Information Security Architect

mid
OtherInformation Security
0 views0 saves0 applied

Quick Summary

Overview

Overview Job Summary The Information Security Architect is responsible for designing, implementing, and managing the organization's security infrastructure.

Technical Tools
OtherInformation Security

The Information Security Architect is responsible for designing, implementing, and managing the organization's security infrastructure. This role involves developing and enforcing security policies, ensuring the protection of sensitive data, and mitigating security risks across the enterprise.

Responsibilities

~1 min read

Requirements

~2 min read
  • Security Architecture and Engineering
    • Design, implement, and govern security architecture for on-premises and cloud environments, including Azure and AWS identity, network, workload, and data-protection controls.
  • Security Governance and Standards
    • Develop, maintain, and enforce security policies, standards, guidelines, and architecture principles aligned with applicable regulatory and security frameworks.
  • Security Assessment and Risk Management
    • Lead security assessments, audits, penetration-testing activities, vulnerability reviews, and configuration assessments. Develop risk-based mitigation strategies addressing least privilege, RBAC, hardening, encryption, TLS, network security, and SaaS controls.
  • Threat Detection and Incident Response
    • Conduct threat monitoring and proactive threat hunting; independently investigate, triage, and run down malware and EDR alerts (e.g., SentinelOne) through containment and resolution.
    • Develop and manage incident response plans, and lead incident response efforts, malware analysis, and forensic investigations through resolution.
  • Security Technology Architecture
    • Evaluate, recommend, and maintain security technologies, including firewalls, IDS/IPS, encryption solutions, endpoint security platforms, and related network controls. Leverage centralized management through FortiManager to maintain consistent Fortinet policy, configuration, and governance across the environment.
  • Application and Cloud Security
    • Secure in-house and cloud-hosted application development through secure design review, code and configuration review, and scripting and automation across the full stack.
    • Provide security architecture guidance for AI-enabled and agentic AI systems, including review of technology stacks, data flows, tool and API access, identity and permission boundaries, prompt and output controls, logging, monitoring, vendor/model risk, and governance requirements to support responsible and compliant AI use.
  • Compliance, Resilience, and Audit Support
    • Ensure compliance with applicable laws, regulations, and standards (HIPAA, SOC 2, HITRUST, GDPR, etc.), and develop and enforce security governance frameworks.
    • Support SOC 2 audits, penetration testing engagements, and disaster recovery and business continuity planning, documentation, and testing.
  • Collaboration and Security Enablement
    • Partner with IT, development, and business teams to integrate security into organizational processes.
    • Mentor staff and produce clear technical documentation, procedures, and architecture diagrams.
  • All other duties as assigned. 
  • In-depth knowledge of security architecture, frameworks, standards, risk management, and threat assessment.
  • Demonstrated hands-on experience designing and securing Azure and/or AWS environments.
  • Knowledge of identity, network, workload, data, application, and endpoint security controls.
  • Experience with EDR platforms, malware investigation, threat hunting, and incident response.
  • Experience with firewalls, IDS/IPS, encryption, FortiGate/Fortinet, FortiManager, or comparable security platforms.
  • Application security knowledge, including secure design, code and configuration review, scripting, and automation.
  • Knowledge of HIPAA, SOC 2, HITRUST, penetration testing, disaster recovery, and business continuity practices.
  • Knowledge of security considerations for AI-enabled and agentic AI systems, including generative AI, AI application stacks, secure development, data protection, model and vendor risk, identity and access controls, monitoring, and governance frameworks for responsible AI use.
  • Strong analytical, problem-solving, organizational, and project-management skills.
  • Excellent verbal and written communication skills, with the ability to mentor others and explain technical risk to varied audiences.
  • Ability to produce clear technical and user-facing documentation, procedures, and architecture diagrams.

The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor’s legal duty to furnish information. 41 CFR 60-1.35(c)

#LI-BR1

Location & Eligibility

Where is the job
—
Location terms not specified

Listing Details

Posted
September 11, 2026
First seen
September 27, 2026
Last seen
September 27, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
16%
Scored at
September 27, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

careers-healthmanagementInformation Security Architect