Skip to Main Content

Cybersecurity Architects

The Job

Cybersecurity architects design, create, maintain, and manage an organization’s information technology systems (i.e., computers, mobile devices, Internet of Things endpoints, networks, data) to protect them from cybercrime and unauthorized access or modification.

During the design phase, they conduct research to better understand the organization’s mission, business processes, and technical requirements and then create models for building the cybersecurity architecture. This architecture takes into account both in-house information technology and that which is used by remote workers, clients, and customers. Architects meet with executives and other stakeholders to identify and prioritize critical business functions as they create the design.

During the design process, most architects incorporate a Zero Trust strategy and architecture into their design, which includes security strategies for data, applications, identity, access management, and infrastructure. The National Institute of Standards and Technology defines zero trust architecture as “an enterprise cybersecurity architecture that is based on zero trust principles and designed to prevent data breaches and limit internal lateral movement. Zero trust is not a single architecture but a set of guiding principles for workflow, system design, and operations that can be used to improve the security posture of any classification or sensitivity level.”

Once the cybersecurity architecture design is approved, architects work with programmers, developers, and other IT professionals to create the cybersecurity architecture, integrate existing databases or infrastructure, and check and address the new architecture for errors or inefficiencies.

Cybersecurity architects have many other duties, including performing security reviews, identifying weaknesses in security architecture, and developing a security risk management plan; ensuring that new or developed systems and architectures are consistent with their organization’s cybersecurity architecture guidelines; and creating individual security plans for each IT project. Other responsibilities include creating and implementing cybersecurity policies and best practices; evaluating new services, vendors, applications, and security tools and, if necessary, updating current security methods with new technologies; educating staff regarding the importance of cybersecurity and best practices; and ensuring that all security policies and procedures are followed.

Related Professions
Featured Companies