You will define and drive enterprise security architecture across Zero Trust, identity, network, endpoint, SaaS, infrastructure, mobile, and operational technology. You will create security standards, reference architectures, and decision records; lead architecture reviews; identify risks and remediation roadmaps; and provide technical direction for strategic security programs.
Responsibilities
- Define and maintain enterprise security architecture across Zero Trust, identity, network, endpoint, SaaS, infrastructure, mobile, and operational technology domains.
- Author and govern security architecture principles, reference designs, and technical standards.
- Drive alignment across Security Operations, Corporate Technology, Information Engineering, and Integrated IT teams.
- Identify architectural gaps and emerging threat vectors and prescribe remediation roadmaps.
- Provide architecture leadership for Zero Trust maturity, identity consolidation, SaaS governance, and device trust initiatives.
- Define Zero Trust and Device Trust architecture, including network segmentation, ZTNA policies, and enforcement models.
- Architect secure remote access controls using Cloudflare WARP/Access or equivalent tools.
- Design network security for office and data center environments, including SD-WAN, firewall policy, 802.1X, and DNS security.
- Establish microsegmentation, East-West traffic inspection, and lateral movement prevention standards.
- Own enterprise identity architecture, including federation, provisioning, MFA, PAM, and lifecycle governance.
- Design device trust and certificate-based authentication frameworks.
- Define RBAC architecture and Joiner-Mover-Leaver automation patterns.
- Architect identity federation for M&A integrations, partners, and customer-facing systems.
- Define endpoint security architecture across macOS, Windows, and mobile platforms.
- Design mobile device management for corporate and BYOD scenarios.
- Establish endpoint hardening, application allow-listing, DLP, and removable media standards.
- Provide architectural oversight for remote management tooling and security controls.
- Define SaaS security programs, vendor risk frameworks, integration standards, and posture monitoring.
- Architect CASB, SSPM, and SaaS access governance controls.
- Establish data classification and DLP architecture for SaaS environments.
- Design AI and shadow SaaS governance controls.
- Define security standards for on-premise and cloud-hosted internal infrastructure.
- Architect logging, SIEM integration, and telemetry collection frameworks.
- Design disaster recovery and resilience architecture for critical corporate infrastructure.
- Develop OT security standards for physical and building systems.
- Define OT segmentation and monitoring architecture.
- Establish vulnerability management frameworks for OT assets.
- Maintain enterprise security architecture documentation and domain reference architectures.
- Conduct security architecture reviews for technology programs, vendor, and infrastructure changes.
- Define security requirements and acceptance criteria for strategic projects.
- Produce architecture decision records and reusable security design patterns.
Requirements
- 8+ years of information security experience, including at least 4 years in security architecture, security engineering leadership, or an equivalent senior technical role.
- Expertise designing and implementing enterprise Zero Trust architectures, including ZTNA, identity-aware access, and microsegmentation.
- Knowledge of identity and access management, including Okta or equivalent, SAML, OIDC, SCIM, MFA, PAM, and certificate-based authentication.
- Endpoint security architecture experience across macOS and Windows, including EDR, MDM, and patch management.
- Experience architecting SaaS security programs, including vendor risk frameworks, CASB and SSPM tooling, and OAuth or API integration controls.
- Understanding of network security architecture, including firewalls, SD-WAN, 802.1X, DNS security, and network segmentation.
- Familiarity with OT and IoT security architecture.
- Ability to produce security architecture documentation, reference architectures, design patterns, and ADRs.
- Ability to present complex security topics to technical and senior non-technical stakeholders.
- CISSP, SABSA, CCSP, or equivalent architecture or security certification.
- Experience with post-M&A multi-tenant identity and infrastructure consolidation.
- Familiarity with Cloudflare Access/WARP, Meraki, CrowdStrike Falcon, Kandji, Qualys VMDR, or Drata/GRC.
- Experience designing AI governance and shadow SaaS controls.
- Experience in regulated industries or with SOC 2, ISO 27001, or FedRAMP compliance frameworks.