> Markdown version of [/jobs/ext/1247834-enterprise-integration-security-architect](https://www.wearedevelopers.com/jobs/ext/1247834-enterprise-integration-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Enterprise Integration Security Architect - **Company:** State Street - **Location:** Quincy, MA, United States - **Experience:** Expert - **Salary:** $120,000.0 - $202,500.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Application Integration Architecture, User Authentication, Microsoft Azure, Software as a Service, Cloud Engineering, Cyber Security, Software Design Patterns, Electronic Data Interchange (EDI), Middleware, File Transfer, IBM WebSphere MQ, Internet Security, Information Systems Security Architecture Professional, Key Management, Enterprise Messaging Systems, OAuth, Public Key Infrastructure, RabbitMQ, Openid Connect, Cloud Services, Zero Trust Network Access, JSON Web Token, Sherwood Applied Business Security Architecture, Security Assertion Markup Language (SAML), Software Engineering, Data Streaming, Systems Integration, Tokenization, Azure Service Bus, Software Security, Apigee, Togaf, Event Driven Architecture, Kubernetes, Information Technology, Enterprise Integration, Integration Frameworks, Apache Kafka, Cloud Integration, Api Gateway, Serverless Computing, Mulesoft, Microservices - **Published:** July 12, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=ab654ffd6f18ed63 ## About the Role * Deep expertise in API security, application integration, messaging security, and service-to-service communications. * Strong understanding of modern integration architectures including APIs, microservices, event-driven architectures, cloud integrations, and SaaS connectivity. * Experience with authentication and authorization frameworks including OAuth 2.0, OpenID Connect, SAML, JWT, mTLS, and machine-to-machine authentication. * Strong analytical, problem-solving, and risk assessment skills with the ability to develop practical, scalable security solutions. * Strong communication and stakeholder management skills with the ability to collaborate across architecture, engineering, cloud, and business teams., * Degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related discipline. * 14 years or more of experience in security architecture, application security, integration architecture, middleware technologies, or related technology disciplines with at least 8 years of hands-on cybersecurity experience preferred. * Demonstrated experience designing and securing enterprise integration platforms, APIs, messaging environments, and cloud-native services. * Deep expertise in API security, OAuth, OpenID Connect, SAML, JWT, mTLS, PKI, secrets management, and machine identity security. * Experience with enterprise messaging and integration technologies such as IBM MQ, Kafka, Solace, Event Hubs, RabbitMQ, MuleSoft, Apigee, Kong, Azure Integration Services, or equivalent platforms. * Strong understanding of cloud-native architectures, microservices, containers, Kubernetes, serverless technologies, and modern application architectures. * Experience conducting security architecture reviews, threat modeling, and risk assessments for integration and data exchange solutions. * Knowledge of Zero Trust principles, data protection requirements, encryption technologies, and secure communication architectures. * Professional certifications such as CISSP, CCSP, GIAC, TOGAF, SABSA, AWS Security Specialty, Azure Security Engineer, or equivalent certifications are highly desirable. * Experience within financial services or other highly regulated industries is preferred., * Experience supporting enterprise API programs, cloud transformation initiatives, and third-party connectivity solutions. * Ability to work effectively with application, cloud, infrastructure, engineering, and cybersecurity teams in a global environment. * Limited travel may be required based on business needs. ## Description We are looking for an Enterprise Integration Security Architect. You will be responsible for designing and governing security architectures for enterprise integrations, APIs, messaging platforms, event-driven architectures, managed file transfer services, and third-party connectivity solutions. You will partner with application development, cloud engineering, infrastructure, data, and cybersecurity teams to ensure secure, resilient, and scalable integration patterns are implemented across the enterprise. Why This Role Is Important To Us The team you will be joining is part of the Security Architecture organization, a function that is critical to protecting the firm's applications, data, cloud platforms, and technology services. As organizations increasingly rely on APIs, cloud services, third-party platforms, and event-driven architectures, this role is responsible for ensuring integration security controls are built into enterprise technology solutions, reducing cyber risk while enabling business innovation and digital transformation. What You Will Be Responsible For As an Enterprise Integration Security Architect, you will: * Design and maintain security architectures, standards, and reference patterns for APIs, messaging platforms, event streaming services, file transfers, and third-party integrations. * Conduct security architecture reviews for enterprise integration solutions across cloud, SaaS, hybrid, and on-premises environments. * Define security requirements for API gateways, service-to-service communications, machine identities, partner connectivity, and integration platforms. * Provide subject matter expertise on authentication, authorization, encryption, tokenization, secrets management, and secure integration design patterns. * Partner with engineering and architecture teams to embed security controls into enterprise integration platforms and services. * Assess integration security risks and recommend mitigation strategies aligned with enterprise security standards and regulatory requirements. * Evaluate emerging integration technologies and industry trends to support future-state architecture and secure technology adoption. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Why make use of an integration platform in today's software developments and infrastructure?](https://www.wearedevelopers.com/videos/758-why-make-use-of-an-integration-platform-in-today-s-software-developments-and-infrastructure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Lessons learned from observing a billion API requests](https://www.wearedevelopers.com/videos/1574-lessons-learned-from-observing-a-billion-api-requests) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders)