Senior Security Architect
Indexed description
At Qnity, we’re more than a global leader in materials and solutions for advanced electronics and high-tech industries – we’re a tight-knit team that is motivated by new possibilities, and always up for a challenge. All our dedicated teams contribute to making cutting-edge technology possible. We value forward-thinking challengers, boundary-pushers, and diverse perspectives across all our departments, because we know we play a critical role in the world enabling faster progress for all. Learn how you can start or jumpstart your career with us.
Qnity is seeking a Senior Security Architect to define secure, practical cybersecurity patterns across our global enterprise, cloud, network, endpoint, email, manufacturing, and application environments. Ideally, this role will be based on-site (hybrid) in Wilmington, DE. Alternatively, remote may be considered for a highly qualified candidate.
This role will partner closely with Cybersecurity Engineering, Network, Cloud, Infrastructure, Endpoint, Identity, Manufacturing IT, Cybersecurity Operations, and project teams. The architect will develop reference architectures and standards, review designs, and provide practical implementation options that balance security, reliability, cost, and delivery timelines.
This is a hands-on architecture role requiring broad cybersecurity knowledge. The successful candidate must be comfortable moving between strategic design and detailed technical discussions involving cloud architecture, network security, endpoint controls, email security, identity, application security dependencies, logging, vulnerability management, data flows, and security operations.
Key Responsibilities
- Develop cybersecurity reference architectures, standards, and approved design patterns across cloud, network, endpoint, email, identity, infrastructure, and application environments.
- Define secure patterns for Azure, enterprise networking, remote access, internet egress, endpoint security, email security, application publishing, third-party connectivity, and manufacturing environments.
- Review solution and application architectures to identify security requirements, risks, dependencies, and required controls.
- Translate cybersecurity requirements into practical technical designs that engineering and project teams can implement.
- Provide preferred approaches and acceptable alternatives rather than a single rigid solution.
- Develop patterns integrating security technologies including Microsoft Entra ID, Defender, Sentinel, Intune, Azure, PKI, Palo Alto Networks, vulnerability management, email security, and security operations platforms.
- Support hybrid cloud and enterprise infrastructure designs involving routing, DNS, TLS, private connectivity, segmentation, identity, endpoint controls, and application data flows.
- Develop security patterns for manufacturing and operational technology environments, including segmentation, remote support, privileged access, endpoint protection, and monitoring.
- Partner with project teams to identify and resolve security architecture issues early in the design process.
- Define architectural requirements for security logging, monitoring, telemetry, vulnerability management, policy ownership, access control, and operational support.
- Evaluate new technologies and cybersecurity capabilities and determine how they should integrate with the broader security architecture.
- Support the development and maturation of cybersecurity programs, standards, control frameworks, and engineering practices.
- Maintain clear, usable architecture documentation, diagrams, reference patterns, and technical decision records.
- Significant experience in cybersecurity architecture, security engineering, or a senior technical security role within a complex enterprise.
- Broad knowledge across multiple cybersecurity domains, including cloud security, network security, endpoint security, email security, identity and access management, vulnerability management, logging, and security operations.
- Strong understanding of Microsoft Azure and enterprise cloud security concepts.
- Strong understanding of enterprise networking concepts including routing, DNS, NAT, VPNs, proxies, TLS, segmentation, and secure connectivity.
- Experience with endpoint protection, device management, EDR, and modern endpoint security architectures.
- Familiarity with enterprise email security, phishing protection, secure email gateways, and Microsoft 365 security controls.
- Experience integrating security controls with SIEM, identity, endpoint, network, vulnerability-management, and IT service-management platforms.
- Ability to understand application architectures and translate business and technical requirements into secure, supportable designs.
- Experience developing reference architectures, engineering standards, control patterns, and reusable technical guidance.
- Ability to work across multiple technical disciplines without requiring deep specialization in every technology.
- Strong written, verbal, and diagramming skills.
- Demonstrated judgment in balancing security requirements with operational and project constraints.
- Experience in a global manufacturing or industrial environment.
- Familiarity with Purdue-model segmentation and operational technology security.
- Experience with Microsoft Sentinel, Defender, Entra ID, Intune, Azure, Palo Alto Networks, Proofpoint, ServiceNow, FireMon, PKI, or comparable enterprise security technologies.
- Experience with Azure networking, private endpoints, ExpressRoute, Windows 365, Azure Virtual Desktop, and hybrid connectivity.
- Experience participating in or helping develop cybersecurity programs such as vulnerability management, security monitoring, endpoint security, cloud security, network security, identity security, or security architecture.
- Relevant certifications such as CISSP, CCSP, Microsoft Azure, GIAC, PCNSE, or comparable technical security certifications.
- Broadly knowledgeable, technically credible, and comfortable working across cybersecurity disciplines.
- Able to recognize when specialist expertise is required and effectively engage the appropriate engineering teams.
- Pragmatic and comfortable challenging weak designs.
- Able to explain both what must change and how it can be implemented.
- Flexible in approach without weakening core security requirements.
- Comfortable working in a developing organization where standards, reference architectures, and operating models are still being established.
- Produces architecture that engineering and project teams can actually use.
Qnity is an equal opportunity employer. Qualified applicants will be considered without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability or any other protected class. If you need a reasonable accommodation to search or apply for a position, please visit our Accessibility Page for Contact Information.
Qnity offers a comprehensive pay and benefits package. To learn more visit the Compensation and Benefits page.
We use Artificial Intelligence (AI) to enhance our recruitment process.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search