Full Job Description
Enterprise Architects work with stakeholders, leadership, and subject matter experts to build a holistic view of the organization's value streams, goals, strategies, capabilities, processes, information, and information technology assets. The role of the enterprise architect is to ensure that the business and IT are in alignment. The enterprise architect links the business mission, strategy, capabilities and processes of an organization to its IT strategy, documents this using multiple architectural models or views that show how the current and future needs of an organization will be met in an efficient, sustainable, agile, and adaptable manner, and fosters the changes needed to achieve.
Costco's Architecture team is looking for a highly ambitious, self-motivated, experienced technical individual to fill the role of Enterprise Architect with a focus on Information Security and Compliance. This architect will partner with IT business areas to govern, design and implement secure information systems that support Costco's global system architecture. They will translate business objectives and risk management strategies into enterprise standards, reference architectures, and secure-by-design patterns across on-prem, hybrid, and cloud environments, and will guide the secure adoption of emerging technologies, including AI. This architect must possess demonstrable knowledge of cloud security, networking, identity and access management, and regulatory compliance, and will serve as a senior trusted advisor to project teams and IT leaders.
ROLE
3 Partners with Enterprise Architecture to develop strategies, standards, and secure reference architectures for enterprise solutions.
3 Reviews and designs new systems, embedding security and compliance requirements.
3 Creates reusable security design patterns and reference architectures; drives zero trust and secure-by-design adoption across the enterprise.
3 Creates design Security reference architectures, technical target architectures, conceptual solution architectures and patterns that can be repeatedly utilized across Costco systems and ensures these architectures are documented and periodically ratified.
3 Identifies dependencies with Costco value streams and shared services based on enterprise security architectures.
3 Identifies and integrates essential safeguards and practices into the overall solution design of technology initiatives to deliver security requirements, documenting any residual risks.
3 Maintains Security related Business Capability Hierarchies and collaborates with Security delivery teams to assess maturity of the capabilities resulting in heat maps and road maps.
3 Analyzes technical risks, conducts threat modeling and security architecture reviews, and advises on risk mitigation strategies.
3 Defines security patterns for machine and non-human identities (service accounts, workload identities, API keys, and AI agents), including credential lifecycle, least-privilege scoping, and workload identity federation.
3 Establishes software supply chain security requirements, including third-party and open-source software risk, SBOM visibility, and secure software development lifecycle practices aligned to NIST SSDF (SP 800-218).
3 Takes responsibility for the technical content (architecture and design), integrity, quality, and security of solutions.
3 Addresses compliance requirements such as Payment Card Industry (PCI), Health Insurance Portability and Accountability Act (HIPAA), Personally Identifiable Information (PII), and Sarbanes-Oxley (SOX).
3 Designs and deploys secure cloud solutions and applies best practices in security for cloud, hybrid, and on-prem applications.
3 Defines secure patterns, standards, and governance for the adoption of AI/ML, generative AI, and agentic AI systems.
3 Serves as a senior trusted advisor, providing security-focused architecture consulting to project teams and IT leaders.
3 Defines data protection architectures spanning data classification, data loss prevention (DLP), encryption and key management, tokenization, and data security posture management (DSPM) across cloud and on-prem data stores.
3 Develops secure API and integration patterns (API gateways, service-to-service authentication and authorization) for internal and partner-facing services.
3 Partners with Security Operations and Incident Response to translate incident findings, threat intelligence, and red/purple team results into architectural improvements and updated patterns.
3 Co-designs the security related integration and deployment architectures for our on-premise and Cloud Networks.
3 Supports the development of product roadmaps based on delivery or prioritized features.
3 Evaluates and recommends security technologies and services (RFI/RFP, proof of concept) and drives consolidation and rationalization of the enterprise security tooling portfolio.
3 Coaches and mentors peers and associates in Costco's architecture framework.
3 Measures and matures Costco's Enterprise Architects practice.
3 Establishes and maintains Costco's Architectural Framework and Governance Model.
3 Participates in team planning and activities for improving skills, knowledge, and quality of work.
3 Continues personal growth in the areas of technology, business knowledge, and company policies.
REQUIRED
3 Interpersonal skills, including collaboration, facilitation, and negotiation.
3 Experience with architecture frameworks, methods, and tools.
3 Graphical modeling skills.
3 Analytical skills.
3 Planning and organizational skills.
3 Applied broad knowledge of technical domains (application, information, integration, and infrastructure) and business functional domains.
3 Ability to assess risks and apply risk profiles to Enterprise Architects alternatives.
3 Ability to estimate the financial impact of Enterprise Architects alternatives.
3 Understands the political climate of an enterprise and how to navigate the politics.
3 10+ years' of professional Information Technology experience in solutioning, designing, development, and delivering Architecture solutions for larger enterprise.
3 5+ years' experience in a senior architecture role, with expertise across security disciplines such as identity and access management (IAM), networking, application security, and infrastructure, Security operations.
3 5+ years' enterprise-level experience designing and deploying secure cloud solutions (Azure, GCP, or AWS), integrating identity and access management, network security, data protection, and encryption.
3 5+ years' of technical team leadership experience.
3 Experience designing security standards and patterns to ensure compliance with regulatory requirements and industry frameworks such as PCI, SOX, HIPAA, GDPR, ISO 27001, and NIST.
3 Experience with zero trust architecture, threat modeling, and security architecture reviews.
3 Experience applying industry security architecture frameworks and references such as SABSA, NIST Cybersecurity Framework (CSF) 2.0, CIS Controls, and MITRE ATT&CK.
3 Demonstrates a strong understanding of emerging technologies, including AI/ML, and their security and governance implications.
3 Excellent verbal and written communication skills; ability to translate technical designs and security trade-offs to multiple audiences, including Executives.
3 Proven skills in leadership, collaboration, governance, and consensus building within a large, matrixed organization.
Recommended
3 Bachelor's degree or equivalent experience in computer science, information systems, cybersecurity, or related fields.
3 Industry certifications such as CISSP, CCSP, CISM, or TOGAF.
3 Cloud security certifications (e.g., AWS Certified Security - Specialty, Google Professional Cloud Security Engineer, Microsoft Azure security certifications), SABSA (SCF), or CCSK.
3 Experience with AI security and governance frameworks (e.g., NIST AI RMF, ISO/IEC 42001).
3 Experience securing generative and agentic AI systems and their non-human identities (e.g., OWASP Top 10 for LLM Applications, OWASP Agentic Security guidance, MCP/A2A protocol security considerations).
3 Experience with containers (Kubernetes, Docker), Infrastructure as Code, and DevSecOps practices.
3 Experience and understanding of Costco's business model and legacy systems.
3 Extensive knowledge in one or more of the following areas: Identity and Access Management, Cloud Security, Cloud Networking, Data Security, Infrastructure Security, Zero Trust, Security Ops, Security Engineering.
3 Proficient in Google Workspace applications, including Sheets, Docs, Slides, and Gmail.
Required Documents
3 Cover Letter
3 Resume
Pay Ranges:
Level 3 - $171,000 - $205,000, Bonus and Restricted Stock Unit (RSU) eligible
Level 4 - $201,000 - $240,000, Bonus and Restricted Stock Unit (RSU) eligible
We offer a comprehensive package of benefits including paid time off, health benefits - medical/dental/vision/hearing aid/pharmacy/behavioral health/employee assistance, health care reimbursement account, dependent care assistance plan, short-term disability and long-term disability insurance, AD&D insurance, life insurance, 401(k), stock purchase plan to eligible employees.