Zorky CRMZorky CRM
EN|RU
@termdocs

Security Architect: market

Security Architect — architect specialisation at the intersection of the architect direction and security: designs security at the architecture level — security reference architectures, threat modelling at scale, Zero Trust architecture, security-by-design, security patterns + standards. Unlike a Security Engineer (operations — SIEM / EDR / incident response — see security-engineer) — Security Architect works at the design level: how security is embedded into systems and the enterprise landscape before anything is built. Role family: Security Architect (general — security design for systems / solutions), Senior / Principal Security Architect (enterprise security architecture + strategy), Enterprise Security Architect (org-wide security architecture — Security as a domain inside Enterprise Architecture / TOGAF), Cloud Security Architect (cloud-focused — overlap with Cloud Security), Application Security Architect (secure software design — overlap with AppSec), Zero Trust Architect (rising 2024+ — Zero Trust transformation specialist). Stack 2026: Security architecture frameworks: SABSA (Sherwood Applied Business Security Architecture — main security architecture framework, business-driven, 6-layer model), TOGAF Security Architecture (security as part of enterprise architecture), NIST Cybersecurity Framework (CSF 2.0) (Identify / Protect / Detect / Respond / Recover + Govern), NIST SP 800-53 (security controls catalog), O-ESA (Open Enterprise Security Architecture). Zero Trust: NIST SP 800–207 (Zero Trust Architecture — canonical reference), Zero Trust maturity models (CISA), micro-segmentation, identity-centric security, "never trust, always verify" — main architecture trend 2024–2026. Security domains for architecture: identity & access management architecture (IAM / Zero Trust identity), network security architecture (segmentation / SASE), data security architecture (encryption strategy / key management / DLP / classification), application security architecture (secure SDLC design), cloud security architecture (CSPM / CNAPP design — see cloud-security), infrastructure security. Risk & compliance: risk assessment methodologies, security control selection, compliance-driven architecture (PCI-DSS / ISO 27001 / SOC 2 / GDPR / 152-FZ + 187-FZ — design systems for compliance requirements). Security patterns: secure design patterns, security reference architectures, security controls catalog, defence-in-depth design. Cryptography architecture: encryption strategy (at-rest / in-transit / in-use), key management architecture (HSM / KMS / envelope encryption), PKI design, post-quantum cryptography awareness (rising 2026 — NIST PQC standards). Modelling: ArchiMate (security overlay), C4 model (security views), data flow diagrams for threat modelling. Engineering background: Security Architect — typically ex-Security Engineer / Senior Architect (technical + security credibility needed), but the role is design + strategy + governance oriented. According to Zorky CRM, 18 active openings with explicit security-architect scope (narrow senior niche — real pool is wider due to overlap with Senior Security Engineer / Solutions Architect). Top stack: cloud, azure, agile, sabsa, togaf. 22% remote.

18
open jobs
—
median $/mo
—
observed supply
22%
remote

The Security Architect market currently has 18 open roles, 1 of them freshly observed. Median salary not published. Observed candidate pool — not published.

22% of Security Architect jobs are remote or hybrid. Security architecture work (design + threat modelling + reviews) — remote-friendly. Outsourcers — more remote. Russian banks + state corporations — hybrid/office due to regulatory + clearances (security architecture — sensitive role, especially 187-FZ). Stakeholder-heavy role → hybrid often optimal. International enterprise + consulting — hybrid-standard.

⚠ salary known for 4 of 18 jobs; remote share from 18 with a stated format; 1 counted as fresh observations; trend and hiring difficulty are not shown

Demand and observed supply

Open demand18
Observed supply— not published

⚠ candidates matching a vacancy are not counted yet: demand and the observed pool are shown

Salary distribution

Lower grades in histogram — mis-titled positions.

The chart will appear once enough observations accumulate for this breakdown.

Demand geography

countryjobs
GB6
PL4
US3
PT1
KR1
CA1
IN1

The leader by Security Architect job count is Russia (0 positions). Russia — banks + Russian security vendors + state corporations (187-FZ critical infrastructure) + outsourcers (EPAM Security Practice) dominate. Poland — security-friendly EU hub. Germany — enterprise security. International — security consulting (Big 4 security practices).

⚠ job counts only: salary by country is not published

Used together with

cloud 12azure 6sabsa 4togaf 4aws 4devsecops 3llm 2mlops 2gcp 1active directory 1angular 1java 1

Top Security Architect skills 2026: security architecture frameworks (SABSA main security architecture framework + TOGAF Security Architecture + NIST CSF 2.0 + NIST SP 800-53 controls + O-ESA), Zero Trust (NIST SP 800–207 canonical + CISA Zero Trust Maturity Model + micro-segmentation + identity-centric — main architecture trend 2024–2026), threat modelling (STRIDE + PASTA + LINDDUN + attack trees + MITRE ATT&CK + tools OWASP Threat Dragon / Microsoft Threat Modeling Tool / IriusRisk), security domains for architecture (IAM architecture + network security architecture SASE/segmentation + data security encryption/key management + application security secure SDLC + cloud security architecture CSPM/CNAPP + infrastructure security), risk & compliance (risk assessment + security control selection + compliance-driven architecture PCI-DSS/ISO 27001/SOC 2/GDPR/152-FZ/187-FZ), security patterns (secure design patterns + security reference architectures + defence-in-depth), cryptography architecture (encryption strategy at-rest/in-transit/in-use + key management HSM/KMS + PKI + post-quantum cryptography awareness), modelling (ArchiMate security overlay + C4 model security views + data flow diagrams), risk communication to executives.

Demand by grade

gradejobs
senior6
principal2

Senior-tier role (lower grades = mis-titled; realistic — Senior / Lead). Two entry paths: Senior Security Engineer (6+ years) + architecture thinking, OR Solutions / Software Architect + security specialisation. Then: Senior / Principal Security Architect → either Chief Security Architect / Head of Security Architecture, Enterprise Security Architect, or CISO (Security Architect — main feeder for CISO role).

⚠ demand side only: the grade of the observed pool is unknown for most of it

Employers

Demand is spread across 15 employers. The largest accounts for 11.8%, the top ten for 70.6%; the remaining 29.4% is long tail.

sharevalue
top-111.8%
top-329.4%
top-1070.6%
long tail29.4%

⚠ names are not shown: staffing agencies and end employers are not yet told apart by the classifier

Where Zorky sees this market

Observed across 9 sources; the largest accounts for 27.8% — this market does not rest on a single channel.

A significant share — executive search + internal promotion.

Recent openings

All jobs →

Latest open Security Architect jobs — most recent positions in the sample (narrow senior niche — real market is wider due to overlap with Senior Security Engineer). The full list is in our CRM or via the "see all" link below. For broader view check security-engineer + solutions architect pages.

Adjacent markets

ArchitectureSolutions ArchitectSoftware ArchitectCloud ArchitectData ArchitectEnterprise ArchitectIntegration Architect

Security Architect overlaps with Security Engineer (~50% — Architect design-focused, Engineer operations), Solutions Architect (~40% — Security Architect security-deep specialisation), Enterprise Architect (~50% — Security Architecture domain inside EA), Cloud Security / DevSecOps / AppSec (security implementation specialties), CISO (career destination). Comparison with solutions/software/enterprise/data/integration — in the SiblingSubnichesChart above.

⚠ adjacent markets for comparison are not defined yet

How this is measured
Vacancy
an open job that cleared the quality gate and lists at least two technologies
Observed candidate
a candidate whose stack contains this technology; an aggregate — not a single record leaves the perimeter
Matchable candidate
not counted yet
Window
jobs open at the moment the snapshot was built

About the data

  • Some breakdowns are hidden: their data coverage is not yet sufficient.
  • Statistics are shown only where the sample clears a quality gate.
  • A missing block does not mean a value of zero.

Breakdowns currently hidden: 9.

Data as of 2026-09-27

Direction: Architecture

Related specializations

Cloud ArchitectData ArchitectEnterprise ArchitectIntegration ArchitectSoftware ArchitectSolutions Architect

Frequently asked questions

Answers recompute automatically.

What does a Security Architect Junior, Middle, Senior, or Lead earn?

Security Architect — senior-tier role ("Junior Security Architect" doesn't exist; lower grades = mis-titled — realistic benchmarks see Senior / Lead). Career flow: two entry paths — 1) Senior Security Engineer (6+ years — SIEM / IAM / network security operations) + architecture thinking → Security Architect; 2) Solutions / Software Architect + security specialisation → Security Architect. Then: Senior / Principal Security Architect → either Chief Security Architect / Head of Security Architecture, Enterprise Security Architect (Security domain inside EA), CISO track (Chief Information Security Officer — Security Architect — common path to CISO), or security consulting (Big 4 / specialised).

What stack / skills are most often required of a Security Architect?

Top skills: cloud, azure, agile, sabsa, togaf. Security architecture frameworks: SABSA (Sherwood Applied Business Security Architecture — main security architecture framework, business-driven, 6-layer model), TOGAF Security Architecture, NIST Cybersecurity Framework (CSF 2.0 — Identify / Protect / Detect / Respond / Recover + Govern), NIST SP 800-53 (security controls catalog), O-ESA. Zero Trust: NIST SP 800–207 (Zero Trust Architecture — canonical reference), CISA Zero Trust Maturity Model, micro-segmentation, identity-centric security — main architecture trend 2024–2026. Security domains for architecture: IAM architecture (Zero Trust identity), network security architecture (segmentation / SASE), data security architecture (encryption strategy / key management / DLP / classification), application security architecture (secure SDLC design), cloud security architecture (CSPM / CNAPP design), infrastructure security. Risk & compliance: risk assessment methodologies, security control selection, compliance-driven architecture (PCI-DSS / ISO 27001 / SOC 2 / GDPR / 152-FZ + 187-FZ — design for compliance). Security patterns: secure design patterns, security reference architectures, defence-in-depth design. Cryptography architecture: encryption strategy (at-rest / in-transit / in-use — confidential computing), key management architecture (HSM / KMS / envelope encryption), PKI design, post-quantum cryptography awareness (NIST PQC standards — rising 2026). Modelling: ArchiMate (security overlay), C4 model (security views), data flow diagrams. Broad technical foundation: Security Architect must understand systems / networks / cloud / applications enough to design security across them. Soft skills: risk communication to business / executives, security-vs-usability trade-off articulation, governance facilitation, stakeholder management.

Security Architect vs Security Engineer vs Enterprise Architect vs Solutions Architect — what's the difference?

Security Engineer — operational security: SIEM / EDR operations, incident response, vulnerability management, hands-on security tooling. See Security Engineer (general). Security Architect (this page) — design-level security: designs how security is embedded into systems / enterprise before anything is built — security reference architectures, threat modelling at scale, Zero Trust design, security patterns + standards. Solutions Architect — designs solutions broadly (security is one aspect, not primary). See Solutions Architect. Enterprise Architect — org-wide technology landscape (Security Architecture is one of the domains; Enterprise Security Architect = Security domain within EA). See Enterprise Architect. Reality 2026 (overlap heatmap): Security Architect ↔ Security Engineer: 50% (Architect design-focused, Engineer operations-focused — but both deeply security). Security Architect ↔ Solutions Architect: 40% (Security Architect — security-deep specialisation, often works with Solutions Architects ensuring security in their solutions). Security Architect ↔ Enterprise Architect: 50% (Security Architecture — domain within EA framework). Career flow: two paths into Security Architect — Security Engineer Senior + architecture thinking, OR Solutions / Software Architect + security specialisation. Security Architect → often → CISO (Chief Information Security Officer — Security Architect — one of the main feeder roles for CISO). Career choice: Security Engineer if you like hands-on operations + incident response; Security Architect if you like design + strategy + threat modelling + designing security-by-design; then CISO if you like security leadership + business risk + executive level.

Security architecture frameworks 2026 — SABSA vs TOGAF Security vs NIST vs Zero Trust?

Decision tree for security architecture approach 2026: 1) SABSA (Sherwood Applied Business Security Architecture) — main dedicated security architecture framework. Business-driven (security architecture derives from business requirements + risk), 6-layer model (Contextual / Conceptual / Logical / Physical / Component / Operational — parallel to Zachman). Pros: comprehensive, business-aligned, vendor-neutral, SABSA certification recognised. Cons: heavy if applied literally. Use case: dedicated security architecture practice, enterprise context — must-know framework for Security Architect. 2) TOGAF Security Architecture — security integrated into general enterprise architecture (TOGAF doesn't have a deep security model on its own, but has security architecture guidance + integration with SABSA — "TOGAF + SABSA" — common combination). Use case: organisations using TOGAF for EA — security as a domain. 3) NIST Cybersecurity Framework (CSF 2.0, 2024) — risk-based, 6 functions (Govern / Identify / Protect / Detect / Respond / Recover). NOT an architecture framework strictly — risk management framework, but widely used for structuring security programmes. NIST SP 800-53 — detailed security controls catalog (what specifically to implement). Use case: structuring security capabilities + controls selection, US-influenced organisations. 4) Zero Trust Architecture (NIST SP 800–207) — main architecture trend 2024–2026. Not a framework in the SABSA sense, but an architecture model / philosophy: "never trust, always verify", elimination of implicit trust based on network location, per-resource access decisions, continuous verification, micro-segmentation, identity-centric. Drivers: remote work (perimeter dissolved), cloud (apps outside datacenter), supply chain attacks, US Executive Order 14028 mandate. CISA Zero Trust Maturity Model — roadmap. Use case 2026: Zero Trust — this is WHAT a modern Security Architect designs (target architecture); SABSA / TOGAF — this is HOW (methodology). 5) O-ESA (Open Enterprise Security Architecture), OSA (Open Security Architecture) — alternative / supplementary. Default 2026 recommendations: know SABSA (dedicated security architecture framework — methodology + certification value), apply Zero Trust Architecture (NIST SP 800–207 — target state of modern security architecture), use NIST CSF for programme structuring + SP 800-53 for controls, integrate with TOGAF if the organisation is on TOGAF EA. Reality: "SABSA / TOGAF — methodology, Zero Trust — target architecture, NIST — controls reference". Modern Security Architect balances framework rigour with pragmatic Zero Trust transformation.

Can Security Architects work remotely?

Yes, 22% of Security Architect jobs are full-remote or hybrid. Security architecture work — design + threat modelling + documentation + reviews — technically remote-friendly. Outsourcers — more remote. Russian banks + state corporations — hybrid/office due to regulatory + security clearances (security architecture — sensitive role, especially for 187-FZ critical infrastructure). Russian security vendors — hybrid. International enterprise + security consulting — hybrid-standard. Caveat: Security Architect — stakeholder-heavy role (security reviews + threat modelling workshops + risk communication to executives) — hybrid often optimal. Relocant hubs: Poland / Germany / Canada / UAE. English for international Security Architect remote — must (security frameworks + standards — NIST / SABSA — English-language, executive risk communication in English).

How is Zero Trust Architect (rising 2024+) different from Security Architect?

Security Architect (general) — broad security architecture: designs security across all domains (IAM / network / data / application / cloud / infrastructure). Zero Trust Architect (rising specialty 2024+) — focus specifically on Zero Trust transformation: leads the organisation's transition from perimeter-based security model to Zero Trust architecture. Day-to-day: 1) Zero Trust maturity assessment (where the organisation is now — CISA Zero Trust Maturity Model — 5 pillars: Identity / Devices / Networks / Applications / Data), 2) Zero Trust roadmap design (incremental — you can't "turn on Zero Trust" at once), 3) Identity-centric security architecture (identity as primary perimeter — IAM / MFA / conditional access integration), 4) Micro-segmentation strategy (network — Illumio / Cisco / etc.), 5) ZTNA / SASE architecture (replace VPN — Zscaler / Cloudflare / Palo Alto Prisma), 6) Device trust + posture, 7) Continuous verification design, 8) Policy engine architecture (centralised access decisions). Drivers: remote work permanence, cloud migration, supply chain attacks, regulatory push (US EO 14028, similar trends elsewhere). Pay: Zero Trust Architect — premium for rising-demand specialty, comparable / higher than general Security Architect. Reality 2026: Zero Trust — not always a separate role, more often specialisation / focus area within Security Architect (like Software Architect doing microservices — part of work, not a separate profession). But in large organisations during Zero Trust transformation — this can be a dedicated role for 2-4 years of programme. Career flow: Security Architect + Zero Trust transformation project experience → Zero Trust Architect / Zero Trust transformation lead.

Where to start the path to Security Architect in 2026?

Roadmap (Security Architect — senior-tier, two entry paths): Path A (from security): 1) Become Senior Security Engineer (6+ years — SIEM / IAM / network security / cloud security operations). 2) Develop architecture thinking — design-level, not just operations. Path B (from architecture): 1) Become Solutions / Software Architect. 2) Specialise deeply in security. Common roadmap: 1) Security fundamentals deep — OWASP Top 10, cryptography (applied), network security, IAM, cloud security — broad foundation across security domains. 2) CISSP (Certified Information Systems Security Professional — ISC² — de-facto senior security cert) → CISSP-ISSAP (Information Systems Security Architecture Professional — architecture concentration — most relevant for Security Architect). 3) SABSA certification (SABSA Foundation → Practitioner — dedicated security architecture framework). 4) TOGAF (if you work in enterprise architecture context — security as a domain). 5) Threat modelling mastery — STRIDE + PASTA + attack trees + MITRE ATT&CK. Practice on real systems. Book: "Threat Modeling: Designing for Security" Adam Shostack (canonical). 6) Zero Trust deep — NIST SP 800–207 (Zero Trust Architecture) + CISA Zero Trust Maturity Model. This is the main modern security architecture target. 7) NIST frameworks — Cybersecurity Framework (CSF 2.0) + SP 800-53 controls catalog. 8) Security domains breadth — IAM architecture, network security architecture (SASE / segmentation), data security (encryption / key management), cloud security architecture, application security architecture. 9) Compliance-driven architecture — how to design for PCI-DSS / ISO 27001 / SOC 2 / GDPR / 152-FZ / 187-FZ. 10) Cryptography architecture — encryption strategy, key management (HSM / KMS), PKI, post-quantum cryptography awareness (NIST PQC). 11) Risk communication — translate technical risk into business language for executives — critical skill. 12) Practice — in current role take security architecture tasks: threat modelling sessions, security design reviews, security reference architecture proposals. International (EN): SABSA official training, (ISC)² CISSP / CISSP-ISSAP training, SANS security architecture courses (SEC530 Defensible Security Architecture), "Threat Modeling" Adam Shostack, NIST publications (SP 800–207 Zero Trust + CSF — free), "Zero Trust Networks" Gilman / Barth. Senior Security Engineer / Architect (6+ years) + CISSP-ISSAP + SABSA + threat modelling mastery → Security Architect.

How many Security Architect jobs are open across CIS and Europe?

18 active open Security Architect positions with explicit security-architect scope — narrow senior niche. The real market is wider — many security-architecture roles classified as Senior Security Engineer / Solutions Architect (security-focused) / Security Lead. Geography: Russia / Poland / remote. A significant share of Security Architect jobs — executive search + internal promotion (organisations grow Security Architects from Senior Security Engineers). Time to close a Senior Security Architect — 8-16 weeks (seniority + security depth + architecture skills + extensive vetting due to role sensitivity).

What skills does a Senior Security Architect need?

A Senior Security Architect owns the full security architecture + technical leadership cycle. Security architecture frameworks mastery: SABSA (business-driven security architecture — 6-layer model), TOGAF Security Architecture integration, NIST CSF 2.0 + SP 800-53 controls, O-ESA. Zero Trust architecture mastery: NIST SP 800–207 deep, CISA Zero Trust Maturity Model, design Zero Trust transformation roadmaps, identity-centric architecture, micro-segmentation, ZTNA / SASE design. Threat modelling mastery: STRIDE + PASTA + LINDDUN + attack trees + MITRE ATT&CK threat-informed defence — lead threat modelling sessions for complex systems. Security domains breadth + depth: IAM architecture (Zero Trust identity), network security architecture (segmentation / SASE / NDR), data security architecture (encryption strategy / key management / DLP / classification), application security architecture (secure SDLC), cloud security architecture (CSPM / CNAPP), infrastructure security. Cryptography architecture: encryption strategy (at-rest / in-transit / in-use — confidential computing), key management architecture (HSM / KMS / envelope encryption), PKI design, post-quantum cryptography migration planning (NIST PQC standards). Risk & compliance: risk assessment methodologies, security control selection, compliance-driven architecture (PCI-DSS / ISO 27001 / SOC 2 / GDPR / 152-FZ / 187-FZ), risk quantification. Security patterns: secure design patterns, security reference architecture development, defence-in-depth design, security architecture governance. Broad technical foundation: sufficient understanding of systems / networks / cloud / applications / data to design security across them (Security Architect — broad, not deep in one domain). Architecture modelling: ArchiMate (security overlay), C4 model (security views), data flow diagrams for threat modelling. System design for security: design secure architecture on whiteboard, design Zero Trust transformation, design enterprise security architecture, design secure-by-default platforms. Risk communication — critical: translate technical security risk into business language for executives / board, articulate security-vs-usability-vs-cost trade-offs, security investment business cases. Soft skills: stakeholder management, security architecture governance facilitation (security review boards), influence without authority, mentoring Security Engineers, working with development teams (security-by-design — partnership needed, not gatekeeping). English for Senior+ MUST — security frameworks / standards (NIST / SABSA / ISO) + executive communication are English-language in international context. Certifications: CISSP / CISSP-ISSAP (architecture concentration), SABSA, TOGAF, cloud security certs. Optional bonus: Zero Trust transformation track record, conference speaking (RSA / security architecture), published security architecture thought leadership — sharply increase market value for Chief Security Architect / CISO track.

Leave a request

Describe the task and leave a contact — the request goes to our CRM and we reply at the contact you provide.