> Markdown version of [/jobs/ext/115088-security-risk-architect](https://www.wearedevelopers.com/jobs/ext/115088-security-risk-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Risk Architect - **Company:** L.E.K. Consulting LLC - **Location:** Boston, MA, United States - **Experience:** Expert - **Salary:** $130,000.0 - $150,000.0 - **Contract:** Permanent contract - **Skills:** Active Directory, Artificial Intelligence, Software System Penetration Testing, Microsoft Azure, Cloud Computing Security, Static Program Analysis, Cyber Security, Data Governance, Digital Forensics, Disaster Recovery, Identity and Access Management, Open Web Application Security, Secure Coding, Software Engineering, Software Vulnerability Management, Cloud Platform System, Microsoft Power Automate, Software Security, AI Platforms, Information Technology, Free and Open-Source Software, Static Application Security Testing, Dynamic Application Security Testing - **Published:** May 20, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=422c37f48e2f7ea2 ## About the Role Do you have experience in Stakeholder relationship building?, Do you have a Bachelor's degree?, * Bachelor's degree or equivalent experience * 6+ years of experience in Information Technology, including 3+ years in Information Security * Experience with enterprise security technologies and cloud security platforms * Familiarity with cybersecurity frameworks such as NIST and ISO 27001 * Knowledge of application security concepts, including SAST, DAST, SCA, and secure coding practices * Understanding of AI/ML security risks and governance principles * Relevant certifications such as CISSP, Security+, or CEH are preferred Skills & Competencies * Strong analytical and problem-solving skills * Excellent communication and stakeholder management abilities * Ability to lead initiatives and mentor junior team members * Strong organizational and project management skills * Adaptability in a fast-paced, evolving environment * Ability to influence technical strategy and drive cross-functional security initiatives ## Description The Security & Risk Architect is a senior technical leader within the Information Security team, responsible for advancing the firm's cybersecurity strategy and strengthening enterprise security capabilities across infrastructure, cloud platforms, applications, and emerging AI technologies. This role partners closely with IT, engineering, and business stakeholders to manage security operations, vulnerability management, incident response, secure software development practices, and AI security governance. The position supports a global environment aligned to the NIST Cybersecurity Framework and ISO 27001 standards., Security Operations & Risk Management * Identify, assess, and respond to cybersecurity and privacy risks across the organization * Serve as a technical escalation point for security incidents, investigations, and threat response activities * Support incident response, digital forensics, and coordination during critical security events * Monitor threat intelligence and recommend proactive risk mitigation strategies Security Architecture & Tooling * Lead the management and optimization of enterprise security tools and platforms * Evaluate security technologies, identify capability gaps, and recommend improvements * Manage security controls across Active Directory, Azure, Entra ID, endpoint security, and cloud environments * Ensure systems and infrastructure maintain secure and hardened configurations Vulnerability & Compliance Management * Oversee vulnerability management processes, reporting, and remediation coordination * Configure and maintain security monitoring, reporting, and compliance metrics * Drive continuous improvement initiatives across security processes, tools, and policies * Support disaster recovery, backup oversight, and operational resilience efforts Application Security & Secure Development * Integrate security requirements into the software development lifecycle * Partner with development teams to implement secure-by-design practices within CI/CD pipelines * Lead application security reviews, code analysis, and penetration testing activities * Promote secure coding standards aligned with OWASP, NIST, and ISO 27001 frameworks * Manage third-party and open-source software risk, including supply chain security controls AI Security & Governance * Support governance and security oversight for AI platforms and tools, including Microsoft Copilot and Azure OpenAI * Establish controls for AI usage, access management, and data governance * Monitor emerging AI security risks, including prompt injection, adversarial behavior, and data exposure threats * Partner with legal, compliance, and business stakeholders to develop responsible AI usage policies ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [This App Reached 10,000 Users in One Week. Here's How.](https://www.wearedevelopers.com/videos/100329-this-app-reached-10-000-users-in-one-week-here-s-how) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [How GitHub secures open source](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)