Tech Mahindra
Associate Security Architect
Tech MahindraQatar8 hours ago
Full-timeRemote FriendlyInformation Technology
Job Summary

TechM177323 Security Architect JOB DESCRIPTION The Security Architect plays a pivotal role in safeguarding the digital and physical assets of a water and electricity government company. As public utilities are essential to national well-being and economic stability, this position is both highly strategic and deeply technical. The Security Architect is responsible for designing, implementing, and maintaining robust security frameworks that protect the organization’s critical infrastructure from a constantly evolving landscape of threats. Key Responsibilities Security Strategy & Architecture Design: Develop, update, and maintain the company’s enterprise security architecture, ensuring alignment with best practices, regulatory requirements, and business objectives. Create blueprints for secure network, systems, and application architectures tailored to the unique needs of water and electricity utilities. Risk Assessment & Management: Conduct comprehensive risk assessments of information systems, operational technology (OT), and industrial control systems (ICS/SCADA) environments. Identify vulnerabilities and threats, evaluate their potential impact, and recommend effective mitigation strategies. Policy Development & Compliance: Lead the creation and enforcement of security policies, standards, and guidelines. Ensure compliance with national and international regulations (such as NIST, ISO 27001, NERC CIP) relevant to public utilities and the energy sector. Incident Response Planning: Design and test incident response and disaster recovery plans, ensuring rapid and coordinated responses to security incidents and breaches. Conduct tabletop exercises and simulations to maintain a high level of organizational readiness. Security Solutions Implementation: Oversee deployment of security solutions in both IT and OT environments, including firewalls, intrusion detection and prevention systems (IDS/IPS), SIEM, endpoint protection, and network segmentation. Governance, Risk, and Compliance (GRC): Work with internal and external auditors to assess and document compliance with security requirements, lead risk remediation initiatives, and report on risk posture to senior management and government stakeholders. Vendor & Third-Party Security: Evaluate and manage security risks associated with vendors, contractors, and service providers. Conduct third-party security assessments and ensure adherence to security standards in supply chain operations. Security Awareness & Training: Develop and deliver training programs for employees and contractors, promoting a culture of security awareness and shared responsibility across the organization. Innovation & Continuous Improvement: Stay abreast of emerging threats, technologies, and regulatory requirements. Drive continuous improvement in security practices, tools, and processes, advocating for proactive, forward-thinking approaches to risk management. Collaboration & Communication: Act as a trusted advisor to executive leadership and work closely with cross-functional teams, including IT, operations, engineering, legal, and emergency response units. Required Qualifications Bachelor’s or Master’s degree in Computer Science, Information Security, Cybersecurity, Engineering, or related field. Relevant certifications such as CISSP, CISM, SABSA, TOGAF, or equivalent. 5-10 years of hands-on experience in information security, preferably within critical infrastructure sectors (utilities, water, energy, transportation, etc.). In-depth knowledge of security architecture methodologies and frameworks. Strong understanding of operational technology (OT) security, ICS/SCADA systems, and the unique challenges of securing industrial environments. Experience with regulatory frameworks and compliance requirements relevant to public utilities. Proven track record in risk assessment, mitigation, and incident response. Excellent written and verbal communication skills, including the ability to present technical concepts to non-technical audiences. Strong analytical, organizational, and leadership skills. Ability to obtain and maintain security clearance as required by government regulations. Preferred Skills & Attributes Experience with cloud security architecture in hybrid environments. Familiarity with smart grid technologies, IoT security, and protocols used in water and electricity distribution networks. Knowledge of physical security systems (CCTV, access control, perimeter defenses) integrated with digital security operations. Ability to conduct penetration testing and vulnerability assessments in both IT and OT domains. Understanding of threat intelligence platforms and security analytics. Proactive, detail-oriented, and capable of working under pressure in a mission-critical environment. Demonstrated commitment to ethics, transparency, and public service values. Key Challenges Balancing security and operational continuity in 24/7 environments where downtime is not an option. Integrating legacy systems with modern security controls and technologies. Managing risks associated with supply chain, contractors, and third-party vendors. Staying ahead of constantly evolving cyber and physical threats, including nation-state attacks and natural disasters. Ensuring compliance with multiple, sometimes overlapping, regulatory regimes. Typical Projects & Initiatives Development of segmentation strategies to isolate critical infrastructure from less secure corporate networks. Modernization of incident detection and response capabilities, including adoption of artificial intelligence and machine learning tools for threat detection. Deployment of advanced threat intelligence feeds and integration into operational workflows. Leading cyber resilience assessments in collaboration with government agencies and international partners. 6+ Doha Qatar As per Client QAR 18-20K Immediate /30 days

Key Skills

Ranked by relevance