Security Risk Architect

L.E.K. Consulting LLC
Boston, MA, United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Compensation
$130,000.0 - $150,000.0
Working hours
Regular working hours
Job source

Tech stack

Active Directory Artificial Intelligence Software System Penetration Testing Microsoft Azure Cloud Computing Security Static Program Analysis Cyber Security Data Governance Digital Forensics Disaster Recovery Identity and Access Management Open Web Application Security
+11 more
Secure Coding Software Engineering Software Vulnerability Management Cloud Platform System Microsoft Power Automate Software Security AI Platforms Information Technology Free and Open-Source Software Static Application Security Testing Dynamic Application Security Testing

Job description

The Security & Risk Architect is a senior technical leader within the Information Security team, responsible for advancing the firm’s cybersecurity strategy and strengthening enterprise security capabilities across infrastructure, cloud platforms, applications, and emerging AI technologies.

This role partners closely with IT, engineering, and business stakeholders to manage security operations, vulnerability management, incident response, secure software development practices, and AI security governance. The position supports a global environment aligned to the NIST Cybersecurity Framework and ISO 27001 standards., Security Operations & Risk Management

  • Identify, assess, and respond to cybersecurity and privacy risks across the organization
  • Serve as a technical escalation point for security incidents, investigations, and threat response activities
  • Support incident response, digital forensics, and coordination during critical security events
  • Monitor threat intelligence and recommend proactive risk mitigation strategies

Security Architecture & Tooling

  • Lead the management and optimization of enterprise security tools and platforms
  • Evaluate security technologies, identify capability gaps, and recommend improvements
  • Manage security controls across Active Directory, Azure, Entra ID, endpoint security, and cloud environments
  • Ensure systems and infrastructure maintain secure and hardened configurations

Vulnerability & Compliance Management

  • Oversee vulnerability management processes, reporting, and remediation coordination
  • Configure and maintain security monitoring, reporting, and compliance metrics
  • Drive continuous improvement initiatives across security processes, tools, and policies
  • Support disaster recovery, backup oversight, and operational resilience efforts

Application Security & Secure Development

  • Integrate security requirements into the software development lifecycle
  • Partner with development teams to implement secure-by-design practices within CI/CD pipelines
  • Lead application security reviews, code analysis, and penetration testing activities
  • Promote secure coding standards aligned with OWASP, NIST, and ISO 27001 frameworks
  • Manage third-party and open-source software risk, including supply chain security controls

AI Security & Governance

  • Support governance and security oversight for AI platforms and tools, including Microsoft Copilot and Azure OpenAI
  • Establish controls for AI usage, access management, and data governance
  • Monitor emerging AI security risks, including prompt injection, adversarial behavior, and data exposure threats
  • Partner with legal, compliance, and business stakeholders to develop responsible AI usage policies

Requirements

Do you have experience in Stakeholder relationship building?, Do you have a Bachelor’s degree?, * Bachelor’s degree or equivalent experience

  • 6+ years of experience in Information Technology, including 3+ years in Information Security
  • Experience with enterprise security technologies and cloud security platforms
  • Familiarity with cybersecurity frameworks such as NIST and ISO 27001
  • Knowledge of application security concepts, including SAST, DAST, SCA, and secure coding practices
  • Understanding of AI/ML security risks and governance principles
  • Relevant certifications such as CISSP, Security+, or CEH are preferred

Skills & Competencies

  • Strong analytical and problem-solving skills
  • Excellent communication and stakeholder management abilities
  • Ability to lead initiatives and mentor junior team members
  • Strong organizational and project management skills
  • Adaptability in a fast-paced, evolving environment
  • Ability to influence technical strategy and drive cross-functional security initiatives

Benefits & conditions

Pulled from the full job description

  • 401(k)
  • Health insurance
  • Paid time off
  • Vision insurance
  • Health savings account
  • Dental insurance
  • Life insurance, * The expected base salary range for this position is $130,000 - $150,000 annually. Actual compensation will be determined based on experience, qualifications, skills, and location. This position may also be eligible for discretionary bonus and a comprehensive benefits package.
  • L.E.K. Consulting offers a competitive total rewards package including medical, dental, vision, life and disability insurance, 401(k) with employer contribution, HSA contributions (where applicable), paid time off, and other firm-sponsored benefits.
  • This role is based in any of our U.S. office and follows our hybrid work model for U.S. offices. We require employees to be in their assigned home office Tuesday, Wednesday, and Thursday each week, as well as the first Friday of each month.
  • Applicants must be legally authorized to work in the United States on a permanent basis without the need for employer sponsorship. Unfortunately, we are unable to consider candidates requiring visa sponsorship, including but not limited to H-1B, TN, F-1 (OPT/CPT/STEM), or other work authorization.
  • L.E.K. Consulting is an Equal Opportunity Employer. We are committed to providing equal employment opportunities to all qualified individuals regardless of race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law.
  • In accordance with applicable state and local laws, we will provide reasonable accommodations for qualified individuals with disabilities and for sincerely held religious beliefs, practices, or observances.

About the company

L.E.K. Consulting is one of the premier strategy consulting firms worldwide. At L.E.K., we are passionate about helping our clients succeed with breakthrough insights that drive real impact. Our clients view us as trusted partners that help address their most pressing challenges and biggest opportunities.

We bring together the rigor of data-driven analysis with the creativity and curiosity of a collaborative team. By hiring exceptional people and fostering a culture of ownership, inclusion, and continuous learning, we develop leaders who thrive on challenge and bring energy and optimism to every engagement. Founded in 1983, L.E.K. employs more than 2,200 professionals across five continents, and is consistently recognized as one of the industry’s best firms to work for. For more information, visit lek.com.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:36 min

Choosing between managed AI platforms and custom governance

Péter Farkas Péter Farkas · Europe 2026 Virtual

2:59 min

Applying secure coding practices and proactive system monitoring

Mihaela-Roxana Ghidersa · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

10:35 min

Teaching and coaching security concepts for lasting impact

Tanya Janca · WWC 2021

3:03 min

Career evolution in data engineering and AI platforms

Maria Apazoglou · Coffee With Developers

Videos

See all

Related articles

See all