Enter a job title or keyword

Security Architect

GFT


Job Location:

Hanoi - Vietnam

Monthly Salary: Not provided by the employer
Posted: 23 August 2026 (4 days ago)
Application Deadline: 20 November 2026
Vacancies: 1 Vacancy

Job Summary

Role Summary

As a Security Architect you will enable the business to change IT systems and pursue new opportunities securely by enforcing security policies and designing solutions that protect business value from security risks threats and vulnerabilities. You will define the core security principles conceptual and logical security models and controls required to design secure system solutions within the organisations risk appetite. You will work in a consultancy capacity with business project architecture and technical teams to identify critical security concerns and ensure that security requirements are appropriately reflected in proposed solutions. The role requires strong business engagement and influencing skills including the ability to navigate complex topics through fact-based analysis manage difficult conversations and advise senior management and project leaders on significant security and architectural decisions.

This role sits within Group Security Security Consulting and reports to the Lead Security Consultant.

Key Activities

  • Provide Security Architecture thought leadership and subject-matter expertise to help business and project teams understand the security impacts of proposed system changes and solutions.

  • Assess whether proposed solutions comply with the Group Information Risk Policy and remain within the organisations agreed risk appetite.

  • Analyse non-normative flows across systems applications and proposed solutions to identify security risks threats and vulnerabilities.

  • Determine the security control components countermeasures and design requirements needed to address identified risks.

  • Develop conceptual and logical security architecture designs for proposed solutions.

  • Define security controls across areas including:

  • Identity and Access

  • Data and Media Protection

  • Security Information and Event Management

  • Communications

  • Configurations

  • Vulnerability Management

  • Determine appropriate security controls to address identified risks while considering technical capability business benefit and commercial implications.

  • Manage technical deviations and significant risks including recommending alternative solutions or compensating controls to reduce potential impacts.

  • Influence senior management sponsors project leaders and technical stakeholders to update solution requirements and reflect relevant security needs.

  • Manage significant architectural decisions to ensure secure outcomes and compliance with appropriate governance practices.

  • Support required notifications and engagement with Technology Architecture Forums.

  • Leverage and update existing security control reference patterns.

  • Develop new security patterns that describe integration approaches use cases reusable components and technical references for enterprise security capabilities.

  • Proactively manage security risk and assurance requirements when developing designs that may change the organisations risk posture.

  • Support compliance with applicable internal security policies governance requirements and risk management expectations.

  • Engage with business domain executives Product Owners technology delivery teams Release Train Engineers Architecture and Strategy teams and Governance Risk and Compliance stakeholders.

  • Act as a trusted security adviser to both technical and business stakeholders.

  • Influence the security aspects of relevant target-state architectures and central technology roadmaps.

  • Coach and mentor others in the practical application of security and risk management concepts principles strategies and relevant industry standards.

  • Support the professional development of colleagues by sharing security knowledge and helping them develop relevant capabilities.

Required Skills

  • At least 10 years of experience in the technology industry.

  • At least two years of Security Architecture experience; or at least five years of Solution Architecture experience with significant security exposure.

  • A degree in Computer Science Information Systems or an equivalent technical qualification.

  • Strong experience in business engagement and stakeholder influence.

  • Ability to provide fact-based analysis when navigating complex security and architectural topics.

  • Ability to assess proposed solutions against information risk policies security requirements and agreed risk appetite.

  • Strong understanding of conceptual and logical security architecture models and controls.

  • Ability to analyse systems applications solution designs and non-standard flows to identify security risks threats and vulnerabilities.

  • Experience determining appropriate security controls countermeasures alternative solutions and compensating controls.

  • Understanding of security architecture domains such as Identity and Access Data and Media Protection Security Information and Event Management Communications Configurations and Vulnerability Management.

  • Ability to balance security changes and technical capability with commercial considerations and business benefits.

  • Strong commercial acumen business alignment and negotiation skills.

  • Ability to manage significant architectural decisions and engage effectively with senior management sponsors project leaders and architecture governance forums.

  • Experience developing maintaining or applying security control reference patterns and enterprise security capabilities.

  • Strong understanding of security risk assurance governance and compliance requirements.

  • Ability to communicate security concerns clearly to both technical and business stakeholders.

  • Ability to handle difficult conversations and influence stakeholders toward secure outcomes.

  • Strong coaching and mentoring capabilities.

  • Demonstrated capabilities in:

  • Decision Quality

  • Strategic Mindset

  • Situational Adaptability

  • Self-Awareness

  • Courage

  • Ensuring Accountability

Nice-to-have Requirements

  • Relevant security certifications such as CSSP.

  • Architecture or technology-related certifications such as SABSA or Cloud Security certifications.

(Note: Due to the high volume of applications we receive we are unable to respond to every candidate individually. If you have not received a response from GFT regarding your application within 10 workdays please consider that we have decided to proceed with other candidates. We truly appreciate your interest in GFT and thank you for your understanding)


Required Experience:

Staff IC


About Company

Company Logo

We see opportunity in technology. In domains such as cloud, AI, mainframe modernisation, DLT and IoT, we blend established practice with new thinking to help our clients stay ahead.

View Profile View Profile