وصف الوظيفة
Role Overview
Enterprise Security Architect Lead at Chalhoub Group. The role is based in the Middle East, leading the Group's enterprise security architecture capability across a global luxury retail organization.
Company Overview
Chalhoub Group is a luxury retailer operating across the Middle East for over seven decades. The Group manages a portfolio of over 10 owned brands and distributes over 400 international names across luxury fashion, beauty, jewellery, watches, eyewear, and art de vivre. It operates more than 950 stores, online platforms, and mobile apps, delivering omnichannel experiences. The Greenhouse is the Group's innovation hub, incubator, and accelerator for startups and emerging businesses.
Role Purpose
Define and lead the Group's Enterprise Security Architecture capability, ensuring security is embedded by design across business transformation, technology delivery, digital innovation and operational change. Enable business growth through pragmatic risk management, modern security engineering practices and strategic technology governance.
Key Responsibilities
Strategy & Architecture Design
- Define, own and continuously evolve the Group Enterprise Security Architecture strategy, standards, principles and target-state roadmap.
- Establish security architecture patterns and reference architectures that support business transformation and technology modernisation.
- Develop and maintain enterprise security architecture standards aligned with recognised industry frameworks and regulatory requirements.
- Partner with Enterprise Architecture to shape enterprise technology roadmaps, ensuring security requirements are embedded into strategic technology decisions and future-state architectures.
Governance & Risk Management
- Own the Security Design Authority and provide governance for enterprise architecture decisions, security design standards, architecture exceptions and technology risk across the Group.
- Govern architecture decisions, design exceptions and technology risk to ensure alignment with enterprise standards and business objectives.
- Represent Information Security at architecture, technology governance and investment forums.
- Provide independent security architecture assurance and technical due diligence for strategic programmes, enterprise platforms, cloud services, third-party solutions and technology investments.
- Assess emerging technologies and evolving cyber threats to inform the Group's security architecture strategy.
Security Embedding & Integration
- Ensure security is embedded throughout the technology lifecycle and incorporated into solution design from inception.
- Embed Security by Design across the full technology lifecycle, ensuring security requirements are considered from concept through implementation and operational transition.
- Evaluate new technologies and major investments to ensure they meet security, resilience and architectural standards.
Leadership & Capability Development
- Provide enterprise security architecture leadership across strategic programmes, digital initiatives and enterprise technology platforms.
- Drive continuous improvement of the Group's enterprise security architecture capability and maturity.
- Drive the adoption of modern security architecture practices, automation and engineering capabilities. Continuously develop and mature the Group's Enterprise Security Architecture capability, standards, methodologies and operating model.
- Lead and develop the Enterprise Security Architecture capability, fostering technical excellence, collaboration and innovation.
- Promote standardisation, simplification and continuous improvement across the technology landscape.
Stakeholder & Partnership Management
- Act as the trusted security architecture advisor to senior technology and business leaders ensuring technology enables business growth while effectively managing cyber risk.
- Build strong partnerships across Technology & Data, Digital, Product, Engineering and business functions. Provide architectural leadership across identity, cloud, infrastructure, applications, data, enterprise platforms and emerging technologies.
Qualifications & Experience
- Minimum 10–12 years' experience in Enterprise Security Architecture.
- Proven experience defining and governing enterprise security architecture within a complex, global organisation.
- Demonstrated experience leading security architecture across large-scale business transformation, cloud adoption and enterprise technology modernisation programmes.
- Experience providing architectural governance for enterprise platforms, digital products and third-party technology solutions.
- Experience supporting major ERP or enterprise platform transformations (e.g. SAP or equivalent) is highly desirable.
- Strong experience influencing senior technology leaders, enterprise architects and executive stakeholders.
- Experience developing enterprise architecture standards, reference architectures and security design governance.
Skills & Competencies
- Enterprise Security Architecture.
- Security by Design and Secure Engineering principles.
- Enterprise Architecture and Architecture Governance.
- Cloud & Hybrid Security Architecture.
- Identity & Access Management.
- Infrastructure, Network & Platform Security.
- Application, API & Data Security.
- DevSecOps and Secure Software Development Lifecycle (SSDLC).
- Zero Trust Architecture.
- Cyber Risk Management and Security Governance.
- Emerging technologies, including Artificial Intelligence and Automation.
- Strategic thinking with strong commercial and business acumen.
- Executive presence with exceptional communication, influencing and stakeholder management skills.
- Ability to balance business enablement with effective cyber risk management.
- Strong decision-making and problem-solving capability within complex enterprise environments.
- Collaborative leadership with ability to build trusted partnerships across business and technology functions.
- Passion for developing people, fostering innovation and driving continuous improvement.
Additional Information
Competitive benefits package includes health care, child education contribution, remote and flexible working policies and exclusive employee discounts.
Chalhoub Group is committed to inclusion and diversity. All applicants are welcome to apply without regard to gender, age, race, religion, national origin or disability status.
Candidates are asked to complete assessments and interviews independently and without assistance from generative AI tools.