Lead Information Security Architect

HarveyNash USA
United States
25 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$83,200.0 - $91,520.0
Working hours
Regular working hours
Job source

Tech stack

Authentication Protocols Cyber Security Information Systems DevOps Document-Oriented Databases Identity and Access Management Intrusion Detection and Prevention Information Systems Security Architecture Professional Network Segmentation Systems Integration Firewalls (Computer Science) Information Technology

Job description

As the Subject Matter Expert (SME) for all security operations, you will guide internal Agency developers and vendor partners on security strategy and requirements. Your role will be instrumental in analyzing the current state of the division’s security program, designing future states, and creating implementation roadmaps to enhance security posture. Additionally, you will play a crucial role in designing, implementing, and maintaining robust security solutions to protect our organization’s sensitive information and assets. Collaboration with various teams to assess security risks, develop strategies, and implement controls to mitigate threats effectively will be essential. This role requires a deep understanding of security principles, technologies, and industry best practices. Other responsibilities include, · Analyze the current state of the Division’s security program and design future states, creating a roadmap for implementation.

· Develop a business case and key performance indicators (KPIs) and socialize the security program within the Division.

· Security Policy Management:

· Assess, manage, and improve security policies and procedures to align with industry best practices and organizational objectives.

· Advise on security decisions and direction based on the Division’s vision and mission.

· Collaboration and Strategy Development:

· Collaborate with other Division Architects and the Security Operations Manager to develop global security strategies based on industry best practices.

· Advise on security decisions and direction based on a deep understanding of the Division’s vision and mission.

Security Architecture Development:

· Develop and maintain a security architecture process aligned with business and technology drivers.

· Create security strategy plans and roadmaps based on enterprise architecture practices.

Security Standards and Procedures:

· Draft security procedures and standards for executive management approval or authorization by the Cabinet CISO.

· Determine baseline security configuration standards for operating systems, network segmentation, and identity and access management.

Risk Assessment and Response:

· Perform risk assessments, advise on risk response strategies, and identify security issues from system integration.

· Conduct or facilitate threat modeling of services and applications to mitigate associated risks.

Collaboration and Coordination:

· Coordinate with DevOps teams to advocate secure coding practices and escalate concerns about poor coding practices.

· Liaise with privacy and compliance officers to document data flows of sensitive information and recommend appropriate controls.

Security Operations Support:

· Support internal security controls testing and validation as directed by the CISO or internal audit team.

· Review security technologies, tools, and services and recommend their use based on security metrics.

Security Infrastructure Implementation:

· Evaluate, select, and implement security technologies, tools, and solutions to enhance the organization’s security posture.

· Configure and deploy security infrastructure components such as firewalls, intrusion detection/prevention systems, endpoint protection, encryption, and authentication mechanisms.

Incident Response and Forensics:

· Develop incident response plans and procedures to mitigate security incidents effectively.

· Conduct post-incident analysis and forensic investigations to identify root causes and prevent future occurrences.

Security Awareness and Training:

· Develop and deliver security awareness training programs to educate employees on security risks and best practices.

· Provide ongoing support and guidance to staff regarding security-related inquiries and concerns

Requirements

Bachelor’s degree in computer science, Information Security, or related field; advanced degree preferred. Proven experience (5+ years) in information security architecture, design, and implementation.

Candidates with one or more of the following certifications are a plus:

Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information System Auditor (CISA), or other relevant certifications preferred.

Benefits & conditions

$40 - $44 an hour - Contract

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · WWC Europe 2026

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · WWC Europe 2026

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

Videos

See all

Related articles

See all