Full Time
$4,000
40
Sep 16, 2026
SENIOR CYBERSECURITY ARCHITECT - TWO COMPANIES OPERATING IN TANDEM
Remote, Philippines. One-month fixed-fee build, then a second scoped engagement.
USD 3,500 flat for the first build, plus USD 500 if you start within 5 business days and clear the day-14 milestone. The second engagement and ongoing oversight are priced from the risk assessment you write. About PHP 220,000 for the month - the upper end of the Philippine security-architect range - and a contractor fee rather than a salary: no employer contributions, no 13th month, Philippine taxes yours.
THE CLIENTS
A U.S. law firm holding Protected Health Information and privileged work product: fewer than 12 remote staff, Microsoft 365, client files syncing from the cloud, no enforced control layer yet.
And a professional services and software development company that builds and operates the firm's systems, already has written security policies and a security lead who validates implementations against ISO 27001 and NIST CSF, and needs working access to the firm's files.
They remain separate entities with separate agreements and no commingling of data. You recommend, then build and configure - hands-on, not advisory. Both are identified to finalists once the confidentiality agreements are signed.
WHAT YOU D
1) SEPARATING DEVELOPMENT FROM PRIVILEGED DATA
Developers can reach real client files today, and the same product will later be sold to other firms. Design the end state without stopping the work:
- Development, test and production separated.
- Lower environments on synthetic or de-identified data.
- Production support access that is named, approved, time-limited and logged, with no shared or service accounts standing in for people.
- Bulk export blocked and detectable.
- An architecture in which no client data can travel with the product when it is sold.
- A recommendation, defended: one tenant with strict separation, or two tenants with governed cross-tenant access?
2) ACCESS TIERS FOR THE FIRM
Two or three tiers, enforced in technology rather than in a policy nobody can audit:
- Bottom tier: entry-level records and intake staff with turnover. Minimum-necessary access scoped to assigned matters, no local copies, downloads, removable media or printing, full activity logging.
- Middle tier: case staff working matters end to end, with nothing resting on the endpoint.
- Top tier: attorney and owner, with administrative rights held separately from daily-use accounts.
Tell us whether two or three is right, then build it. Cheap to administer beats elegant - a non-technical owner has to operate and audit this after handoff.
3) THE PLATFORM
Harden the current laptops under Microsoft 365 Business Premium, move compute and data off the endpoint with Cloud PCs or virtual desktops, use browser-only access on locked-down devices, or apply different models by tier. On files: does Google Drive stay on a plan and configuration that holds with a signed business associate agreement, or do files consolidate onto SharePoint and OneDrive alongside identity and mail? We lean toward Business Premium and want an architect's independent view, not a reseller's: whether it suffices, where exactly it stops, what add-ons it needs, and all-in cost per seat and per tier.
BUILD ONE - THE LAW FIRM. 80 TO 120 HOURS
The build implements what we approve. If your recommendation needs more hours than this band, quote it and we will scope a change order rather than squeeze it.
- ACCESS TIERS AND ENVIRONMENT SEPARATION implemented, with a written matrix of who can reach what and how it is audited.
- ENDPOINT AND DATA-LOCATION MODEL implemented for staff, per the approved recommendation.
- FILES: migration to the chosen platform with history intact, permissions plus external-sharing and link-expiry controls, sync blocked on unmanaged devices, retention and legal hold, ransomware recovery, audit-log retention, and a signed business associate agreement with the provider.
-
- IDENTITY AND ENDPOINTS: MFA everywhere, phishing-resistant for admins, conditional access baseline, legacy authentication off, least-privilege roles, break-glass account held by the owner; and an Intune-or-equivalent baseline on every machine - encryption, EDR alerting, patch enforcement.
- CLOSING DELIVERABLES: a cybersecurity risk assessment with prioritized action plans; a WORKING i
We pay for the licensing and tooling your design requires, within a budget agreed before you build.
BUILD TWO - THE SOFTWARE COMPANY
Scoped separately from your assessment: controls satisfying policies already written, validated with the security lead, plus the secure development lifecycle for a product sold to other firms. Not guaranteed, genuinely intended.
WHAT ONGOING WORK LOOKS LIKE
Program oversight, i
The first build is fixed-fee with no guaranteed second month, so do not leave a job for it. If the work continues, we intend to employ you through an established Philippine employer of record with SSS, PhilHealth, Pag-IBIG, 13th month pay and statutory leave. An intention, not a promise.
YOU
- 8+ years in security, 3+ where you personally configured what you designed.
- Microsoft 365 and Entra ID depth: conditional access, Defender, Intune, Purview, mail flow, DMARC to enforcement on a live domain. Plus fluency in licensing boundaries - Business Premium versus E3 and E5, and what needs an add-on. We spend on your advice.
- Windows 365, Azure Virtual Desktop or an equivalent virtual-desktop deployment taken to production.
- Development, test and production separation in a regulated environment, using de-identified or synthetic data and just-in-time, logged privileged access. Plus cross-tenant governance between organizations that collaborate without merging.
- Role-based access implemented for tiered or offshore staff, with least-privilege scoping and audit.
- Enterprise file sync and storage at the policy level - SharePoint and OneDrive, or Dropbox Business or similar - including a migration you ran yourself.
- ISO 27001 and NIST CSF in practice: controls implemented against someone else's written policy, not your own preference.
- Monitoring and alerting you stood up and tuned, with one i
- Excellent written English, a habit of documenting without being asked, and availability to start within 5 business days and finish inside one month with reliable internet, backup connectivity and backup power.
- Preferred: current CISSP, CISM, CCSP, OSCP, GIAC or Microsoft security certification; legal, medical or financial client data; the Philippine Data Privacy Act.
CONDITIONS
Before any access you sign confidentiality, work-product and data-processing agreements with each company directly, work only from a company-provided managed device or virtual desktop, hold a named admin account that is never the only Global Administrator, and pass certification and reference checks. No subcontracting, and no client data into any third-party or AI service without written authorization. No exclusivity, but disclose any engagement adverse to either company.
PAY AND MILESTONES
- USD 1,200 - signed scope, accepted tier and separation design, platform recommendation.
- USD 1,300 - day 14: DMARC at quarantine, MFA and conditional access live, endpoint baseline and records tier deployed.
- USD 1,000 - final acceptance: all deliverables, runbook included.
- USD 500 - fast-start bonus: started within 5 business days, day 14 met on time.
Out-of-scope work is a change order. Full terms go to shortlisted candidates.
Fully remote, likely permanently, on your own hours plus one weekly live hour with the owner and security lead, in your morning or evening. If an office opens in Metro Manila or Cebu (Makati, BGC, IT Park) - no sooner than January 2027, und
HOW TO APPLY
Subject line: SENTINEL - Security Architect. Without it, we do not read it.
1. Your CV, certifications with numbers and expiry dates, and two references for the finalist stage.
2. Under 300 words: one security system you personally recommended, configured and put into production - what was exposed before, what you built, how you proved it worked.
3. Under 250 words: how you would separate the software company's development and support from the firm's privileged files, and guarantee no client data ships with the product.
4. Under 200 words: your access-tier model and platform recommendation for the environment described above, with a rough all-in cost per seat.
5. Under 100 words: one tenant with separation, or two with governed cross-tenant access, and why. Is the first build achievable in one month at 80 to 120 hours?
6. Earliest start date, location, connectivity and power setup, confirmation that a weekly live call in your morning or evening works, and a rough monthly range for ongoing oversight of both companies.
Finalists complete a short paid written exercise on a synthetic environment, then a video call with the owner and the security lead. We review applications as they arrive.