Technology Cyber Security Architect
Overview
In this role you will design and maintain enterprise security architecture across on-premises, hybrid, and AI-enabled environments to protect firm assets. You will collaborate with Technology and Innovation teams to embed security, privacy, and governance into system design and delivery. Your focus includes AI/ML security controls, threat mitigation, and aligning with regulatory frameworks. This position offers impact on security strategy and architecture across the firm, with opportunities to lead architectural decisions and incident response improvements.
Compensation / Benefitsmedical benefitshealth savings accountdentalvisionFSAslife insurance and AD&D
ResponsibilitiesDesign and maintain enterprise security architecture across on-premises, hybrid, and AI-enabled environmentsDefine security standards, patterns, and reference architectures aligned with business objectives and regulatory requirementsConduct security architecture reviews for new systems, applications, AI/ML platforms, and major technology changesPartner with engineering, infrastructure, DevOps, and data teams to embed security, privacy, and governance into system designDesign security controls for AI and ML systems (data pipelines, training environments, inference platforms, AI integrations)Identify and mitigate risks related to AI systems (data leakage, prompt injection, adversarial attacks)Evaluate and recommend security tools, platforms, and AI-enabled security technologiesEnsure architectures comply with legal, regulatory, and industry frameworks (e.g., NIST, ISO 27001, SOC 2, GDPR, AI regulations)Establish guardrails for responsible and secure use of generative AI/LLMs (access controls, monitoring, logging, auditability)Support incident response, forensics, and post-incident architecture improvementsProvide guidance and mentorship to security engineers and stakeholdersCommunicate architectural decisions and risks to technical and non-technical audiences
Key requirements3+ years direct applicable experience (3+; senior level 5+ years)Strong knowledge of network security, IAM, encryption, and endpoint securityAbility to translate business requirements into secure designsExperience configuring security controls and secure migration of enterprise appsExperience with implementing security tools and architecture (Access Controls, DLP, WAF, Secure SDLC, Firewalls, anti-malware, encryption, network security, monitoring)Formal requirements definition experienceCISSP, CISM or equivalentCI/CD pipelinesCloud certifications (AWS, Azure, GCP) or relatedanalyticalcommunicationproject managementSecurity architectureAI/ML security controlsData encryption in transit and at rest