Position Summary:The
Enterprise Information Security Architect leads the definition and implementation of enterprise wide cybersecurity strategies. In collaboration with other architects, engineers, and IT/Security specialists, this role is responsible for analyzing current Information Technology (IT) and Cyber Security trends, developing technology strategies, policies, standards, and roadmaps to provide guidance for technology solutions and planning efforts. Additionally, they are responsible to provide leadership on product evaluation and implementation as well as support cybersecurity risk reduction efforts across the organization. Their primary goal is to provide strategic focus and consistency across the enterprise in an effort to protect company information and technology assets.
What you will do:- Embraces an enterprise level architecture focus and alignment with the overall company business strategy
- In collaboration with other architects, engineers, and IT/Security specialists defines the enterprise information security architectural vision and strategic roadmaps, and supporting implementations through key initiatives and projects
- Engages with the architecture teams as well as all other technology architects and engineers to ensure adherence to the cybersecurity architectural vision and standards
- Provides leadership and oversight to planning and implementation of strategic IT information security solutions
- Partners with other architecture and technology leaders in defining complex, cross domain solutions
- Researches current technologies that will protect company information and technology assets
- Provides leadership in technology vendor evaluations to determine the preferred technology and partners
- Collaborates with IT Project teams to determine security requirements and design. This includes but is not limited to NIST, SOX, PCI, IAM, API, Zero Trust, IoT, and Cloud
- Fulfill the role of Lead Engineer on key EIS/Security projects
- Mentor and provide leadership to other cybersecurity architects, engineers, and analysts
- Participation on the PCI Team (collaboration with Stores)
- Provide assistance with the development/maintenance of IT Policies and Security Employee Awareness programs
- Coordinate with the security Team Managers to develop and maintain the Enterprise Security roadmaps of products and projects
- Other duties and responsibilities as assigned
When you will work:- Monday to Friday, 8am to 5pm
- Hybrid schedule, 4 days in office in Wyoming, MI or Atlanta, GA with 1 day remote
What you'll bring to the table:- Bachelor's Degree in Business, Computer Science, or a related field required.
- Five or more years' experience in:
- Security architecture, demonstrating solutions delivery, principles and emerging technologies: Designing and implementing security solutions. This includes continuous monitoring and making improvements to those solutions, working with a cybersecurity team.
- Consulting and engineering in the development and design of security best practices and implementation of solid security principles across the organization, to meet business goals along with customer and regulatory requirements.
- Security considerations of cloud computing including: data breaches, broken authentication, hacking, account hijacking, malicious insiders, third parties, APTs, data loss and DoS attacks.
- Cloud concepts including: governance, computing, networking, workload configuration, data protection, compliance, Identity and Access Management
- Identity and access management (IAM): the framework of security policies and technologies that limit and track the access of those in an organization to sensitive technology resources.
- Prior work experience to include:
- Java/J2EE, API/web services, scripting languages and a relational database management system (RDBMS) such as MS SQL Server, Oracle or BigQuery. These are some of the technical elements needed to build security into an organization.
- Relevant National Institute of Standards and Technology (NIST) standards.ISO27001 - specifications for a framework of policies and procedures that include all legal, physical and technical controls involved in an organization's risk management.
- Control Objectives for Information and Related Technologies (COBIT).
- Must have excellent written, verbal, organizational and communication skills
- Must have the ability to multitask, prioritize and be able to work independently or within a team environment
- Must have good customer service and time management skills
- Ability to develop solutions to a variety of complex problems, and reference established precedents and policies