> Markdown version of [/jobs/ext/1576366-outcome-driven-lead-security-architect](https://www.wearedevelopers.com/jobs/ext/1576366-outcome-driven-lead-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # outcome-driven Lead Security Architect - **Company:** Toyota Financial Services - **Location:** Plano, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Team Foundation Server, Zero Trust Network Access, Data Streaming, Data Processing, Delivery Pipeline - **Published:** July 21, 2026 - **Apply:** https://www.dice.com/job-detail/2b485173-c6f1-4e7e-8981-06655fba47b4 ## About the Role * Proven experience applying threat modeling methodologies, especially data-centric approaches (NIST SP 800-154) * Hands-on experience with threat modeling tools (e.g., IriusRisk/Threat Modeler, Microsoft Threat Modeling Tool, or equivalents) - strongly preferred * Strong understanding of data protection, data flow analysis, and sensitive data handling within financial services environments * Experience influencing complex, cross-functional architecture decisions at scale * Ability to translate technical threats into business risk and executive-lev Added bonus if you have * Certified Information Systems & Security Professional (CISSP), Certified Information Security Manager (CISM), or equivalents ## Description This role is accountable for embedding Data-Centric Threat Modeling (NIST SP 800-154) into the architecture lifecycle ensuring that security decisions are driven by how data is created, processed, stored, and exposed, rather than relying solely on perimeter or technology-centric controls. The ideal candidate will operate as a senior technical authority, influencing design decisions, enforcing architectural standards, and driving measurable improvements in control effectiveness across TFS environments., * Identify threats, attack paths, and control gaps based on data flows, sensitivity, and business impact * Integrate threat modeling into solution design, architecture reviews, and delivery pipelines * Drive consistency through standardized methodologies and tooling (e.g., Threat Modeler, IriusRisk) Define & Enforce Security Architecture * Establish and govern security architecture standards, patterns, and reference models aligned to TFS policy and risk tolerance * Lead architecture design reviews and provide binding security decisions for critical initiatives * Ensure solutions align to Zero Trust principles, least privilege access, and data protection requirements Drive Risk-Based Decision Making * Translate threat models and architectural assessments into actionable risk insights for executives and stakeholders * Support risk acceptance, exception handling, and architectural trade-offs with clear business impact articulation * Identify control gaps and redundancies across security tooling; recommend optimization and rationalization strategies Partner Across the Organization * Collaborate with engineering, infrastructure, data, and application teams to embed security early in the development lifecycle * Influence third-party and vendor design reviews using threat-informed architecture criteria, not just checklist-based assessments * Align with risk and compliance teams to ensure regulatory expectations (e.g., financial services controls) are integrated into design Evaluate Control Effectiveness * Move beyond artifact review (e.g., SOC 2, ISO 27001) to assess real-world control effectiveness against identified threats * Correlate assurance evidence with actual attack scenarios and data exposure risks * Drive continuous improvement in architecture based on evolving threats and control performance ## Related Videos - [Python-Based Data Streaming Pipelines Within Minutes](https://www.wearedevelopers.com/videos/1233-python-based-data-streaming-pipelines-within-minutes) - [Real-world Threat Modeling](https://www.wearedevelopers.com/videos/936-real-world-threat-modeling) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Implementing continuous delivery in a data processing pipeline](https://www.wearedevelopers.com/videos/73-implementing-continuous-delivery-in-a-data-processing-pipeline) - [Why and when should we consider Stream Processing frameworks in our solutions](https://www.wearedevelopers.com/videos/1085-why-and-when-should-we-consider-stream-processing-frameworks-in-our-solutions) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How software is steering vehicle technology](https://www.wearedevelopers.com/magazine/515-how-software-is-steering-vehicle-technology) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions)