The Roles · Who defends it

Security architect

Written from published sources

The person who decides how a system will be defended before it exists. An architect works in drawings and decisions rather than in configuration: which trust boundaries the design has, what each one is enforced by, what happens when a component is compromised, and which controls are load-bearing rather than decorative. The output is a design somebody else builds, and a set of arguments for why it is shaped that way.

What the day looks like

  • Reading a proposed design and finding the boundary that is assumed rather than enforced.
  • Choosing between controls that overlap, and saying which one the design depends on when both are present.
  • Writing the pattern down so that ten teams solve the problem the same way rather than ten ways.
  • Sitting in a review where the honest answer is that the risk is acceptable, and recording why.
  • Revisiting a decision made two years ago against a threat that did not exist then.

What it answers for

  • A design whose failure modes were considered before it was built.
  • Control choices that are justified against a stated threat rather than a product feature.
  • Patterns that the teams building them can actually implement.

What it is measured on

  • Designs that survive their first real incident without a redesign.
  • Adoption of the patterns, which is the only proof they were usable.
  • Exceptions requested, which measures whether the architecture fits the organisation it serves.

Who it receives from

The business
What is being built, and the deadline it is being built against.
Risk and compliance
The obligations the design has to satisfy, and their real deadlines.
Engineering
What is actually deployable here, as distinct from what is theoretically correct.

Who it serves

Security engineers
A design specific enough to build without guessing.
Network and platform teams
Boundaries and requirements they can implement in their own systems.
Auditors
A written rationale that answers why, not only what.

Who else has a stake

  • The teams who will operate the result long after the architect has moved to the next design.
  • Procurement, whose purchase is constrained by an architectural decision they did not attend.
  • Whoever inherits the exception register, which is the true record of where the architecture bent.

What it takes

  • Enough depth in networks, identity and platforms to be wrong in front of specialists and recover.
  • The judgement to accept a risk deliberately rather than escalating everything.
  • Writing. An architecture that exists only in conversation is not an architecture.
  • Tolerance for being overruled commercially, and the discipline to record the decision anyway.

What the job turns on

The architect is accountable for decisions made before anyone can prove them wrong. That is the whole difficulty: the work is judged years later, by an incident, against a threat model written when the budget was set.

The published sources

Where it leads

Roles that lead here

The work itself

The Practice covers how this work is done — triage, escalation, evidence, handover — across the whole corpus.

Read The Practice