OverviewWho we're looking forToyota Financial Services (TFS) Technology is seeking a highly experienced and outcome-driven
Lead Security Architect to define, govern, and advance a threat-informed, data-centric security architecture across enterprise platforms and business services.
This role is accountable for embedding Data-Centric Threat Modeling (NIST SP 800-154) into the architecture lifecycle ensuring that security decisions are driven by how data is created, processed, stored, and exposed, rather than relying solely on perimeter or technology-centric controls. The ideal candidate will operate as a senior technical authority, influencing design decisions, enforcing architectural standards, and driving measurable improvements in control effectiveness across TFS environments.
What you'll be doingLead Data-Centric Threat Modeling- Own and operationalize Data-Centric Threat Modeling (NIST SP 800-154) across application, cloud, and enterprise architectures
- Identify threats, attack paths, and control gaps based on data flows, sensitivity, and business impact
- Integrate threat modeling into solution design, architecture reviews, and delivery pipelines
- Drive consistency through standardized methodologies and tooling (e.g., Threat Modeler, IriusRisk)
Define & Enforce Security Architecture- Establish and govern security architecture standards, patterns, and reference models aligned to TFS policy and risk tolerance
- Lead architecture design reviews and provide binding security decisions for critical initiatives
- Ensure solutions align to Zero Trust principles, least privilege access, and data protection requirements
Drive Risk-Based Decision Making- Translate threat models and architectural assessments into actionable risk insights for executives and stakeholders
- Support risk acceptance, exception handling, and architectural trade-offs with clear business impact articulation
- Identify control gaps and redundancies across security tooling; recommend optimization and rationalization strategies
Partner Across the Organization- Collaborate with engineering, infrastructure, data, and application teams to embed security early in the development lifecycle
- Influence third-party and vendor design reviews using threat-informed architecture criteria, not just checklist-based assessments
- Align with risk and compliance teams to ensure regulatory expectations (e.g., financial services controls) are integrated into design
Evaluate Control Effectiveness- Move beyond artifact review (e.g., SOC 2, ISO 27001) to assess real-world control effectiveness against identified threats
- Correlate assurance evidence with actual attack scenarios and data exposure risks
- Drive continuous improvement in architecture based on evolving threats and control performance
What you bring- Deep expertise in enterprise security architecture across cloud, application, identity (Identity and Access Management), and network domains
- Proven experience applying threat modeling methodologies, especially data-centric approaches (NIST SP 800-154)
- Hands-on experience with threat modeling tools (e.g., IriusRisk/Threat Modeler, Microsoft Threat Modeling Tool, or equivalents) - strongly preferred
- Strong understanding of data protection, data flow analysis, and sensitive data handling within financial services environments
- Experience influencing complex, cross-functional architecture decisions at scale
- Ability to translate technical threats into business risk and executive-lev
Added bonus if you have- Certified Information Systems & Security Professional (CISSP), Certified Information Security Manager (CISM), or equivalents
What we'll bringDuring your interview process, our team can fill you in on all the details of our industry-leading benefits and career development opportunities.
A few highlights include:
• A work environment built on teamwork, flexibility and respect
• Professional growth and development programs to help advance your career, as well as tuition reimbursement
• Team Member Vehicle Purchase Discount
• Toyota Team Member Lease Vehicle Program (if applicable)
• Comprehensive health care and wellness plans for your entire family
• Toyota 401(k) Savings Plan featuring a company match, as well as an annual retirement contribution from Toyota regardless of whether you contribute
• Paid holidays and paid time off
• Referral services related to prenatal services, adoption, childcare, schools and more
• Tax Advantaged Accounts (Health Savings Account, Health Care FSA, Dependent Care FSA)
• Relocation assistance (if applicable)