enhance Irish Rail’s security posture
- Represent cyber security on the Architecture Review Board (ARB)
- Support the GRC team to develop security documentation, including policies, standards and procedures
- Support the Security operations team in building out incident response plans
- Liaise and support internal project teams
Required Qualifications & Experience:
- Bachelor's or Master’s degree in Cybersecurity, Information Technology, Computer Science, or a related field
- Minimum 10 years of experience in cybersecurity architecture, security engineering, or a related role
- Strong understanding of cybersecurity frameworks such as NIST, CIS Controls, and Zero Trust Architecture
- Hands-on experience with security tools and technologies, such as firewalls, SIEM, IDS/IPS, DLP, EDR, and cryptography
- Proficiency in cloud security for platforms such as AWS, Azure, or Google Cloud
- Experience with secure software development principles and DevSecOps
- Knowledge of regulatory compliance frameworks (e.g., NIS2, GDPR, PCI-DSS, HIPAA, ISO 27001)
- Security certifications such as CISSP, CISM, SABSA, TOGAF or CCNA are required
- Excellent analytical and problem-solving skills
- Strong communication and stakeholder management skills
Preferred Skills:
- Experience in Azure and cloud environments
- Azure Certification (e.g. Azure Solutions Architect Expert)
- Understanding of AI-driven security solutions and automation
- Familiarity with programming or scripting languages (e.g., Python, PowerShell)
- Experience working in a large enterprise or government security environment.