Enterprise Security Architect
When to Use
- Define enterprise security reference architecture — domains, layers, trust boundaries, patterns catalog
- Harmonize security domains — identity, data, application, network, endpoint, operations
- Design zero-trust and segmentation — identity-centric access, micro-segmentation, east-west controls
- Map control frameworks — NIST CSF, ISO 27001 Annex A, CIS, SOC 2 to architecture building blocks
- Integrate security with enterprise architecture (EA) — capability maps, standards, exception process
- Align architecture with risk appetite — control tiers, compensating controls, treatment themes
- Publish BU and acquisition standards — mandatory patterns, integration playbooks, sunset rules
- Run security architecture review — ARB criteria, threat-informed design gates, pattern exceptions
- Prepare architecture executive briefings — standards adoption, zero-trust roadmap, pattern gaps, acquisition integration (not CISO program KRIs)
When NOT to Use
- Multi-BU cloud landing zones, CCoE, EA commits, regulated cloud placement, cloud guardrail catalog →
enterprise-cloud-architect
- Single-product or single-account cloud target design →
cloud-architect
- Implement SCPs, CSPM rules, cloud IAM policies, KMS wiring →
cloud-security-engineer
- Deploy SSO connectors, SIEM pipelines, EDR, hardening runbooks →
information-security-engineer
- Build risk registers, inherent/residual scoring, FAIR estimates →
security-risk-analyst
- Entitlement modeling, access reviews, PAM vault configuration →
iam-specialist
- GRC program scope, audit prep, questionnaire packs →
compliance-specialist
- Automate control evidence from IdP, CI/CD, CSPM →
compliance-engineer
- CI SAST/SBOM, pipeline scan gates, artifact signing only →
devsecops
- Security program strategy, policies, vuln/IR program, pentest governance →
cybersecurity
- Board program briefings, risk appetite, KRIs, crisis comms →
chief-information-security-officer
- Product/service ADRs, C4 models, strangler migrations →
senior-system-architecture
- Infrastructure capex portfolio and facility supply chain →
vp-of-infrastructure
Related skills
| Need |
Skill |
| Enterprise cloud governance and landing zones |
enterprise-cloud-architect |
| Product or account cloud architecture |
cloud-architect |
| Cloud guardrails, CSPM, cloud IAM implementation |
cloud-security-engineer |
| Control deployment, SIEM/EDR, secrets, hardening |
information-security-engineer |
| Risk registers, scoring, treatment decisions |
security-risk-analyst |
| IAM lifecycle, RBAC, federation, PAM detail |
iam-specialist |
| GRC program, audits, framework scope |
compliance-specialist |
| Technical control evidence automation |
compliance-engineer |
| Secure SDLC pipeline implementation |
devsecops |
| Security program strategy and policies |
cybersecurity |
| CISO board narrative, risk appetite, program ops |
chief-information-security-officer |
| Cross-service ADRs and integration architecture |
senior-system-architecture |
| Infrastructure portfolio and executive infra narrative |
vp-of-infrastructure |
Core Workflows
1. Define scope and operating model
Clarify enterprise vs federated ownership, ARB authority, and mandatory vs recommended controls.
See references/enterprise_security_architect_scope.md.
2. Publish reference architecture
Layered model, domain map, pattern catalog, and integration points to EA.
See references/security_reference_architecture.md.
3. Design identity, data, and zero trust
Identity-centric access, data protection tiers, segmentation, and ZTNA/SASE alignment.
See references/identity_data_and_zero_trust.md.
4. Standardize application and integration security
Secure SDLC gates, API/B2B patterns, secrets, and third-party integration standards.
See references/application_and_integration_security.md.
5. Map governance, frameworks, and controls
Map frameworks to architecture blocks; define control tiers and exception lifecycle.
See references/governance_frameworks_and_controls.md.
6. Brief executives on architecture posture
Architecture packs for board/CISO: standards adoption, KPIs, investment cases, acquisition integration (program KRIs → chief-information-security-officer).
See references/executive_security_architecture_briefings.md.
7. Integrate acquisitions and new BUs
Apply assimilation playbook — identity, logging, segmentation, mandatory patterns by day 1/30/90.
See references/enterprise_security_architect_scope.md (M&A stakeholders) and references/executive_security_architecture_briefings.md (acquisition summaries).
Outputs
- Enterprise security reference architecture — domains, layers, trust zones, pattern catalog
- Zero-trust roadmap — phases, dependencies, identity and segmentation milestones
- Control-to-architecture matrix — framework clauses mapped to building blocks and evidence owners
- Security standards catalog — mandatory, recommended, deprecated; BU adoption checklist
- ARB/security review checklist — threat-informed gates, exception template with expiry
- Acquisition integration playbook — identity, logging, data, network assimilation steps
- Executive briefing deck outline — posture, top gaps, investments, measurable outcomes
Principles
- Architecture before tooling — patterns and control intent precede vendor selection
- Identity is the perimeter — authenticate, authorize, and continuously validate every access path
- Defense in depth by domain — no single control family carries the entire risk
- Measurable standards — every mandatory pattern has a validation method and owner
- Federation with guardrails — central standards, local delivery within approved patterns
- Risk-informed exceptions — time-bound, logged, tied to residual risk acceptance
- Patterns before implementation —
information-security-engineer and cloud-security-engineer deploy; this skill defines intent and standards
1---2name: enterprise-security-architect3description: Guides enterprise-wide security architecture—reference architectures and domains (identity, data, application, network, endpoint), zero-trust and segmentation, framework mapping (NIST CSF, ISO 27001, CIS), EA and risk alignment, architecture executive briefings, and BU/acquisition standards. Use for enterprise security reference models, zero-trust roadmaps, control catalogs, security ARB standards, or acquisition integration—not cloud landing zones (enterprise-cloud-architect), cloud IAM/terraform (cloud-security-engineer), control deployment/SIEM/EDR (information-security-engineer), product ADRs (senior-system-architecture), risk scoring (security-risk-analyst), GRC program (compliance-specialist), evidence automation (compliance-engineer), CI gates (devsecops), or CISO board program (chief-information-security-officer).4---56# Enterprise Security Architect78## When to Use910- Define **enterprise security reference architecture** — domains, layers, trust boundaries, patterns catalog11- Harmonize **security domains** — identity, data, application, network, endpoint, operations12- Design **zero-trust and segmentation** — identity-centric access, micro-segmentation, east-west controls13- Map **control frameworks** — NIST CSF, ISO 27001 Annex A, CIS, SOC 2 to architecture building blocks14- Integrate security with **enterprise architecture (EA)** — capability maps, standards, exception process15- Align architecture with **risk appetite** — control tiers, compensating controls, treatment themes16- Publish **BU and acquisition standards** — mandatory patterns, integration playbooks, sunset rules17- Run **security architecture review** — ARB criteria, threat-informed design gates, pattern exceptions18- Prepare **architecture executive briefings** — standards adoption, zero-trust roadmap, pattern gaps, acquisition integration (not CISO program KRIs)1920## When NOT to Use2122- Multi-BU cloud landing zones, CCoE, EA commits, regulated cloud placement, cloud guardrail catalog → `enterprise-cloud-architect`23- Single-product or single-account cloud target design → `cloud-architect`24- Implement SCPs, CSPM rules, cloud IAM policies, KMS wiring → `cloud-security-engineer`25- Deploy SSO connectors, SIEM pipelines, EDR, hardening runbooks → `information-security-engineer`26- Build risk registers, inherent/residual scoring, FAIR estimates → `security-risk-analyst`27- Entitlement modeling, access reviews, PAM vault configuration → `iam-specialist`28- GRC program scope, audit prep, questionnaire packs → `compliance-specialist`29- Automate control evidence from IdP, CI/CD, CSPM → `compliance-engineer`30- CI SAST/SBOM, pipeline scan gates, artifact signing only → `devsecops`31- Security program strategy, policies, vuln/IR program, pentest governance → `cybersecurity`32- Board program briefings, risk appetite, KRIs, crisis comms → `chief-information-security-officer`33- Product/service ADRs, C4 models, strangler migrations → `senior-system-architecture`34- Infrastructure capex portfolio and facility supply chain → `vp-of-infrastructure`3536## Related skills3738| Need | Skill |39|---|---|40| Enterprise cloud governance and landing zones | `enterprise-cloud-architect` |41| Product or account cloud architecture | `cloud-architect` |42| Cloud guardrails, CSPM, cloud IAM implementation | `cloud-security-engineer` |43| Control deployment, SIEM/EDR, secrets, hardening | `information-security-engineer` |44| Risk registers, scoring, treatment decisions | `security-risk-analyst` |45| IAM lifecycle, RBAC, federation, PAM detail | `iam-specialist` |46| GRC program, audits, framework scope | `compliance-specialist` |47| Technical control evidence automation | `compliance-engineer` |48| Secure SDLC pipeline implementation | `devsecops` |49| Security program strategy and policies | `cybersecurity` |50| CISO board narrative, risk appetite, program ops | `chief-information-security-officer` |51| Cross-service ADRs and integration architecture | `senior-system-architecture` |52| Infrastructure portfolio and executive infra narrative | `vp-of-infrastructure` |5354## Core Workflows5556### 1. Define scope and operating model5758Clarify enterprise vs federated ownership, ARB authority, and mandatory vs recommended controls.5960**See `references/enterprise_security_architect_scope.md`.**6162### 2. Publish reference architecture6364Layered model, domain map, pattern catalog, and integration points to EA.6566**See `references/security_reference_architecture.md`.**6768### 3. Design identity, data, and zero trust6970Identity-centric access, data protection tiers, segmentation, and ZTNA/SASE alignment.7172**See `references/identity_data_and_zero_trust.md`.**7374### 4. Standardize application and integration security7576Secure SDLC gates, API/B2B patterns, secrets, and third-party integration standards.7778**See `references/application_and_integration_security.md`.**7980### 5. Map governance, frameworks, and controls8182Map frameworks to architecture blocks; define control tiers and exception lifecycle.8384**See `references/governance_frameworks_and_controls.md`.**8586### 6. Brief executives on architecture posture8788Architecture packs for board/CISO: standards adoption, KPIs, investment cases, acquisition integration (program KRIs → `chief-information-security-officer`).8990**See `references/executive_security_architecture_briefings.md`.**9192### 7. Integrate acquisitions and new BUs9394Apply assimilation playbook — identity, logging, segmentation, mandatory patterns by day 1/30/90.9596**See `references/enterprise_security_architect_scope.md` (M&A stakeholders) and `references/executive_security_architecture_briefings.md` (acquisition summaries).**9798## Outputs99100- **Enterprise security reference architecture** — domains, layers, trust zones, pattern catalog101- **Zero-trust roadmap** — phases, dependencies, identity and segmentation milestones102- **Control-to-architecture matrix** — framework clauses mapped to building blocks and evidence owners103- **Security standards catalog** — mandatory, recommended, deprecated; BU adoption checklist104- **ARB/security review checklist** — threat-informed gates, exception template with expiry105- **Acquisition integration playbook** — identity, logging, data, network assimilation steps106- **Executive briefing deck outline** — posture, top gaps, investments, measurable outcomes107108## Principles109110- **Architecture before tooling** — patterns and control intent precede vendor selection111- **Identity is the perimeter** — authenticate, authorize, and continuously validate every access path112- **Defense in depth by domain** — no single control family carries the entire risk113- **Measurable standards** — every mandatory pattern has a validation method and owner114- **Federation with guardrails** — central standards, local delivery within approved patterns115- **Risk-informed exceptions** — time-bound, logged, tied to residual risk acceptance116- **Patterns before implementation** — `information-security-engineer` and `cloud-security-engineer` deploy; this skill defines intent and standards