Security engineers deploy and tune controls. Security architects decide which controls exist, where they sit, how they combine and what risk remains after they are in place. The move between the two is a change in the questions you are paid to answer.
Design over configuration
The architect’s output is a design: trust boundaries, control placement, data flows, assumptions and residual risk, written down so others can build, review and audit it. Configuration follows from the design and belongs to engineers.
Risk is the currency
Every decision is a trade between risk reduced, cost incurred and friction added. An architect who cannot express a control in terms of the risk it addresses will lose every budget conversation.
Working across the organisation
Architecture reviews for new systems, standards that teams build against, advice to leadership on risk appetite, and evidence for auditors. The role is as much communication as engineering.
Action Step
Write a one-page charter for a security architect role in an organisation you know: decisions owned, decisions delegated, the forums the role attends and what it produces for each.
This course is vendor-independent: it is not affiliated with, endorsed by or accredited by any tool vendor or certification body, names products only for identification, and issues no credential. Verify current documentation before applying anything in production.