Senior Security Architect
Hybrid · Melbourne, Victoria, Australia
Job Summary
Senior Security Architect at KPMG Australia’s Connected Technology Group. Lead and perform strategic and hands-on security architecture across complex enterprise environments, shaping Secure by Design within architecture governance, collaborating with domain leads (enterprise, cloud, infrastructure, data, application) to embed security across designs, and aligning with KPMG Australia/global security standards. Conduct security architecture reviews, identify risks and gaps, embed threat modelling into design and delivery, mentor other security architects, and document security patterns, baselines, and checklists to enable scalable, secure-by-design solutions. Work across business, information, application, and technology domains to deliver IT controls and systems in line with governance, risk and compliance frameworks, while engaging with local and international colleagues. Requires strong communication to stakeholders, ability to translate security concepts for executives, and ability to operate in a flexible, hybrid work environment in Melbourne, Australia.
Required Qualifications
- Ability to obtain and maintain Australian Government security clearance to NV1 level
- Formal qualifications or certifications in architecture disciplines, such as TOGAF, SABSA, or equivalent
- Recognised cybersecurity certifications such as CISSP, CCSP, CCNA (Security) or equivalent
- Tertiary qualifications in information management, computer science, information systems, cybersecurity, or equivalent industry experience
- Strong working knowledge of recognised cybersecurity frameworks and standards, such as NIST, ISO 27001 and the Australian Government ISM
- Experience embedding threat modelling into solution design and delivery
- Broad experience across multiple security domains, including identity and access management, network security, data protection, and application security
- Experience designing security architectures for modern cloud environments, including the use of contemporary tools, platforms, and security-by-design practices
- Understanding of relevant Australian regulatory and legislative requirements, such as APRA CPS 234, SOCI, ISM, and related obligations
- Demonstrated ability to obtain and maintain NV1 clearance
- Formal architecture qualifications (TOGAF, SABSA) or equivalent practical experience
- Recognised cybersecurity certifications (CISSP, CCSP, CCNA (Security))
- Tertiary qualifications in information management, computer science, information systems, cybersecurity, or equivalent experience
- Ability to translate complex security and architectural concepts into actionable guidance for executives and senior leaders
Apply with one swipe on Sorce. We auto-fill applications and apply on your behalf — no cover letters, no 40-minute forms.
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.