Senior Manager, Security Architecture

Simpson Thacher and Bartlett LLP

$190K — $220K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in information security, IT, or related discipline
  • 10+ years of experience in IT or Information Security
  • 5+ years in an enterprise or security architecture role
  • Strong technical knowledge of security frameworks and tools
  • Professional certifications such as CISSP, CCSP, or CISM preferred

Responsibilities

  • Define and evolve the enterprise security architecture framework
  • Develop and maintain security architecture roadmaps
  • Participate in IT architecture review for security compliance
  • Architect secure implementations across hybrid environments
  • Establish configuration management and system hardening standards
  • Define AI security usage standards and best practices
  • Conduct security architecture reviews to identify risks

Benefits

  • Flexible working arrangements with hybrid options
  • Strong emphasis on training and continuous learning
  • Collaborative and inclusive work environment
  • Access to latest security tools and technologies
  • Opportunity to work with global teams on cutting-edge projects
Full Job Description
The Senior Manager, Enterprise Security Architecture, is responsible for developing and leading a modern security architecture framework that ensures systems, applications, and data are secure by design. This role drives the evaluation, integration, and governance of security solutions, including AI-enabled capabilities-that align with business objectives and evolving threat landscapes. The position establishes enterprise technical standards, embeds risk mitigation strategies, and leverages cyber threat intelligence to proactively identify, assess, and address emerging risks.

The ideal candidate is a hands-on engineer with deep expertise in security frameworks, infrastructure, and cloud environments as well as a strong understanding of AI-driven security use cases and adversarial risks. They bring a strong security mindset-thinking like an attacker to identify and address vulnerabilities-and excel at influencing and collaborating across teams. This individual is adaptable, meticulous, and able to navigate complexity, solve problems quickly, and drive effective outcomes in a dynamic environment. This is an individual contributor role.

ESSENTIAL JOB DUTIES & RESPONSIBILITIES
  • Define, establish, and continuously evolve the enterprise security architecture framework aligned to business and technology strategy.
  • Develop and maintain target-state security architecture roadmaps, ensuring alignment with enterprise architecture and business objectives.
  • Participate in Firm's IT architecture review board to ensure that new initiatives and related projects adhere to Firm security architecture strategy, including review and approval of key design documents.
  • Architect and guide secure implementations across hybrid environments, including on-premises, cloud, and containerized platforms.
  • Establish and enforce secure configuration management and system hardening standards.
  • Define standards and best practices for secure use of AI, including data protection, access controls, and safe consumption patterns.
  • Evaluate and secure enterprise adoption of AI-powered tools, platforms, and third-party services.
  • Partner with engineering teams to embed security controls into AI/ML lifecycles.
  • Create technical security standards and guidelines for all IT assets, including servers, endpoints, cloud platforms, hypervisors, mobile devices, network devices, and emerging technologies.
  • Conduct security architecture reviews to identify gaps, risks, and drive remediation strategies.
  • Document the impact of new systems and integrations on the Fim's overall security posture.
  • Oversee the security tools portfolio, ensuring effective selection, deployment, and integration across the technology stack.
  • Lead proof of concepts, testing, and integration of new security tools, services, configurations, and risk mitigation strategies.
  • Design and implement cybersecurity solutions to prevent unauthorized access, detect threats, and mitigate cyber-attacks across IT systems.
  • Function as a trusted advisor to business, IT teams, and product organizations on security architecture and technology risk management.
  • Define, and report key performance indicators (KPIs) to measure security effectiveness and maturity.
  • Stay current on emerging threats, technologies, and industry trends to proactively reduce organizational risk.
  • Build strong cross-functional partnerships across global teams and external stakeholders.


EDUCATION

Required
  • Bachelor's degree in information security, IT, related discipline, or equivalent experience

Preferred
  • Professional certifications such as CISSP, CCSP, CISM, or similar


SKILLS AND EXPERIENCE
  • 10+ years of experience in an IT or Information Security role, with at least 5 years of experience in an enterprise or security architecture role
  • Strong technical knowledge of security frameworks, security tools, encryption standards, authentication and authorization standards and infrastructure security standards
  • Deep expertise across security domains - Infrastructure Security, Identity and Access Management, Data Protection and Application Security
  • Knowledge of AI/ML, cloud platforms, and hybrid architecture.
  • Experience planning and building enterprise cloud security at scale and mitigating security threats in the cloud.
  • Experience working in a global organization and broad knowledge of security domains, technology risk management concepts, and a working knowledge of security and risk frameworks.
  • Knowledge of common application architectures, design, protocols, and agile deployment methodology and best practices.
  • Hands-on engineering experience across servers, endpoints, networks, mobile, and cloud computing.
  • Knowledge of core networking concepts including TCP/IP, firewalls, and network security products.
  • Ability to create and execute a clear strategic vision for target state architecture that supports and enables businesses functions.
  • Ability to manage multiple concurrent projects and activities and make effective judgments in prioritizing and time allocation.
  • Must be able to execute with limited information and ambiguity.
  • Must have a continuous learning mindset and a demonstrated aptitude for understanding strategic investments and new technologies.
  • Must be able to build collaborative relationships and is comfortable interacting frequently with leadership and internal/external stakeholders


Salary Information

NY Only: The estimated base salary range for this position is $190,000 to $220,000 at the time of posting.

The actual salary offered will depend on a variety of factors, including without limitation, the qualifications of the individual applicant for the position, years of relevant experience, level of education attained, certifications or other professional licenses held, and if applicable, the location in which the applicant lives and/or from which they will be performing the job. This role is exempt meaning it is not overtime pay eligible.

Simpson Thacher will not sponsor applicants for work visas for this position.

Privacy Notice

For information about how Simpson Thacher & Bartlett LLP collects and processes your personal information, please refer to our Privacy Notice available at https://www.stblaw.com/other/privacy-notice.

#LI-Hybrid

Similar Jobs

More Jobs at Simpson Thacher and Bartlett LLP

More Information Technology Jobs

Find similar Senior Manager, Security Architecture jobs: