Security Hub Lead/Architect
Role details
Job location
Tech stack
Job description
Security Hub Architecture & Design
Define the end-to-end Security Hub architecture aligned with enterprise security and DPC requirements.
Design a control-driven security framework supporting approximately 60 controls across multiple security domains.
Establish Security Hub as the centralized system of record for security findings, governance, and reporting.
Define high availability, resiliency, scalability, and disaster recovery requirements.
Develop logical, physical, and integration architecture artifacts.
Security Controls & Detection
Design and implement triple-mode detection capabilities utilizing:
Real-time security events
Observability metrics
Periodic compliance and security scans
Translate enterprise security controls into enforceable technical controls.
Define control validation, compliance monitoring, and evidence-generation requirements.
Establish control traceability and audit-readiness processes.
Integration Architecture
Define an integration-first architecture supporting event-driven security operations.
Design integrations with:
Keycloak
Ranger
OpenShift APIs
Kafka
LGTM
StorageGRID
DataHub
Vault/Venafi
ServiceNow
Enterprise observability platforms
Define telemetry ingestion, normalization, correlation, and workflow orchestration patterns.
Automation & AI Enablement
Design automated remediation workflows and approval-gated enforcement processes.
Define AI-assisted triage, root-cause analysis, prioritization, and recommendation capabilities.
Leverage accelerator frameworks and reusable implementation patterns to accelerate delivery.
Ensure AI-enabled capabilities align with enterprise governance and architecture standards.
Governance & Operational Readiness
Participate in architecture governance, design reviews, and stakeholder workshops.
Support development of operational processes, runbooks, and support models.
Ensure alignment with compliance, risk, audit, and regulatory requirements., Successful deployment of Security Hub on OpenShift
Full implementation of planned security controls
Successful integration across enterprise and DPC platforms
Audit-ready reporting and compliance evidence generation
Automated remediation and workflow orchestration operational
Achievement of performance, scalability, and resiliency objectives
Successful production deployment and transition to steady-state operations
This role would be considered the technical authority for the entire Security Hub program, responsible for ensuring the solution architecture supports governance, integrations, automation, reporting, and long-term operational sustainability.
Requirements
Experience
15+ years of cybersecurity, cloud security, or security architecture experience.
5+ years designing and implementing enterprise security platforms.
Experience leading large-scale security transformation initiatives within highly regulated environments.
Experience establishing centralized security operations, governance, and compliance platforms.
Technical Skills
Security Architecture
OpenShift / Kubernetes
Cloud Security (AWS, Azure, Google Cloud Platform)
SIEM / SOAR Platforms
Security Operations (SecOps)
Vulnerability Management
Identity & Access Management (IAM)
Event-Driven Architecture
Kafka
API Integration
ServiceNow
Observability Platforms
Security Control Frameworks
Security Framework Knowledge
NIST Cybersecurity Framework
CIS Controls
NIST 800-53, Experience designing Security Hub, SIEM, SOC, CNAPP, CSPM, or centralized security platforms.
Experience implementing control-driven governance models.
Experience with ServiceNow Security Operations.
Experience with policy-as-code and automation frameworks.
Experience integrating AI/GenAI capabilities into security operations.
Experience supporting financial services organizations and regulatory environments.
Key Deliverables
Security Hub Architecture Documents
Control Framework Design
Triple-Mode Detection Design
Integration Architecture & Data Flow Designs
Security Control Mapping & Traceability Matrix
Automation & Remediation Architecture
Reporting & Compliance Architecture
Operational Readiness & Governance Artifacts
Architecture Review & Approval Packages