Tory Burch LLC
• $200K — $250K *Qualifications
Responsibilities
Benefits
A Day in the Life:
· Lead the Cybersecurity Architecture & Engineering function and provide direction, coaching, prioritization, performance support, and professional development for the Cybersecurity Architect and Cybersecurity Engineer.
· Own the end-to-end Cybersecurity Architecture & Engineering service offering, including service scope, intake, engagement model, standards, deliverables, roadmaps, metrics, and continuous improvement.
· Define and maintain enterprise security architecture principles, standards, reference architectures, reusable patterns, engineering requirements, and security guardrails.
· Partner closely with Infrastructure, Digital, Data, Enterprise Architecture, and Application teams to integrate security into planning, architecture, design, build, deployment, migration, change, and operational processes.
· Design and establish new security architecture and engineering processes where existing processes do not adequately support secure technology delivery.
· Establish security participation in architecture review boards and related technology governance forums. Develop practical, low-friction intake, triage, review, escalation, exception, and approval processes that engage security early and provide clear, timely guidance.
· Ensure security architecture reviews and design decisions occur early enough to influence solution direction, reduce rework, improve supportability, and avoid unnecessary delivery delays.
· Lead security architecture reviews for cloud initiatives, infrastructure changes, identity services, endpoint platforms, digital capabilities, applications, integrations, APIs, data flows, collaboration services, and emerging technologies.
· Guide the design of secure end-to-end solutions that connect distributed systems and business processes through integrations, APIs, event flows, orchestration, and automated workflows.
· Ensure end-to-end designs address identity, authentication, authorization, device trust, secrets, encryption, network controls, data protection, logging, monitoring, resilience, third-party dependencies, user experience, and secure failure behavior.
· Define security architecture and engineering requirements for networks, secure connectivity, segmentation, remote access, cloud networking, platform services, and hybrid technology environments.
· Provide architecture and engineering leadership across the Microsoft ecosystem, including Microsoft Entra, Microsoft Intune, Microsoft 365, Azure, and related identity, endpoint, collaboration, and security capabilities.
· Guide the design of modern identity and access capabilities, including adaptive and risk-based access, device trust, authentication strength, passwordless authentication, passkeys, privileged access, application access, and identity lifecycle integration.
· Establish reusable security patterns and guardrails for managed devices, conditional access, authentication, administrative access, application access, secure collaboration, and platform configuration.
· Ensure identity, endpoint, and collaboration controls are risk-based, forward-looking, and designed to minimize unnecessary user friction while maintaining appropriate protection, governance, visibility, and resilience.
· Lead security architecture and engineering considerations for platform modernization and technology transitions, ensuring integrations, dependencies, user impact, operational readiness, control design, and support requirements are addressed as part of the end-to-end solution.
· Evaluate new and evolving platform capabilities and determine how they should be adopted, configured, integrated, and governed to improve security outcomes, operational efficiency, and user experience.
· Establish and mature application security capabilities, including secure software development lifecycle practices, threat modeling, application architecture reviews, secure coding requirements, and engineering standards.
· Implement and govern DevSecOps practices, including static application security testing, dynamic application security testing, software composition analysis, secrets scanning, container security, API security, and Infrastructure-as-Code security controls.
· Ensure code scanning and automated security validation are embedded into CI/CD pipelines, supported by actionable remediation workflows, and measured for effectiveness.
· Define cloud security requirements and reusable patterns for Microsoft Azure and Google Cloud Platform services, identities, networks, workloads, data services, APIs, logging, monitoring, and platform configurations.
· Drive remediation of architectural and engineering risks through collaboration with technology owners and business stakeholders.
· Develop architecture and engineering roadmaps aligned to cybersecurity strategy, enterprise technology direction, platform modernization, and business objectives.
· Establish metrics, KPIs, and maturity measures that demonstrate early security engagement, review efficiency, adoption of secure patterns, control coverage, user impact, and measurable risk reduction.
To Land This Role:
· Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related discipline, or equivalent practical experience.
· Ten or more years of progressive cybersecurity experience with significant security architecture, engineering, and technical leadership responsibilities.
· Experience managing technical security professionals and leading complex cross-functional initiatives.
· Demonstrated ownership of a broad security architecture and engineering service portfolio spanning infrastructure, network, identity, endpoint, cloud, application, data protection, and enterprise technology domains.
· Strong architecture and engineering experience in cloud environments, including Microsoft Azure and Google Cloud Platform.
· Experience defining cloud security architectures, guardrails, reusable patterns, and controls across identities, networks, workloads, platforms, applications, APIs, logging, monitoring, and data services.
· Advanced architecture and engineering experience across the Microsoft ecosystem, including Microsoft Entra, Microsoft Intune, Microsoft 365, Azure, and related identity, endpoint, device management, collaboration, and security capabilities.
· Demonstrated experience designing identity-first security architectures using adaptive and risk-based access controls, managed-device signals, modern authentication, authentication-strength requirements, passwordless authentication, passkeys, privileged access controls, and application access policies.
· Strong knowledge of modern identity architecture, including authentication, authorization, federation, application integration, identity lifecycle management, device trust, privileged access, and phishing-resistant authentication.
· Experience developing secure and usable access patterns that balance risk, business requirements, operational supportability, and user experience.
· Experience designing security architecture for enterprise endpoints, collaboration platforms, network services, cloud services, SaaS applications, and hybrid technology environments.
· Ability to lead architecture and engineering for major platform modernization efforts involving identity, device management, connectivity, cloud, collaboration, or enterprise infrastructure capabilities.
· Demonstrated ability to assess native platform security capabilities and determine when to use built-in controls, integrate complementary technologies, or establish additional compensating controls.
· Demonstrated experience designing end-to-end technology and security processes that connect distributed systems and business processes through integrations, APIs, automation, orchestration, and workflows.
· Ability to evaluate end-to-end solution designs, identify security and operational dependencies, and translate risk into practical architecture and engineering requirements.
· Demonstrated experience integrating security into architecture review boards, enterprise architecture governance, change processes, and technology delivery lifecycles.
· Experience designing low-friction security intake and review processes that engage teams early, provide timely decisions, and maintain appropriate governance and traceability.
· Strong understanding of network security, secure connectivity, segmentation, identity, infrastructure, endpoint security, application security, data protection, API security, cloud security, and enterprise architecture.
· Hands-on experience implementing application security, DevSecOps, and secure software development lifecycle practices.
· Experience integrating security controls, code scanning, and automated validation into CI/CD pipelines and software delivery workflows.
· Ability to communicate effectively with executives, engineers, architects, developers, product leaders, infrastructure teams, and business stakeholders.
· Preferred certifications include CISSP, CCSP, TOGAF, SABSA, CSSLP, CISM, Microsoft security or architecture credentials, Google Cloud security or architecture credentials, or equivalent.
Similar Jobs



More Jobs at Tory Burch LLC





More Information Technology Jobs