Full Job Description
Senior IT Information Security Architect
The Senior IT Information Security Architect is a high-impact technical leadership role responsible for defining, guiding, and validating security architecture across Gentherm's global enterprise technology landscape. This role will establish secure-by-design standards, reference architectures, and practical security requirements for infrastructure, cloud, identity, endpoint, network, application, operational technology, and data protection initiatives. The position partners with Information Security, Infrastructure, Digital Workplace, Enterprise Applications, Engineering, Legal, Internal Audit, Data Protection Officer, and business stakeholders to reduce cyber risk while enabling business transformation.
The role will help mature Gentherm's information security program by translating security strategy, regulatory obligations, customer expectations, and risk priorities into scalable architecture patterns and implementation roadmaps. The IT Security Architect Senior will serve as a senior subject matter expert for security design reviews, Zero Trust architecture, cloud and identity security, vulnerability and risk remediation, incident response readiness, and compliance alignment with frameworks such as NIST Cybersecurity Framework, ISO 27001/27002, TISAX, SOC 2, SOX, GDPR, EU AI Act, NIS2 and other applicable requirements.
ESSENTIAL FUNCTIONS AND RESPONSIBILITIES
• Define, maintain, and govern Gentherm's enterprise security architecture, standards, reference architectures, baseline security configurations, and secure designs across cloud, systems, network, identity, endpoint, application, and data environments.
• Design and guide security architectures for Identity and Access Management (IAM), Single Sign-On (SSO), Multi-Factor Authentication (MFA), Privileged Access Management (PAM), Zero Trust, cloud platforms, Microsoft 365, e-mail security, hybrid
infrastructure, secure remote access, network segmentation, and enterprise integrations.
• Partner with network, systems, applications, digital workplace, engineering, and manufacturing teams to embed security requirements and controls into technology roadmaps, operational processes, and solution designs.
• Lead security architecture reviews, design assessments, and technical risk evaluations for new technologies, projects, acquisitions, and major business initiatives, providing remediation recommendations and tracking risk treatment activities.
• Ensure alignment with security, compliance, and regulatory requirements including SOX, TISAX, ISO 27001, NIST, SOC 2, GDPR, NIS2, EU AI Act, customer security requirements, and internal audit standards by providing architecture guidance, control mappings, and compliance support.
• Define, evaluate, and recommend security technologies, controls, and architectural improvements that enhance confidentiality, integrity, availability, resilience, and regulatory compliance across the global enterprise.
• Work closely with Security Operations to ensure architecture decisions support effective threat detection, monitoring, incident response, forensic readiness, vulnerability management, business continuity, disaster recovery, and cyber resilience objectives.
• Provide senior technical leadership and subject matter expertise during cybersecurity incidents, major risk remediation efforts, vulnerability reduction initiatives, and strategic security transformation programs.
• Develop and monitor architecture-related security metrics, KPIs, and risk indicators; communicate security posture, technology risks, exceptions, and remediation progress to IT leadership and executive stakeholders.
• Coordinates with manufacturing engineering and facility management teams to assess and improve the security of operational technology (OT) and IoT (Internet of Things) systems
• Evaluate security standard exceptions, recommend compensating controls, assess residual risks, and provide guidance on business impact and risk acceptance decisions.
• Lead or support enterprise security initiatives including technology evaluations, proof-of-concept activities, architecture roadmaps, security modernization programs, M&A integration efforts, and emerging technology assessments.
• Collaborate with Logistics and Purchasing teams to conduct security assessments of existing and prospective vendors, and evaluate the audit reports and statements of work (SOWs) for providers to ensure that adequate security protections are in place
• Serve as a trusted advisor and mentor to security engineers, analysts, architects, administrators, and project teams by promoting secure-by-design principles, threat modeling, architecture governance, and security best practices.
• Continuously evaluate emerging cybersecurity threats, technology trends, AI security developments, and industry best practices, and incorporate appropriate improvements into Gentherm's security architecture framework.
MINIMUM QUALIFICATIONS
• Bachelor's degree in Information Security, Information Technology, Computer Science, Engineering, Information Systems, or a closely related field, or equivalent combination of education, certifications, and relevant experience.
• Minimum of eight (8) years of progressive IT or cybersecurity experience, including at least five (5) years in security architecture, security engineering, infrastructure architecture, cloud security, identity security, or enterprise security design roles.
• Demonstrated experience designing, reviewing, or implementing security controls in large enterprise environments with global business, infrastructure, cloud, network, endpoint, and application dependencies.
• Strong working knowledge of enterprise security frameworks and standards such as NIST Cybersecurity Framework, ISO 27001/27002, TISAX, SOC 2, COBIT, MITRE ATT&CK, and applicable privacy or regulatory requirements.
• Hands-on knowledge of identity and access management, SSO, MFA, PAM, conditional access, endpoint security, network security, application security, vulnerability management, incident response, cloud security, and compliance operations.
• Experience conducting security architecture reviews, risk assessments, design gap analysis, control mapping, technical remediation planning, and risk-based prioritization with cross-functional teams.
• Ability to translate complex technical and security concepts into clear business language, architecture decisions, executive-ready recommendations, and actionable implementation requirements.
• Strong documentation, presentation, facilitation, and stakeholder management skills, including experience influencing results in a matrixed global organization.
• Demonstrated ability to lead complex technical workstreams, manage competing priorities, mentor technical staff, and deliver measurable risk reduction outcomes.
• Ability to provide timely support for critical security incidents or urgent risk issues, including limited off-hours escalation support as needed.
PREFERRED QUALIFICATIONS
• Security-related certifications such as CISSP, CISM, CRISC, CCSP, Security+, GIAC, SABSA, TOGAF, Azure Security Engineer, AWS Security Specialty, or equivalent.
• Experience supporting TISAX or ISO 27001 implementation, certification, audit readiness, gap remediation, and evidence collection in a global or manufacturing environment.
• Experience with Microsoft security technologies, including Microsoft Entra ID, Microsoft 365, Defender, Sentinel, Intune, Purview, conditional access, endpoint management, and identity governance capabilities.
• Experience with Azure, AWS, hybrid cloud security, SaaS security, data protection, DevSecOps, application security, secure SDLC, infrastructure as code, and cloud-native security controls.
• Experience with Palo Alto Networks, CrowdStrike, secure remote access, SASE, ZTNA, firewalls, IDS/IPS, NDR, EDR, SIEM/SOAR, vulnerability management platforms, DLP, and email security technologies.
• Automotive supplier, manufacturing, operational technology, product cybersecurity, connected systems, or regulated-industry experience.
• Experience with M&A security assessment and post-acquisition security integration planning.
• Scripting or automation experience using PowerShell, Python, APIs, or similar tools to improve security reporting, control validation, or repetitive security processes.
• Experience preparing executive-level materials, architecture roadmaps, risk reports, business cases, and security metrics for leadership review.
NICE TO KNOW
Travel: Must be willing to travel up to 15% of the time (domestic and international).
Leadership Responsibilities: Providing mentorship and guidance to Information Security Analysts, and cross-functional teams
PHYSICAL DEMANDS/WORK ENVIRONMENT (US):
All positions in our office require interaction with people and technology while either standing or sitting. In order to best serve our customers, internal and external, all associates must be able to communicate face-to-face and on the phone with or without reasonable accommodation.