Overview
As Expert Associate Partner, Architecture (Cybersecurity), you lead security-architecture workstreams for large transformations. You will design enterprise security architectures across cloud, hybrid, OT, and legacy environments and partner with C-suite stakeholders to align security with business goals. The role combines hands-on technical leadership with advisory excellence to shape security strategy and transformation programs. You’ll mentor teams, stay ahead of vendor trends, and contribute to Bain’s security offerings.
Responsibilities
- Own cybersecurity architecture workstreams in large client transformation programmes
- Design and deliver security architectures across cloud, hybrid, OT, and legacy environments
- Engage with CISO, CIO, and sponsors to shape security strategy and gain credibility as a technical peer
- Sit on project leadership team and represent security across business and technology workstreams
- Manage and direct teams of architects and consultants day-to-day
- Produce as-is/to-be security architecture documentation, risk assessments, and migration artefacts
- Identify client opportunities, develop security-focused viewpoints, and support account expansion
- Lead multi-million security transformation programmes from scoping to delivery
- Coach and develop junior architects and consultants
- Stay current on vendor landscape to shape Bain’s security offerings
- Review security architectures and vendor proposals, stress-test assumptions and provide independent view
Key requirements
- 15+ years in cybersecurity with hands-on and strategic experience
- Deep expertise in at least one domain (cloud security, IAM, SOC) and broad knowledge across the landscape
- Experience designing and delivering security architecture in large, complex organisations
- Comfort with workshops, executive presentations, and writing for senior audiences
- Ability to discuss security strategy with CIO/CISO including operating model and risk appetite
- Experience beyond architecture (operating model design, capability building, governance)
- Ability to work in ambiguity and bring structure to client problems
- Familiarity with frameworks (NIST CSF, ISO 27001, SABSA, MITRE ATT&CK, NIS2) and cloud platforms (Azure, AWS, GCP)
- Translate technical risk into business risk statements for executives
- Experience scoping and structuring engagements, managing scope and delivery risk
- Clear communication with both technical and non-technical stakeholders
- Threat modelling with STRIDE; legacy-debt modernization experience
- Hands-on or advisory experience in IAM/PAM, vulnerability management, incident response, SIEM, business continuity
- Experience with cloud landing zones, data security (DLP, classification, cryptographic controls), and telemetry/observability
- Knowledge of AI and automation in security architecture
- Executive communication
- client advising
- leadership and mentorship
- Cloud security architecture (Azure, AWS, GCP)
- IAM/PAM, vulnerability management, incident response, SIEM
- Threat modelling (STRIDE)
…
