Apply now »

Security Architect

Security Architect

Custom Field 1:  Architecture
Custom Field 3:  Architecture
Country/Region:  VN
Date:  Aug 21, 2026
Location: 

Ho Chi Minh City, VN, 700000 Hanoi, VN, 10000

Working place:  Hybrid

Role Summary 

As a Security Architect, you will enable the business to change IT systems and pursue new opportunities securely by enforcing security policies and designing solutions that protect business value from security risks, threats, and vulnerabilities. You will define the core security principles, conceptual and logical security models, and controls required to design secure system solutions within the organisation’s risk appetite. You will work in a consultancy capacity with business, project, architecture, and technical teams to identify critical security concerns and ensure that security requirements are appropriately reflected in proposed solutions. The role requires strong business engagement and influencing skills, including the ability to navigate complex topics through fact-based analysis, manage difficult conversations, and advise senior management and project leaders on significant security and architectural decisions. 

This role sits within Group Security – Security Consulting and reports to the Lead Security Consultant.

 

Key Activities 

  • Provide Security Architecture thought leadership and subject-matter expertise to help business and project teams understand the security impacts of proposed system changes and solutions. 

  • Assess whether proposed solutions comply with the Group Information Risk Policy and remain within the organisation’s agreed risk appetite. 

  • Analyse non-normative flows across systems, applications, and proposed solutions to identify security risks, threats, and vulnerabilities. 

  • Determine the security control components, countermeasures, and design requirements needed to address identified risks. 

  • Develop conceptual and logical security architecture designs for proposed solutions. 

  • Define security controls across areas including: 

  • Identity and Access 

  • Data and Media Protection 

  • Security Information and Event Management 

  • Communications 

  • Configurations 

  • Vulnerability Management 

  • Determine appropriate security controls to address identified risks while considering technical capability, business benefit, and commercial implications. 

  • Manage technical deviations and significant risks, including recommending alternative solutions or compensating controls to reduce potential impacts. 

  • Influence senior management, sponsors, project leaders, and technical stakeholders to update solution requirements and reflect relevant security needs. 

  • Manage significant architectural decisions to ensure secure outcomes and compliance with appropriate governance practices. 

  • Support required notifications and engagement with Technology Architecture Forums. 

  • Leverage and update existing security control reference patterns. 

  • Develop new security patterns that describe integration approaches, use cases, reusable components, and technical references for enterprise security capabilities. 

  • Proactively manage security risk and assurance requirements when developing designs that may change the organisation’s risk posture. 

  • Support compliance with applicable internal security policies, governance requirements, and risk management expectations. 

  • Engage with business domain executives, Product Owners, technology delivery teams, Release Train Engineers, Architecture and Strategy teams, and Governance, Risk and Compliance stakeholders. 

  • Act as a trusted security adviser to both technical and business stakeholders. 

  • Influence the security aspects of relevant target-state architectures and central technology roadmaps. 

  • Coach and mentor others in the practical application of security and risk management concepts, principles, strategies, and relevant industry standards. 

  • Support the professional development of colleagues by sharing security knowledge and helping them develop relevant capabilities. 

 

Required Skills 

  • At least 10 years of experience in the technology industry. 

  • At least two years of Security Architecture experience; or at least five years of Solution Architecture experience with significant security exposure. 

  • A degree in Computer Science, Information Systems, or an equivalent technical qualification. 

  • Strong experience in business engagement and stakeholder influence. 

  • Ability to provide fact-based analysis when navigating complex security and architectural topics. 

  • Ability to assess proposed solutions against information risk policies, security requirements, and agreed risk appetite. 

  • Strong understanding of conceptual and logical security architecture models and controls. 

  • Ability to analyse systems, applications, solution designs, and non-standard flows to identify security risks, threats, and vulnerabilities. 

  • Experience determining appropriate security controls, countermeasures, alternative solutions, and compensating controls. 

  • Understanding of security architecture domains such as Identity and Access, Data and Media Protection, Security Information and Event Management, Communications, Configurations, and Vulnerability Management. 

  • Ability to balance security changes and technical capability with commercial considerations and business benefits. 

  • Strong commercial acumen, business alignment, and negotiation skills. 

  • Ability to manage significant architectural decisions and engage effectively with senior management, sponsors, project leaders, and architecture governance forums. 

  • Experience developing, maintaining, or applying security control reference patterns and enterprise security capabilities. 

  • Strong understanding of security risk, assurance, governance, and compliance requirements. 

  • Ability to communicate security concerns clearly to both technical and business stakeholders. 

  • Ability to handle difficult conversations and influence stakeholders toward secure outcomes. 

  • Strong coaching and mentoring capabilities. 

  • Demonstrated capabilities in: 

  • Decision Quality 

  • Strategic Mindset 

  • Situational Adaptability 

  • Self-Awareness 

  • Courage 

  • Ensuring Accountability 

Nice-to-have Requirements 

  • Relevant security certifications, such as CSSP. 

  • Architecture or technology-related certifications, such as SABSA or Cloud Security certifications. 

 

(Note: Due to the high volume of applications we receive, we are unable to respond to every candidate individually. If you have not received a response from GFT regarding your application within 10 workdays, please consider that we have decided to proceed with other candidates. We truly appreciate your interest in GFT and thank you for your understanding)

About Us

We show commitment to our investors and stand for solid, long-term growth performance. Founded in Germany in 1987 and in American territory since 2008, GFT expanded globally to over 10,000 experts. And to more than 15 markets to ensure proximity to clients. With new opportunities from Asia to Brazil, the international growth story continues. We are committed to grow tech talents worldwide. Because our team’s strong consulting and development skills across legacy and pioneering technologies, like GreenCoding, underpin success. We maintain a family atmosphere in an inclusive work environment.

There is room for your talent!

Put your talent to work. At GFT, you'll be working with some of the brightest people in business and technology on challenging and rewarding projects in, a team of like-minded individuals.
Feel it. We are #one team collaboratively working towards the same goal.

Not Ready To Apply?

Stay connected! Enter your e-mail and we will keep you informed about upcoming events and opportunities that match your interests.

Apply now »