Security Architect: market
Security Architect — architect specialisation at the intersection of the architect direction and security: designs security at the architecture level — security reference architectures, threat modelling at scale, Zero Trust architecture, security-by-design, security patterns + standards. Unlike a Security Engineer (operations — SIEM / EDR / incident response — see security-engineer) — Security Architect works at the design level: how security is embedded into systems and the enterprise landscape before anything is built. Role family: Security Architect (general — security design for systems / solutions), Senior / Principal Security Architect (enterprise security architecture + strategy), Enterprise Security Architect (org-wide security architecture — Security as a domain inside Enterprise Architecture / TOGAF), Cloud Security Architect (cloud-focused — overlap with Cloud Security), Application Security Architect (secure software design — overlap with AppSec), Zero Trust Architect (rising 2024+ — Zero Trust transformation specialist). Stack 2026: Security architecture frameworks: SABSA (Sherwood Applied Business Security Architecture — main security architecture framework, business-driven, 6-layer model), TOGAF Security Architecture (security as part of enterprise architecture), NIST Cybersecurity Framework (CSF 2.0) (Identify / Protect / Detect / Respond / Recover + Govern), NIST SP 800-53 (security controls catalog), O-ESA (Open Enterprise Security Architecture). Zero Trust: NIST SP 800–207 (Zero Trust Architecture — canonical reference), Zero Trust maturity models (CISA), micro-segmentation, identity-centric security, "never trust, always verify" — main architecture trend 2024–2026. Security domains for architecture: identity & access management architecture (IAM / Zero Trust identity), network security architecture (segmentation / SASE), data security architecture (encryption strategy / key management / DLP / classification), application security architecture (secure SDLC design), cloud security architecture (CSPM / CNAPP design — see cloud-security), infrastructure security. Risk & compliance: risk assessment methodologies, security control selection, compliance-driven architecture (PCI-DSS / ISO 27001 / SOC 2 / GDPR / 152-FZ + 187-FZ — design systems for compliance requirements). Security patterns: secure design patterns, security reference architectures, security controls catalog, defence-in-depth design. Cryptography architecture: encryption strategy (at-rest / in-transit / in-use), key management architecture (HSM / KMS / envelope encryption), PKI design, post-quantum cryptography awareness (rising 2026 — NIST PQC standards). Modelling: ArchiMate (security overlay), C4 model (security views), data flow diagrams for threat modelling. Engineering background: Security Architect — typically ex-Security Engineer / Senior Architect (technical + security credibility needed), but the role is design + strategy + governance oriented. According to Zorky CRM, 18 active openings with explicit security-architect scope (narrow senior niche — real pool is wider due to overlap with Senior Security Engineer / Solutions Architect). Top stack: cloud, azure, agile, sabsa, togaf. 22% remote.
The Security Architect market currently has 18 open roles, 1 of them freshly observed. Median salary not published. Observed candidate pool — not published.
22% of Security Architect jobs are remote or hybrid. Security architecture work (design + threat modelling + reviews) — remote-friendly. Outsourcers — more remote. Russian banks + state corporations — hybrid/office due to regulatory + clearances (security architecture — sensitive role, especially 187-FZ). Stakeholder-heavy role → hybrid often optimal. International enterprise + consulting — hybrid-standard.
⚠ salary known for 4 of 18 jobs; remote share from 18 with a stated format; 1 counted as fresh observations; trend and hiring difficulty are not shown
Demand and observed supply
| Open demand | 18 |
| Observed supply | — not published |
⚠ candidates matching a vacancy are not counted yet: demand and the observed pool are shown
Salary distribution
Lower grades in histogram — mis-titled positions.
The chart will appear once enough observations accumulate for this breakdown.
Demand geography
| country | jobs |
|---|---|
| GB | 6 |
| PL | 4 |
| US | 3 |
| PT | 1 |
| KR | 1 |
| CA | 1 |
| IN | 1 |
The leader by Security Architect job count is Russia (0 positions). Russia — banks + Russian security vendors + state corporations (187-FZ critical infrastructure) + outsourcers (EPAM Security Practice) dominate. Poland — security-friendly EU hub. Germany — enterprise security. International — security consulting (Big 4 security practices).
⚠ job counts only: salary by country is not published
Used together with
Top Security Architect skills 2026: security architecture frameworks (SABSA main security architecture framework + TOGAF Security Architecture + NIST CSF 2.0 + NIST SP 800-53 controls + O-ESA), Zero Trust (NIST SP 800–207 canonical + CISA Zero Trust Maturity Model + micro-segmentation + identity-centric — main architecture trend 2024–2026), threat modelling (STRIDE + PASTA + LINDDUN + attack trees + MITRE ATT&CK + tools OWASP Threat Dragon / Microsoft Threat Modeling Tool / IriusRisk), security domains for architecture (IAM architecture + network security architecture SASE/segmentation + data security encryption/key management + application security secure SDLC + cloud security architecture CSPM/CNAPP + infrastructure security), risk & compliance (risk assessment + security control selection + compliance-driven architecture PCI-DSS/ISO 27001/SOC 2/GDPR/152-FZ/187-FZ), security patterns (secure design patterns + security reference architectures + defence-in-depth), cryptography architecture (encryption strategy at-rest/in-transit/in-use + key management HSM/KMS + PKI + post-quantum cryptography awareness), modelling (ArchiMate security overlay + C4 model security views + data flow diagrams), risk communication to executives.
Demand by grade
| grade | jobs |
|---|---|
| senior | 6 |
| principal | 2 |
Senior-tier role (lower grades = mis-titled; realistic — Senior / Lead). Two entry paths: Senior Security Engineer (6+ years) + architecture thinking, OR Solutions / Software Architect + security specialisation. Then: Senior / Principal Security Architect → either Chief Security Architect / Head of Security Architecture, Enterprise Security Architect, or CISO (Security Architect — main feeder for CISO role).
⚠ demand side only: the grade of the observed pool is unknown for most of it
Employers
Demand is spread across 15 employers. The largest accounts for 11.8%, the top ten for 70.6%; the remaining 29.4% is long tail.
| share | value |
|---|---|
| top-1 | 11.8% |
| top-3 | 29.4% |
| top-10 | 70.6% |
| long tail | 29.4% |
⚠ names are not shown: staffing agencies and end employers are not yet told apart by the classifier
Where Zorky sees this market
Observed across 9 sources; the largest accounts for 27.8% — this market does not rest on a single channel.
A significant share — executive search + internal promotion.
Recent openings
- Principal Security Architect — DevSecOps · GB · $6,199
- Information Security Architect · PL
- Information Security Architect · PT
- Enterprise Security Architect · PL
- Security Architect · GB · $5,332
- Staff, AI Security Architect · KR
- Senior Zero Trust / Enterprise Security Architect · US · $14,167
- Artificial Intelligence Security Architect · CA
Latest open Security Architect jobs — most recent positions in the sample (narrow senior niche — real market is wider due to overlap with Senior Security Engineer). The full list is in our CRM or via the "see all" link below. For broader view check security-engineer + solutions architect pages.
Adjacent markets
Security Architect overlaps with Security Engineer (~50% — Architect design-focused, Engineer operations), Solutions Architect (~40% — Security Architect security-deep specialisation), Enterprise Architect (~50% — Security Architecture domain inside EA), Cloud Security / DevSecOps / AppSec (security implementation specialties), CISO (career destination). Comparison with solutions/software/enterprise/data/integration — in the SiblingSubnichesChart above.
⚠ adjacent markets for comparison are not defined yet
How this is measured
- Vacancy
- an open job that cleared the quality gate and lists at least two technologies
- Observed candidate
- a candidate whose stack contains this technology; an aggregate — not a single record leaves the perimeter
- Matchable candidate
- not counted yet
- Window
- jobs open at the moment the snapshot was built
About the data
- Some breakdowns are hidden: their data coverage is not yet sufficient.
- Statistics are shown only where the sample clears a quality gate.
- A missing block does not mean a value of zero.
Breakdowns currently hidden: 9.
Data as of 2026-09-27
Direction: Architecture
Related specializations
Frequently asked questions
Answers recompute automatically.
What does a Security Architect Junior, Middle, Senior, or Lead earn?
Security Architect — senior-tier role ("Junior Security Architect" doesn't exist; lower grades = mis-titled — realistic benchmarks see Senior / Lead). Career flow: two entry paths — 1) Senior Security Engineer (6+ years — SIEM / IAM / network security operations) + architecture thinking → Security Architect; 2) Solutions / Software Architect + security specialisation → Security Architect. Then: Senior / Principal Security Architect → either Chief Security Architect / Head of Security Architecture, Enterprise Security Architect (Security domain inside EA), CISO track (Chief Information Security Officer — Security Architect — common path to CISO), or security consulting (Big 4 / specialised).
What stack / skills are most often required of a Security Architect?
Top skills: cloud, azure, agile, sabsa, togaf. Security architecture frameworks: SABSA (Sherwood Applied Business Security Architecture — main security architecture framework, business-driven, 6-layer model), TOGAF Security Architecture, NIST Cybersecurity Framework (CSF 2.0 — Identify / Protect / Detect / Respond / Recover + Govern), NIST SP 800-53 (security controls catalog), O-ESA. Zero Trust: NIST SP 800–207 (Zero Trust Architecture — canonical reference), CISA Zero Trust Maturity Model, micro-segmentation, identity-centric security — main architecture trend 2024–2026. Security domains for architecture: IAM architecture (Zero Trust identity), network security architecture (segmentation / SASE), data security architecture (encryption strategy / key management / DLP / classification), application security architecture (secure SDLC design), cloud security architecture (CSPM / CNAPP design), infrastructure security. Risk & compliance: risk assessment methodologies, security control selection, compliance-driven architecture (PCI-DSS / ISO 27001 / SOC 2 / GDPR / 152-FZ + 187-FZ — design for compliance). Security patterns: secure design patterns, security reference architectures, defence-in-depth design. Cryptography architecture: encryption strategy (at-rest / in-transit / in-use — confidential computing), key management architecture (HSM / KMS / envelope encryption), PKI design, post-quantum cryptography awareness (NIST PQC standards — rising 2026). Modelling: ArchiMate (security overlay), C4 model (security views), data flow diagrams. Broad technical foundation: Security Architect must understand systems / networks / cloud / applications enough to design security across them. Soft skills: risk communication to business / executives, security-vs-usability trade-off articulation, governance facilitation, stakeholder management.
Security Architect vs Security Engineer vs Enterprise Architect vs Solutions Architect — what's the difference?
Security Engineer — operational security: SIEM / EDR operations, incident response, vulnerability management, hands-on security tooling. See Security Engineer (general). Security Architect (this page) — design-level security: designs how security is embedded into systems / enterprise before anything is built — security reference architectures, threat modelling at scale, Zero Trust design, security patterns + standards. Solutions Architect — designs solutions broadly (security is one aspect, not primary). See Solutions Architect. Enterprise Architect — org-wide technology landscape (Security Architecture is one of the domains; Enterprise Security Architect = Security domain within EA). See Enterprise Architect. Reality 2026 (overlap heatmap): Security Architect ↔ Security Engineer: 50% (Architect design-focused, Engineer operations-focused — but both deeply security). Security Architect ↔ Solutions Architect: 40% (Security Architect — security-deep specialisation, often works with Solutions Architects ensuring security in their solutions). Security Architect ↔ Enterprise Architect: 50% (Security Architecture — domain within EA framework). Career flow: two paths into Security Architect — Security Engineer Senior + architecture thinking, OR Solutions / Software Architect + security specialisation. Security Architect → often → CISO (Chief Information Security Officer — Security Architect — one of the main feeder roles for CISO). Career choice: Security Engineer if you like hands-on operations + incident response; Security Architect if you like design + strategy + threat modelling + designing security-by-design; then CISO if you like security leadership + business risk + executive level.
Security architecture frameworks 2026 — SABSA vs TOGAF Security vs NIST vs Zero Trust?
Decision tree for security architecture approach 2026: 1) SABSA (Sherwood Applied Business Security Architecture) — main dedicated security architecture framework. Business-driven (security architecture derives from business requirements + risk), 6-layer model (Contextual / Conceptual / Logical / Physical / Component / Operational — parallel to Zachman). Pros: comprehensive, business-aligned, vendor-neutral, SABSA certification recognised. Cons: heavy if applied literally. Use case: dedicated security architecture practice, enterprise context — must-know framework for Security Architect. 2) TOGAF Security Architecture — security integrated into general enterprise architecture (TOGAF doesn't have a deep security model on its own, but has security architecture guidance + integration with SABSA — "TOGAF + SABSA" — common combination). Use case: organisations using TOGAF for EA — security as a domain. 3) NIST Cybersecurity Framework (CSF 2.0, 2024) — risk-based, 6 functions (Govern / Identify / Protect / Detect / Respond / Recover). NOT an architecture framework strictly — risk management framework, but widely used for structuring security programmes. NIST SP 800-53 — detailed security controls catalog (what specifically to implement). Use case: structuring security capabilities + controls selection, US-influenced organisations. 4) Zero Trust Architecture (NIST SP 800–207) — main architecture trend 2024–2026. Not a framework in the SABSA sense, but an architecture model / philosophy: "never trust, always verify", elimination of implicit trust based on network location, per-resource access decisions, continuous verification, micro-segmentation, identity-centric. Drivers: remote work (perimeter dissolved), cloud (apps outside datacenter), supply chain attacks, US Executive Order 14028 mandate. CISA Zero Trust Maturity Model — roadmap. Use case 2026: Zero Trust — this is WHAT a modern Security Architect designs (target architecture); SABSA / TOGAF — this is HOW (methodology). 5) O-ESA (Open Enterprise Security Architecture), OSA (Open Security Architecture) — alternative / supplementary. Default 2026 recommendations: know SABSA (dedicated security architecture framework — methodology + certification value), apply Zero Trust Architecture (NIST SP 800–207 — target state of modern security architecture), use NIST CSF for programme structuring + SP 800-53 for controls, integrate with TOGAF if the organisation is on TOGAF EA. Reality: "SABSA / TOGAF — methodology, Zero Trust — target architecture, NIST — controls reference". Modern Security Architect balances framework rigour with pragmatic Zero Trust transformation.
Can Security Architects work remotely?
Yes, 22% of Security Architect jobs are full-remote or hybrid. Security architecture work — design + threat modelling + documentation + reviews — technically remote-friendly. Outsourcers — more remote. Russian banks + state corporations — hybrid/office due to regulatory + security clearances (security architecture — sensitive role, especially for 187-FZ critical infrastructure). Russian security vendors — hybrid. International enterprise + security consulting — hybrid-standard. Caveat: Security Architect — stakeholder-heavy role (security reviews + threat modelling workshops + risk communication to executives) — hybrid often optimal. Relocant hubs: Poland / Germany / Canada / UAE. English for international Security Architect remote — must (security frameworks + standards — NIST / SABSA — English-language, executive risk communication in English).
How is Zero Trust Architect (rising 2024+) different from Security Architect?
Security Architect (general) — broad security architecture: designs security across all domains (IAM / network / data / application / cloud / infrastructure). Zero Trust Architect (rising specialty 2024+) — focus specifically on Zero Trust transformation: leads the organisation's transition from perimeter-based security model to Zero Trust architecture. Day-to-day: 1) Zero Trust maturity assessment (where the organisation is now — CISA Zero Trust Maturity Model — 5 pillars: Identity / Devices / Networks / Applications / Data), 2) Zero Trust roadmap design (incremental — you can't "turn on Zero Trust" at once), 3) Identity-centric security architecture (identity as primary perimeter — IAM / MFA / conditional access integration), 4) Micro-segmentation strategy (network — Illumio / Cisco / etc.), 5) ZTNA / SASE architecture (replace VPN — Zscaler / Cloudflare / Palo Alto Prisma), 6) Device trust + posture, 7) Continuous verification design, 8) Policy engine architecture (centralised access decisions). Drivers: remote work permanence, cloud migration, supply chain attacks, regulatory push (US EO 14028, similar trends elsewhere). Pay: Zero Trust Architect — premium for rising-demand specialty, comparable / higher than general Security Architect. Reality 2026: Zero Trust — not always a separate role, more often specialisation / focus area within Security Architect (like Software Architect doing microservices — part of work, not a separate profession). But in large organisations during Zero Trust transformation — this can be a dedicated role for 2-4 years of programme. Career flow: Security Architect + Zero Trust transformation project experience → Zero Trust Architect / Zero Trust transformation lead.
Where to start the path to Security Architect in 2026?
Roadmap (Security Architect — senior-tier, two entry paths): Path A (from security): 1) Become Senior Security Engineer (6+ years — SIEM / IAM / network security / cloud security operations). 2) Develop architecture thinking — design-level, not just operations. Path B (from architecture): 1) Become Solutions / Software Architect. 2) Specialise deeply in security. Common roadmap: 1) Security fundamentals deep — OWASP Top 10, cryptography (applied), network security, IAM, cloud security — broad foundation across security domains. 2) CISSP (Certified Information Systems Security Professional — ISC² — de-facto senior security cert) → CISSP-ISSAP (Information Systems Security Architecture Professional — architecture concentration — most relevant for Security Architect). 3) SABSA certification (SABSA Foundation → Practitioner — dedicated security architecture framework). 4) TOGAF (if you work in enterprise architecture context — security as a domain). 5) Threat modelling mastery — STRIDE + PASTA + attack trees + MITRE ATT&CK. Practice on real systems. Book: "Threat Modeling: Designing for Security" Adam Shostack (canonical). 6) Zero Trust deep — NIST SP 800–207 (Zero Trust Architecture) + CISA Zero Trust Maturity Model. This is the main modern security architecture target. 7) NIST frameworks — Cybersecurity Framework (CSF 2.0) + SP 800-53 controls catalog. 8) Security domains breadth — IAM architecture, network security architecture (SASE / segmentation), data security (encryption / key management), cloud security architecture, application security architecture. 9) Compliance-driven architecture — how to design for PCI-DSS / ISO 27001 / SOC 2 / GDPR / 152-FZ / 187-FZ. 10) Cryptography architecture — encryption strategy, key management (HSM / KMS), PKI, post-quantum cryptography awareness (NIST PQC). 11) Risk communication — translate technical risk into business language for executives — critical skill. 12) Practice — in current role take security architecture tasks: threat modelling sessions, security design reviews, security reference architecture proposals. International (EN): SABSA official training, (ISC)² CISSP / CISSP-ISSAP training, SANS security architecture courses (SEC530 Defensible Security Architecture), "Threat Modeling" Adam Shostack, NIST publications (SP 800–207 Zero Trust + CSF — free), "Zero Trust Networks" Gilman / Barth. Senior Security Engineer / Architect (6+ years) + CISSP-ISSAP + SABSA + threat modelling mastery → Security Architect.
How many Security Architect jobs are open across CIS and Europe?
18 active open Security Architect positions with explicit security-architect scope — narrow senior niche. The real market is wider — many security-architecture roles classified as Senior Security Engineer / Solutions Architect (security-focused) / Security Lead. Geography: Russia / Poland / remote. A significant share of Security Architect jobs — executive search + internal promotion (organisations grow Security Architects from Senior Security Engineers). Time to close a Senior Security Architect — 8-16 weeks (seniority + security depth + architecture skills + extensive vetting due to role sensitivity).
What skills does a Senior Security Architect need?
A Senior Security Architect owns the full security architecture + technical leadership cycle. Security architecture frameworks mastery: SABSA (business-driven security architecture — 6-layer model), TOGAF Security Architecture integration, NIST CSF 2.0 + SP 800-53 controls, O-ESA. Zero Trust architecture mastery: NIST SP 800–207 deep, CISA Zero Trust Maturity Model, design Zero Trust transformation roadmaps, identity-centric architecture, micro-segmentation, ZTNA / SASE design. Threat modelling mastery: STRIDE + PASTA + LINDDUN + attack trees + MITRE ATT&CK threat-informed defence — lead threat modelling sessions for complex systems. Security domains breadth + depth: IAM architecture (Zero Trust identity), network security architecture (segmentation / SASE / NDR), data security architecture (encryption strategy / key management / DLP / classification), application security architecture (secure SDLC), cloud security architecture (CSPM / CNAPP), infrastructure security. Cryptography architecture: encryption strategy (at-rest / in-transit / in-use — confidential computing), key management architecture (HSM / KMS / envelope encryption), PKI design, post-quantum cryptography migration planning (NIST PQC standards). Risk & compliance: risk assessment methodologies, security control selection, compliance-driven architecture (PCI-DSS / ISO 27001 / SOC 2 / GDPR / 152-FZ / 187-FZ), risk quantification. Security patterns: secure design patterns, security reference architecture development, defence-in-depth design, security architecture governance. Broad technical foundation: sufficient understanding of systems / networks / cloud / applications / data to design security across them (Security Architect — broad, not deep in one domain). Architecture modelling: ArchiMate (security overlay), C4 model (security views), data flow diagrams for threat modelling. System design for security: design secure architecture on whiteboard, design Zero Trust transformation, design enterprise security architecture, design secure-by-default platforms. Risk communication — critical: translate technical security risk into business language for executives / board, articulate security-vs-usability-vs-cost trade-offs, security investment business cases. Soft skills: stakeholder management, security architecture governance facilitation (security review boards), influence without authority, mentoring Security Engineers, working with development teams (security-by-design — partnership needed, not gatekeeping). English for Senior+ MUST — security frameworks / standards (NIST / SABSA / ISO) + executive communication are English-language in international context. Certifications: CISSP / CISSP-ISSAP (architecture concentration), SABSA, TOGAF, cloud security certs. Optional bonus: Zero Trust transformation track record, conference speaking (RSA / security architecture), published security architecture thought leadership — sharply increase market value for Chief Security Architect / CISO track.
Leave a request
Describe the task and leave a contact — the request goes to our CRM and we reply at the contact you provide.