Job Description

Location: Johnston, RI

Job Title :: Principal Enterprise Architect (Security)

Location :: Remote

Term :: Fulltime

Job description:

• The Enterprise Security Architect (EA) is a key member of the Enterprise Architecture Organization responsible for strategic alignment of technologies with business vision to enable desired outcomes.

• The enterprise security architect plays an integral role in defining and assessing the organization's technical security strategy, architecture and practices. The enterprise security architect will be required to effectively translate business objectives and risk management strategies into specific security processes enabled by security technologies and services. The incumbent collaborates with other architects to provide guidance that ensures technology products are designed to support the timely evolution of enterprise objectives.

• Enterprise security architect is expected to advocate for security requirements and objectives across stakeholders while ensuring that security architectures and practices do not impede the needs of the business. Specifically, the enterprise security architect will serve as a technical sounding board for the CISO's interaction with other line-of-business constituencies in the organization, while drawing from the context and expertise of other Enterprise Architects. The enterprise security architect will be expected to evaluate new services, vendors, applications and security tools, among other items, from a technical perspective, and to translate the risk characteristics of these activities and functions into enterprise risk terms that the CISO can communicate to the stakeholders.

• The enterprise security architect will be responsible for the following activities and functions:

• Develop and maintain a security architecture process that enables the enterprise to develop and implement security solutions and capabilities that are clearly aligned with business, technology and threat drivers

• Develop security strategy plans and roadmaps based on sound enterprise architecture practices

• Develop and maintain security architecture artifacts (e.g., models, templates, guideline) that can be used to demonstrate security capabilities in projects and operations

• Track developments and changes in the digital business and threat environments to ensure that they're adequately addressed in security strategy plans and architecture artifacts

• Participate in application and infrastructure projects to provide security-planning advice

• A significant accountability of a security EA is to ensure alignment of priorities, practices, implementation options and requirements between all partners, especially other architects, product owners, IT infrastructure personnel and CISO organization.

• Coordinate with DevOps teams to advocate secure coding practices, and to bring up concerns related to poor coding practices to the CISO/Leadership.

• Review IT infrastructure and other reference architectures for security standard processes and recommend changes to enhance security and reduce risks, where applicable

• Review security configurations and access to security infrastructure tools, including firewalls, IPSs, WAFs and anti-malware/endpoint protection systems

• Support the testing and validation of internal security controls, as directed by the CISO or the internal audit team

• Review security technologies, tools and services, and make recommendations to the broader security team for their use, based on security, financial and operational metrics

• Liaise with other security practitioners to share standard processes and insights


Education, experience. skills:

• Bachelor's degree in Information Technology, Computer Science, cyber security or related field; or equivalent work experience and training. Advanced degree and certifications are highly desirable.

• 10+ Years' experience designing, developing, implementing enterprise scale technology solutions

• 3+ Years' experience defining and implementing strategies under a CIO or a Senior technical leader

• Demonstrable experience is addressing security architecture needs in a Public Cloud environment.

• Direct, hands-on experience or strong working knowledge of managing security infrastructure - e.g., firewalls, intrusion prevention systems (IPSs), web application firewalls (WAFs), endpoint protection, SIEM and log management technologies

• Verifiable experience reviewing application code for security vulnerabilities

• Solid understanding of vulnerability management tools

• Solid understanding of the methodologies to conduct threat-modeling exercises on new applications and services.

• Working knowledge of IT infrastructure: Applications, Databases, Operating systems - Windows, Unix and Linux, Hypervisors, WAN and LAN, Public cloud Services

• In-depth experience of designing and implementing information solutions.

• Deep understanding of common architecture frameworks and risk assessment/security frameworks.

• Able to make sound and far-reaching decisions alone on major technical and architectural issues related to security and take full responsibility for them.

