Overview
Security Architect Jobs in Sydney, New South Wales, Australia at Avance Consulting
Title: Security Architect
Company: Avance Consulting
Location: Sydney, New South Wales, Australia
Job Description – Delivery Security Architect (Secure by Design)
Role Title
Delivery Security Architect (Secure by Design – SbD)
Purpose
The Delivery Security Architect is responsible for embedding security into the lifecycle of business and IT initiatives from the earliest stages of design and delivery. The role ensures that solutions are secure by design, compliant with enterprise security policies, and aligned to organisational security standards.
Context
This role supports the organisation’s Secure by Design (SbD) and shift‑left security initiatives by integrating security into solution design rather than retrofitting controls later in the lifecycle.
Delivery Security Architects work closely with project teams, solution architects, engineers, and delivery leads to ensure security is a foundational element of solution delivery across business and technology projects.
Key Responsibilities
1. Define Security Requirements for SbD Iterations
(Delivery Security Requirements)
Define and derive security requirements from:
Business needs
Compliance and regulatory obligations
Threat models and risk assessments
Conduct security exposure assessments to identify potential risks and vulnerabilities early in the project lifecycle.
Ensure security requirements are clearly articulated, documented, and traceable.
Maintain clear, accessible documentation to guide:
Solution architects
Development teams
Testing and assurance teams
2. Capture and Address Design Gaps
(Security Exposure View)
Evaluate solution and architecture designs against defined security requirements, standards, and controls.
Identify security gaps within proposed designs.
Classify identified gaps as either:
A conscious design choice not to use an existing security control, or
A missing enterprise‑wide capability requiring broader remediation.
Document security findings, gaps, and recommended remediation actions.
Collaborate with architects, engineers, and project leads to address identified gaps.
Escalate systemic or recurring security capability gaps to the Advisory and Strategy teams for enterprise‑level resolution.
Stakeholder Engagement
Work closely with delivery teams to embed security into solution design and decision‑making.
Provide practical security architecture guidance throughout delivery.
Act as a key security contact within project and program teams.