JM Family Enterprises is seeking an Enterprise Security Architect who designs, governs, and advances enterprise security architecture across the organization. This role creates security strategies and guidelines. It sets standards and requirements as well. These help teams provide secure and scalable technology solutions that align with business goals. The role involves working with architecture, platform, engineering, data, GRC, product, and security teams.
This is an onsite hybrid role from our Deerfield beach office in Florida.
Responsibilities:
- Define and advance enterprise security architecture strategies, priorities, and roadmaps across multiple security domains.
- Maintain the Enterprise Security Framework, reference architectures, standards, requirements, and reusable patterns.
- Provide architecture leadership across cloud, identity, application, data, network, infrastructure, endpoint, cryptography, third-party, and emerging technology domains.
- Translate business use cases and technology strategies into clear, practical, and risk-based security requirements.
- Lead security architecture reviews and provide timely guidance to project, product, engineering, platform, and business teams.
- Create designs for the current state and the desired future state. These designs should show current capabilities, gaps in maturity, investments needed, and priorities for implementation.
- Partner across technology and security teams to assess capability gaps, align remediation plans, and integrate security controls into enterprise architecture.
- Lead threat modeling. Assess any deviations or exceptions in architecture. Provide risk-based recommendations to support governance, review, and approval processes
- Evaluate third-party technologies, SaaS platforms, cloud services, and emerging capabilities using a risk-based approach and provide clear recommendations to leadership.
- Make sure the architecture meets the needs for logging, monitoring, and detection. It must also support incident response, fortitude, and recovery capabilities.
- Support secure adoption of AI-enabled applications, platforms, and agents where applicable.
- Enable teams by providing documentation. Share reusable patterns and offer guidance on architecture. Provide coaching and communication with executives.
Qualifications:
- 10+ years of progressive experience in cybersecurity, security engineering, technology architecture, or a closely related discipline.
- 5+ years of experience in a senior-level enterprise security architecture role within a large or complex organization.
- Broad expertise in key security areas. These areas include cloud security, identity management, application security, data protection, network security, infrastructure security, endpoint security and cryptography.
- Demonstrated depth in at least two enterprise security domains, with the ability to lead complex architecture decisions and provide authoritative security guidance.
- Experience in designing security architectures for enterprises. This includes making frameworks. It also involves creating reference architecture. Additionally, it includes setting standards, defining requirements, and developing reusable patterns.
- Experience in evaluating current capabilities. Defining target states. Identifying maturity gaps. Developing security strategies that align with business priorities and create roadmaps for implementation.
- Strong understanding of Zero Trust and modern identity architectures, including SSO, federation, Conditional Access, RBAC, privileged access, and non-human identities.
- A robust background in cloud security is required. Experience with Microsoft Azure is preferred. Candidates should know about identity, networking, logging, encryption, workload protection, and landing-zone concepts.
- Working knowledge of secure software development, DevSecOps, APIs, Infrastructure as Code, CI/CD security, containers, and modern application architectures.
- Proficient in data security and privacy. This includes classification, encryption, data loss prevention (DLP), access control, retention, data transfer, and regulatory requirements.
- Experience in leading threat modeling. This includes governance of architecture and design reviews. It also involves managing exceptions, conducting risk assessments, and validating controls.
- Experience applying recognized security frameworks and standards such as NIST, ISO, CIS Controls, MITRE ATT&CK, SABSA, or equivalent frameworks.
- Strong communication and influencing skills, with the ability to translate technical risk into executive-level insights and recommendations.
- Bachelor's degree in computer science, Cybersecurity, Information Technology, Engineering, or an equivalent combination of education and professional experience; relevant security or architecture certifications are preferred.
Preferred Qualifications:
- Experience securing AI-enabled applications, copilots, agents, RAG solutions, model integrations, or enterprise AI platforms.
- Familiarity with established AI security, risk management, and governance practices, including how they apply to enterprise technology environments.
- Understanding of AI-related risks such as prompt injection, data disclosure, insecure tool access, shadow AI, and over-permissive agent identities.
- Experience integrating AI security requirements into architecture reviews, platform governance, threat modeling, monitoring, and incident response.
- Experience with Microsoft Azure security capabilities, including Entra ID, Defender for Cloud, Sentinel, Azure Policy, Key Vault, and landing zones.
- Experience with major enterprise security technologies across cloud, network, identity, data protection, endpoint, and Security Operations domains.
This job description may not be inclusive of all assigned duties, responsibilities, or aspects of the job described, and may be amended at any time at the sole discretion of JM Family. All work arrangements are subject to associate performance, business need and manager discretion, and may be revised as necessary.