Security Architect
Indexed description
About the Role
We're hiring a senior individual contributor to serve as the embedded security and solution architect for one of our business units. You'll be the person business and delivery teams come to early — when an initiative is still taking shape — to make sure what gets built is secure by design, aligned to enterprise standards, and actually deliverable.
This is a design and advisory role, not a gatekeeping one. You'll own the security architecture perspective on new solutions from intake through production, represent your business unit in architecture and security review boards, and work with Enterprise Architecture, Information Security, platform teams, and vendors to get good designs approved without unnecessary delay. When a solution needs to deviate from an established standard, you'll document the risk, propose mitigations, and drive it through the exception process.
The role is deliberately T-shaped: deep expertise in one or two domains, working fluency across the rest — cloud, identity and access management, network and infrastructure security, data protection, application security, and integrations.
What You'll Do
- Serve as the business-unit-aligned solution architect on new and evolving initiatives, applying security-by-design and security-by-default principles end to end
- Co-author secure solution designs with delivery architects, and validate that non-functional and security requirements are met before solutions reach production
- Identify, assess, and clearly articulate architectural and security risk across data protection, IAM, integration security, infrastructure and network security, logging and monitoring, application security, third-party risk, and resilience
- Represent your business unit in Architecture Review Board sessions and engage the Security Architecture Review Board when specialist input is needed — with packages complete enough to pass on the first attempt
- Author security exception documentation when a design departs from published standards, gathering input from delivery, platform, and cyber risk teams and driving it to a documented risk decision
- Evaluate new technologies for architectural fit, overlap with existing platforms, control gaps, operational impact, and vendor sustainability
- Build and promote reference architectures, patterns, and guardrails that let delivery teams move faster with less bespoke design work; draft new patterns where gaps exist and get them approved by Enterprise Architecture and InfoSec
- Provide technical and security input to RFIs/RFPs, evaluate vendor responses, and hold third parties to enterprise architecture and security expectations
- Partner with delivery teams through execution to interpret architectural intent, resolve design issues, and manage trade-offs as constraints change
- Shape demand early during intake — clarifying scope, routing work, and flagging where architectural involvement is needed
- Mentor less-experienced architects and engineers on the team, and contribute architectural input to business unit planning, budgeting, and forecasting
What Success Looks Like
- Initiatives move forward with clear architectural intent and far fewer late-stage surprises
- Security risk is surfaced early, documented well, and managed intentionally rather than discovered in testing
- Governance reviews are efficient and outcome-focused — packages pass cleanly and time-to-approval trends down
- Delivery teams reuse approved patterns and platforms by choice, because doing so is faster
What You'll Bring
- 5+ years in solution architecture, security architecture, or enterprise architecture, including 5+ years with direct security design accountability
- Demonstrated experience carrying solution designs through a formal architecture or security governance process in a large, federated enterprise
- Hands-on depth in at least one core domain — cloud security, identity and access management, network/infrastructure security, application security, or data protection — with credible working knowledge across the others
- Practical experience designing on [Azure / AWS / GCP], including native security services and shared-responsibility trade-offs
- Fluency with security control frameworks and baseline requirements, and the judgment to distinguish material risk from theoretical risk
- Strong written communication — this role produces design documentation and risk write-ups that executives and auditors read
- Ability to influence without authority across business, IT delivery, platform, security, and vendor stakeholders
- Comfort operating in an Agile environment with heavy cross-team coordination; experience with Azure DevOps or comparable tooling
Preferred
- [CISSP, ISSAP, CCSP, SABSA, TOGAF, or cloud architect certification — specify required vs. preferred]
- Experience in a regulated industry [HIPAA / PCI-DSS / SOX / NERC CIP / other]
- Prior consulting background, or experience in a company with a comparable formal architecture review apparatus
- Experience with vendor/third-party risk assessment and RFP evaluation
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search