{"schemaVersion":"jobsearcher.job.v1","id":"3ce847e2bc1da202d037247d","url":"https://jobsearcher.com/jobs/3ce847e2bc1da202d037247d","canonicalUrl":"https://jobsearcher.com/jobs/3ce847e2bc1da202d037247d","title":"Security Architect","description":"Company Overview\n\nHexion is a global leader in specialty chemicals, delivering innovative solutions that improve performance, sustainability, and efficiency across industries. Our manufacturing operations span multiple continents, integrating complex Operational Technology (OT) environments with enterprise IT systems and a growing footprint in Microsoft Azure and Amazon Web Services. As the business adopts cloud platforms and artificial intelligence at scale, Hexion is investing in a security architecture function capable of designing defensible systems across every environment we operate — on-premises data centers, public cloud, the plant floor, and the physical perimeter that protects both.\n\nPosition Overview\n\nThe Security Architect is a senior technical practitioner responsible for designing the security architecture of Hexion’s enterprise environment: on-premises infrastructure, Azure and AWS cloud platforms, AI and machine learning systems, and the interfaces between enterprise IT, Operational Technology, and physical security systems. This role owns reference architectures, security design patterns, and architectural standards — and holds the authority to review, challenge, and approve designs before they are built.\n\nThis is an architecture role, not a compliance role. The successful candidate uses ISO/IEC 27001, 27017, 27018, 42001, and 27019 as the frameworks that shape control selection and design rationale, then works alongside engineering teams to make those controls real in configuration, code, and network design.\n\nThis role ensures:\n\nSecurity is designed into systems at inception rather than assessed after deployment\nOn-premises, Azure, and AWS environments share a coherent identity, network, and data protection architecture\nCloud services are architected against ISO/IEC 27017 and 27018 expectations for cloud security and PII protection\nAI and machine learning systems are designed with governance and technical controls aligned to ISO/IEC 42001 and recognized AI threat models\nOT and process control architectures are secured in partnership with engineering, informed by ISO/IEC 27019 and IEC 62443\nPhysical security systems and controls are treated as part of the security architecture, not a separate discipline\nArchitectural decisions are documented, defensible, and traceable to risk\nJob Responsibilities\n\n1. Enterprise & On-Premises Architecture\n\nOwn the security architecture of Hexion’s on-premises estate:\n\nDesign and maintain reference architectures for network segmentation, zero trust access, remote access, and data center security\nArchitect identity and access management across Active Directory, Entra ID, privileged access management, and federation to cloud and SaaS platforms\nDefine security architecture standards for endpoints, servers, virtualization, backup, and disaster recovery\nLead the architectural review function — evaluate new systems, integrations, and infrastructure changes against defined standards and document exceptions with compensating controls\nDesign detection and logging architecture in partnership with security operations, ensuring telemetry coverage across on-premises and cloud estates\nMaintain the enterprise security architecture roadmap, sequencing capability investments against risk reduction\n\n2. Cloud Security Architecture (Azure and AWS)\n\nServe as the design authority for multi-cloud security:\n\nArchitect landing zones, subscription and account structures, network topology, and guardrails for both Azure and AWS\nDesign cloud identity architecture — workload identity, federation, conditional access, least-privilege IAM policy models, and secrets management\nApply ISO/IEC 27017 cloud security controls to define Hexion’s architectural obligations as a cloud service customer, and where applicable as a cloud service provider\nApply ISO/IEC 27018 controls for protection of personally identifiable information in public cloud, including data residency, encryption, and processor boundary design\nDefine encryption and key management architecture across Azure Key Vault, AWS KMS, and on-premises HSM or key stores\nEstablish policy-as-code and infrastructure-as-code security patterns, embedding controls into Terraform, Bicep, or CloudFormation pipelines\nArchitect CSPM, CWPP, and cloud-native detection coverage; define the standards those tools measure against\nDesign secure connectivity between cloud platforms, on-premises data centers, and plant networks\n\n3. AI Security Architecture (ISO/IEC 42001)\n\nDesign the security architecture for Hexion’s adoption of artificial intelligence:\n\nDefine reference architectures for enterprise AI use — hosted LLM services, retrieval-augmented generation, agentic workflows, and AI-enabled SaaS\nApply ISO/IEC 42001 as the governance framework for AI management, translating its requirements into architectural controls rather than paperwork\nDesign controls against recognized AI threat models — prompt injection, training and inference data poisoning, model and data exfiltration, insecure output handling, and excessive agency (OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF)\nArchitect data protection boundaries for AI systems: what data may reach which model, under what tenancy, with what retention and residency guarantees\nDefine identity, authorization, and audit architecture for AI agents and non-human identities acting on enterprise systems\nEstablish security review patterns for AI use cases, model selection, and third-party AI vendors\nAdvise on secure use of AI within OT and engineering contexts, where model outputs may influence physical processes\nJob Responsibilities continued...\n\n4. OT & Process Control Security Architecture\n\nPartner with engineering and plant operations to secure industrial environments:\n\nDesign IT/OT boundary architecture — segmentation, DMZ patterns, unidirectional gateways where warranted, and secure remote access for vendors and engineers\nApply ISO/IEC 27019 and IEC 62443 concepts to zone and conduit design, asset inventory, and control selection for process control systems\nDefine architectural standards for OT monitoring, passive asset discovery, and safe patching and change practices\nSupport architecture for plant modernization, connected sensor, and industrial IoT initiatives without compromising safety or availability\nTranslate enterprise security standards into requirements that are implementable on the plant floor, respecting availability and safety constraints\n\n5. Physical Security Architecture\n\nTreat physical and logical security as one architecture:\n\nDefine security architecture for physical access control, video surveillance, intrusion detection, and visitor management systems\nArchitect the convergence of physical security platforms with enterprise identity — provisioning, deprovisioning, and access review across badge and logical systems\nAddress the network and lifecycle security of physical security devices, which frequently share infrastructure with OT and enterprise networks\nDefine physical security requirements for data centers, control rooms, network closets, and cloud colocation or interconnect facilities\nSupport site risk assessments and design layered protection appropriate to facility criticality\n\n6. Standards, Patterns & Technical Governance\n\nMaintain the architectural artifacts the organization builds against:\n\nAuthor and maintain security standards, design patterns, and hardening baselines mapped to ISO/IEC 27001 Annex A and the extension standards named above\nProvide architectural input to the ISMS and AI management system, including risk treatment design, Statement of Applicability rationale, and control implementation evidence\nConduct threat modeling and architectural risk assessments for major programs and high-impact changes\nContribute security architecture requirements to vendor selection, third-party integrations, and M&A technical due diligence\nMentor engineers and analysts, raising the architectural fluency of the broader security and IT organization\nCompetencies\nDesign authority — you produce architectures that engineering teams can build from, and you defend them with reasoning rather than mandate\nBreadth with depth — you move credibly between a cloud IAM policy, a plant network diagram, and a badge reader VLAN without losing precision\nStandards as tools — you use the ISO family to sharpen design decisions, not to generate documentation for its own sake\nPragmatic risk judgment — you know which theoretical risks matter in a chemical manufacturing environment and which do not\nEngineering credibility — you have built things, and technical teams recognize it within the first conversation\nClarity in writing — your diagrams and design documents are the artifacts other people work from for years\nForward posture — you track how cloud, AI, and OT threat landscapes are moving and adjust architecture before incidents force it\n\nLeadership Expectations:\n\nServe as the enterprise technical authority on security architecture across IT, cloud, AI, OT, and physical security domains\nInfluence without direct authority — secure architectural outcomes from teams that do not report to security\nPartner with the Compliance and Risk function so that architecture and control frameworks reinforce rather than duplicate each other\nRepresent security architecture in enterprise architecture forums, capital project reviews, and vendor evaluations\nMake and document architectural decisions under uncertainty, revisiting them as conditions change rather than defending them indefinitely\nRaise the security design capability of the wider organization through mentoring, review, and reusable patterns\nMinimum Qualifications\nBachelor’s degree in Computer Science, Information Security, Engineering, or related field (or equivalent practical experience)\n8+ years in information security with at least 4 years in a dedicated security architecture or senior security engineering role\nDemonstrated experience architecting security for both on-premises infrastructure and public cloud at enterprise scale\nHands-on architectural depth in both Microsoft Azure and Amazon Web Services — identity, networking, encryption, and native security services in each\nWorking fluency with ISO/IEC 27001 and Annex A controls as an architectural framework, including practical application of ISO/IEC 27017 and 27018 to cloud designs\nFamiliarity with ISO/IEC 42001 and the AI security threat landscape, with experience designing controls for AI or machine learning systems\nUnderstanding of OT and industrial control system architecture, including ISO/IEC 27019, IEC 62443, or NIST SP 800-82 concepts\nExperience with physical security systems and the integration of physical and logical access control\nStrong identity architecture skills — Active Directory, Entra ID, SAML and OIDC federation, privileged access management, and non-human identity models\nNetwork security design depth — segmentation, zero trust architecture, firewalls, proxies, and secure connectivity across hybrid environments\nProficiency with threat modeling methodologies (STRIDE, PASTA, attack trees) and the ability to produce clear architectural documentation and diagrams\nStrong written and verbal communication — able to defend a design to engineers and explain the same decision to executives\nPreferred Qualifications\nExperience with:\nManufacturing, chemical, energy, or other process industry environments\nInfrastructure-as-code and policy-as-code (Terraform, Bicep, CloudFormation, OPA, Sentinel)\nSecure software development lifecycle, application security, and CI/CD pipeline security\nData security architecture — classification, DLP, tokenization, and data governance platforms\nThird-party and supply chain risk architecture, including SBOM and vendor integration patterns\nGlobal operations across multiple regulatory jurisdictions (GDPR, CCPA, NIS2, or similar)\nCertifications (any of the following valued):\nCISSP or CISSP-ISSAP (Information Systems Security Architecture Professional)\nSABSA, TOGAF, or equivalent architecture credential\nAzure Solutions Architect Expert or Azure Security Engineer Associate\nAWS Solutions Architect Professional or AWS Certified Security – Specialty\nGICSP, ISA/IEC 62443 Cybersecurity Specialist, or equivalent OT credential\nISO/IEC 27001 Lead Implementer or ISO/IEC 42001 Lead Implementer\nCCSP, PSP (Physical Security Professional), or AI security credentials\nWork Environment & Travel\n\nThis is a remote-first position with periodic travel to Hexion manufacturing facilities, data center and colocation sites, and partner or vendor engagements as required (~15–20%). Site visits are an expected part of the role — OT and physical security architecture cannot be designed entirely from a network diagram.\n\nOther\n\nWe are an Equal Opportunity, Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to gender, minority status, sexual orientation, gender identity, protected veteran status, status as a qualified individual with a disability or any characteristic protected by law.\n\nIn order to be considered for this position candidates are required to submit an application for employment through our career site, be at least 18 years of age, willing to take a drug test , submit to a background investigation as part of the selection process, as well as additional periodic background checks as required by the Chemical Facility Anti-Terrorism Standards (CFATS) or regulations adopted by the Department of Homeland Security or other regulatory agencies\n\nCandidates are required to have unrestricted authorization to work in the United States.\n\nIf currently an employee of the Company, you must have current satisfactory work performance and in most cases, have been in your current role 18 months.\n\nDisclaimer: We are not accepting unsolicited assistance from search firms/employment agencies for this employment opportunity. Please, no phone calls or emails to any employee about this position. All resumes submitted by search firms/employment agencies to any employee of the Company via email, the Internet or in any other form and/or method without a valid written search firm agreement in place for this position will be deemed the sole property of the Company; no fee will be paid in the event a candidate is hired by the Company as a result of the unsolicited referral or through other means.","company":"Hexion","rawCompany":"hexion","city":"Columbus","state":"OH","isRemote":false,"isActive":true,"createdAt":"2026-08-27T09:56:05.305Z","occupations":[{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"},{"code":"541330","title":"Engineering Services","slug":"engineering-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Security Architect","description":"Company Overview\n\nHexion is a global leader in specialty chemicals, delivering innovative solutions that improve performance, sustainability, and efficiency across industries. Our manufacturing operations span multiple continents, integrating complex Operational Technology (OT) environments with enterprise IT systems and a growing footprint in Microsoft Azure and Amazon Web Services. As the business adopts cloud platforms and artificial intelligence at scale, Hexion is investing in a security architecture function capable of designing defensible systems across every environment we operate — on-premises data centers, public cloud, the plant floor, and the physical perimeter that protects both.\n\nPosition Overview\n\nThe Security Architect is a senior technical practitioner responsible for designing the security architecture of Hexion’s enterprise environment: on-premises infrastructure, Azure and AWS cloud platforms, AI and machine learning systems, and the interfaces between enterprise IT, Operational Technology, and physical security systems. This role owns reference architectures, security design patterns, and architectural standards — and holds the authority to review, challenge, and approve designs before they are built.\n\nThis is an architecture role, not a compliance role. The successful candidate uses ISO/IEC 27001, 27017, 27018, 42001, and 27019 as the frameworks that shape control selection and design rationale, then works alongside engineering teams to make those controls real in configuration, code, and network design.\n\nThis role ensures:\n\nSecurity is designed into systems at inception rather than assessed after deployment\nOn-premises, Azure, and AWS environments share a coherent identity, network, and data protection architecture\nCloud services are architected against ISO/IEC 27017 and 27018 expectations for cloud security and PII protection\nAI and machine learning systems are designed with governance and technical controls aligned to ISO/IEC 42001 and recognized AI threat models\nOT and process control architectures are secured in partnership with engineering, informed by ISO/IEC 27019 and IEC 62443\nPhysical security systems and controls are treated as part of the security architecture, not a separate discipline\nArchitectural decisions are documented, defensible, and traceable to risk\nJob Responsibilities\n\n1. Enterprise & On-Premises Architecture\n\nOwn the security architecture of Hexion’s on-premises estate:\n\nDesign and maintain reference architectures for network segmentation, zero trust access, remote access, and data center security\nArchitect identity and access management across Active Directory, Entra ID, privileged access management, and federation to cloud and SaaS platforms\nDefine security architecture standards for endpoints, servers, virtualization, backup, and disaster recovery\nLead the architectural review function — evaluate new systems, integrations, and infrastructure changes against defined standards and document exceptions with compensating controls\nDesign detection and logging architecture in partnership with security operations, ensuring telemetry coverage across on-premises and cloud estates\nMaintain the enterprise security architecture roadmap, sequencing capability investments against risk reduction\n\n2. Cloud Security Architecture (Azure and AWS)\n\nServe as the design authority for multi-cloud security:\n\nArchitect landing zones, subscription and account structures, network topology, and guardrails for both Azure and AWS\nDesign cloud identity architecture — workload identity, federation, conditional access, least-privilege IAM policy models, and secrets management\nApply ISO/IEC 27017 cloud security controls to define Hexion’s architectural obligations as a cloud service customer, and where applicable as a cloud service provider\nApply ISO/IEC 27018 controls for protection of personally identifiable information in public cloud, including data residency, encryption, and processor boundary design\nDefine encryption and key management architecture across Azure Key Vault, AWS KMS, and on-premises HSM or key stores\nEstablish policy-as-code and infrastructure-as-code security patterns, embedding controls into Terraform, Bicep, or CloudFormation pipelines\nArchitect CSPM, CWPP, and cloud-native detection coverage; define the standards those tools measure against\nDesign secure connectivity between cloud platforms, on-premises data centers, and plant networks\n\n3. AI Security Architecture (ISO/IEC 42001)\n\nDesign the security architecture for Hexion’s adoption of artificial intelligence:\n\nDefine reference architectures for enterprise AI use — hosted LLM services, retrieval-augmented generation, agentic workflows, and AI-enabled SaaS\nApply ISO/IEC 42001 as the governance framework for AI management, translating its requirements into architectural controls rather than paperwork\nDesign controls against recognized AI threat models — prompt injection, training and inference data poisoning, model and data exfiltration, insecure output handling, and excessive agency (OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF)\nArchitect data protection boundaries for AI systems: what data may reach which model, under what tenancy, with what retention and residency guarantees\nDefine identity, authorization, and audit architecture for AI agents and non-human identities acting on enterprise systems\nEstablish security review patterns for AI use cases, model selection, and third-party AI vendors\nAdvise on secure use of AI within OT and engineering contexts, where model outputs may influence physical processes\nJob Responsibilities continued...\n\n4. OT & Process Control Security Architecture\n\nPartner with engineering and plant operations to secure industrial environments:\n\nDesign IT/OT boundary architecture — segmentation, DMZ patterns, unidirectional gateways where warranted, and secure remote access for vendors and engineers\nApply ISO/IEC 27019 and IEC 62443 concepts to zone and conduit design, asset inventory, and control selection for process control systems\nDefine architectural standards for OT monitoring, passive asset discovery, and safe patching and change practices\nSupport architecture for plant modernization, connected sensor, and industrial IoT initiatives without compromising safety or availability\nTranslate enterprise security standards into requirements that are implementable on the plant floor, respecting availability and safety constraints\n\n5. Physical Security Architecture\n\nTreat physical and logical security as one architecture:\n\nDefine security architecture for physical access control, video surveillance, intrusion detection, and visitor management systems\nArchitect the convergence of physical security platforms with enterprise identity — provisioning, deprovisioning, and access review across badge and logical systems\nAddress the network and lifecycle security of physical security devices, which frequently share infrastructure with OT and enterprise networks\nDefine physical security requirements for data centers, control rooms, network closets, and cloud colocation or interconnect facilities\nSupport site risk assessments and design layered protection appropriate to facility criticality\n\n6. Standards, Patterns & Technical Governance\n\nMaintain the architectural artifacts the organization builds against:\n\nAuthor and maintain security standards, design patterns, and hardening baselines mapped to ISO/IEC 27001 Annex A and the extension standards named above\nProvide architectural input to the ISMS and AI management system, including risk treatment design, Statement of Applicability rationale, and control implementation evidence\nConduct threat modeling and architectural risk assessments for major programs and high-impact changes\nContribute security architecture requirements to vendor selection, third-party integrations, and M&A technical due diligence\nMentor engineers and analysts, raising the architectural fluency of the broader security and IT organization\nCompetencies\nDesign authority — you produce architectures that engineering teams can build from, and you defend them with reasoning rather than mandate\nBreadth with depth — you move credibly between a cloud IAM policy, a plant network diagram, and a badge reader VLAN without losing precision\nStandards as tools — you use the ISO family to sharpen design decisions, not to generate documentation for its own sake\nPragmatic risk judgment — you know which theoretical risks matter in a chemical manufacturing environment and which do not\nEngineering credibility — you have built things, and technical teams recognize it within the first conversation\nClarity in writing — your diagrams and design documents are the artifacts other people work from for years\nForward posture — you track how cloud, AI, and OT threat landscapes are moving and adjust architecture before incidents force it\n\nLeadership Expectations:\n\nServe as the enterprise technical authority on security architecture across IT, cloud, AI, OT, and physical security domains\nInfluence without direct authority — secure architectural outcomes from teams that do not report to security\nPartner with the Compliance and Risk function so that architecture and control frameworks reinforce rather than duplicate each other\nRepresent security architecture in enterprise architecture forums, capital project reviews, and vendor evaluations\nMake and document architectural decisions under uncertainty, revisiting them as conditions change rather than defending them indefinitely\nRaise the security design capability of the wider organization through mentoring, review, and reusable patterns\nMinimum Qualifications\nBachelor’s degree in Computer Science, Information Security, Engineering, or related field (or equivalent practical experience)\n8+ years in information security with at least 4 years in a dedicated security architecture or senior security engineering role\nDemonstrated experience architecting security for both on-premises infrastructure and public cloud at enterprise scale\nHands-on architectural depth in both Microsoft Azure and Amazon Web Services — identity, networking, encryption, and native security services in each\nWorking fluency with ISO/IEC 27001 and Annex A controls as an architectural framework, including practical application of ISO/IEC 27017 and 27018 to cloud designs\nFamiliarity with ISO/IEC 42001 and the AI security threat landscape, with experience designing controls for AI or machine learning systems\nUnderstanding of OT and industrial control system architecture, including ISO/IEC 27019, IEC 62443, or NIST SP 800-82 concepts\nExperience with physical security systems and the integration of physical and logical access control\nStrong identity architecture skills — Active Directory, Entra ID, SAML and OIDC federation, privileged access management, and non-human identity models\nNetwork security design depth — segmentation, zero trust architecture, firewalls, proxies, and secure connectivity across hybrid environments\nProficiency with threat modeling methodologies (STRIDE, PASTA, attack trees) and the ability to produce clear architectural documentation and diagrams\nStrong written and verbal communication — able to defend a design to engineers and explain the same decision to executives\nPreferred Qualifications\nExperience with:\nManufacturing, chemical, energy, or other process industry environments\nInfrastructure-as-code and policy-as-code (Terraform, Bicep, CloudFormation, OPA, Sentinel)\nSecure software development lifecycle, application security, and CI/CD pipeline security\nData security architecture — classification, DLP, tokenization, and data governance platforms\nThird-party and supply chain risk architecture, including SBOM and vendor integration patterns\nGlobal operations across multiple regulatory jurisdictions (GDPR, CCPA, NIS2, or similar)\nCertifications (any of the following valued):\nCISSP or CISSP-ISSAP (Information Systems Security Architecture Professional)\nSABSA, TOGAF, or equivalent architecture credential\nAzure Solutions Architect Expert or Azure Security Engineer Associate\nAWS Solutions Architect Professional or AWS Certified Security – Specialty\nGICSP, ISA/IEC 62443 Cybersecurity Specialist, or equivalent OT credential\nISO/IEC 27001 Lead Implementer or ISO/IEC 42001 Lead Implementer\nCCSP, PSP (Physical Security Professional), or AI security credentials\nWork Environment & Travel\n\nThis is a remote-first position with periodic travel to Hexion manufacturing facilities, data center and colocation sites, and partner or vendor engagements as required (~15–20%). Site visits are an expected part of the role — OT and physical security architecture cannot be designed entirely from a network diagram.\n\nOther\n\nWe are an Equal Opportunity, Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to gender, minority status, sexual orientation, gender identity, protected veteran status, status as a qualified individual with a disability or any characteristic protected by law.\n\nIn order to be considered for this position candidates are required to submit an application for employment through our career site, be at least 18 years of age, willing to take a drug test , submit to a background investigation as part of the selection process, as well as additional periodic background checks as required by the Chemical Facility Anti-Terrorism Standards (CFATS) or regulations adopted by the Department of Homeland Security or other regulatory agencies\n\nCandidates are required to have unrestricted authorization to work in the United States.\n\nIf currently an employee of the Company, you must have current satisfactory work performance and in most cases, have been in your current role 18 months.\n\nDisclaimer: We are not accepting unsolicited assistance from search firms/employment agencies for this employment opportunity. Please, no phone calls or emails to any employee about this position. All resumes submitted by search firms/employment agencies to any employee of the Company via email, the Internet or in any other form and/or method without a valid written search firm agreement in place for this position will be deemed the sole property of the Company; no fee will be paid in the event a candidate is hired by the Company as a result of the unsolicited referral or through other means.","datePosted":"2026-08-27T09:56:05.305Z","dateModified":"2026-08-27T09:56:05.305Z","hiringOrganization":{"@type":"Organization","name":"Hexion","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Columbus","addressRegion":"OH","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"3ce847e2bc1da202d037247d"},"url":"https://jobsearcher.com/jobs/3ce847e2bc1da202d037247d"}}