> Markdown version of [/jobs/ext/2067928-security-architect-md](https://www.wearedevelopers.com/jobs/ext/2067928-security-architect-md). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Architect- MD - **Company:** State Street - **Location:** Quincy, MA, United States - **Experience:** Expert - **Salary:** $120,000.0 - $202,500.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software as a Service, Cloud Computing, Cloud Computing Security, Cyber Security, Data Discovery, Data Security, Software Design Patterns, Identity and Access Management, Information Systems Security Architecture Professional, Key Management, Policy as Code, Model Validation, AI Platforms, Information Technology, Enterprise Integration, Devsecops - **Published:** August 15, 2026 - **Apply:** https://www.careerjet.com/job/uscd715ec22dd29b53ec1f22d1dafc9f51/eaa ## About the Role 15+ years of experience in security architecture, security engineering, or related disciplines. Demonstrated leadership across multiple security domains - ideally spanning AI security, data protection, and cryptography. Deep, hands-on expertise in cryptographic architecture and modernization, with direct experience in PQC transition and cryptographic agility (CBOM). Proven experience designing and scaling secure cloud-native architectures in large, regulated environments. Hands-on experience securing AI/ML and GenAI systems, including governance, data protection, and model risk. Strong background in regulatory audits, control remediation, and executive-level risk communication. Experience leading global, multidisciplinary architecture or engineering teams. Education & Preferred Qualifications Bachelor's degree in Computer Science, Information Security, Engineering, or a related field. Advanced degree preferred. Relevant certifications (CISSP, CISM, CCSP, cloud security, or architecture certifications) strongly Skills & Characteristics Rare breadth of technical credibility across AI, data, and cryptographic security domains. Strong bias toward automation, scale, and measurable outcomes. Ability to unify siloed disciplines into a coherent architectural vision. Executive presence with the ability to translate complex, cross-domain risk into business-aligned decisions. Change agent mindset with a track record of modernizing security functions. Customer-first perspective focused on trust, resilience, and long-term value. ## Description The Managing Director, Security Architect is a senior leadership role responsible for defining and leading the firm's horizontal security architecture across AI Security, Data Protection, Cryptography, and Post-Quantum Cryptography (PQC). Reporting to the SVP, Data & AI Security, this leader ensures that architecture standards, controls, and secure-by-design patterns are coherent, consistent, and mutually reinforcing across all four disciplines. Why this role is important to us This role exists to connect and elevate what would otherwise be siloed domains. The Managing Director will set a unifying architectural vision, establish shared standards and reference designs, and drive the enterprise toward a defensible, forward-looking security posture that spans data, models, keys, and cryptographic systems. The leader balances long-range strategy - including the firm's PQC transition - with the practical delivery of controls embedded into engineering workflows. The successful candidate is a recognized architecture leader with deep, credible expertise across multiple security domains, the executive presence to influence senior technology and business leaders, and a proven ability to translate complex technical risk into actionable decisions. They will lead a team of domain architects and act as a force multiplier across the broader security and engineering organization. What you will be responsible for Horizontal Security Architecture & Strategy Define and steward a unified, enterprise-wide security architecture spanning AI Security, Data Protection, Cryptography, and PQC. Establish shared architecture standards, guardrails, and reference designs that remain consistent across domains while addressing domain-specific risk. Ensure architectural decisions in one discipline reinforce the others (e.g., data protection controls that account for cryptographic agility and AI data exposure). Set the multi-year architectural roadmap and align it with business priorities, regulatory expectations, and the firm's technology transformation. Cryptography & Post-Quantum Readiness Lead the enterprise cryptographic architecture, including encryption, key management, secrets management, and machine identity. Own the firm's Post-Quantum Cryptography (PQC) strategy and transition roadmap, driving cryptographic agility and inventory (CBOM) across the environment. Establish standards for algorithm selection, key lifecycle, and crypto-agile design that support long-lived data protection. Partner with Infrastructure and Platform teams to modernize cryptographic hygiene and reduce operational risk. AI Security Architecture Set enterprise AI security architecture direction, including secure-by-default patterns for AI platforms, GenAI tooling, and AI agents. Ensure AI threat modeling and controls (prompt injection, model inversion, data poisoning, adversarial AI) are integrated with data protection and cryptographic standards. Guide the AI Security Architecture and Engineering teams to deliver coherent, defensible AI controls at scale. Data Protection Architecture Define architecture patterns for data discovery, classification, DLP, access governance, and automated protection controls. Ensure data protection controls operate consistently across on-premises, cloud, SaaS, and AI environments. Align data-centric controls with cryptographic and AI security standards to protect sensitive data throughout its lifecycle. Secure Delivery & Enablement Integrate security architecture into DevSecOps pipelines through paved-road platforms, automation, and policy-as-code. Enable secure adoption of AI, data, and cryptographic capabilities with minimal friction for engineering and business partners. Establish reusable, secure-by-default patterns that scale across product teams. Regulatory, Audit & Operational Excellence Ensure architecture standards align with regulatory expectations (FFIEC, NIST, ISO, NYDFS, GDPR, SEC). Serve as a credible technical voice in regulatory, audit, and client engagements across all four domains. Drive data-driven architecture decisions using metrics on coverage, risk concentration, and control effectiveness. Executive Engagement & Team Leadership Serve as a trusted technical advisor to the SVP, Data & AI Security, and to CISO, CIO, and architecture leadership. Deliver concise executive briefings on cross-domain security posture, emerging risks, and architectural tradeoffs. Build and lead a high-performing team of domain architects across AI, Data, and Cryptography. Act as a multiplier for security engineering and platform teams through coaching and architectural leadership., Who We Are Looking For We are looking for an Enterprise Integration Security Architect. You will be responsible for designing and governing security architectures for enterprise … + 1 month ago, Who We Are Looking For We are looking for a Cloud Security Architect. You will be responsible for defining, implementing, and governing cloud security architectures, standards, a… + 1 month ago, Who We Are Looking For We are looking for a Senior Data Security Architect. You will be responsible for designing, reviewing, and governing security architectures that protect th… + 1 month ago + ## Related Videos - [Architecting the Future: Leveraging AI, Cloud, and Data for Business Success](https://www.wearedevelopers.com/videos/1096-architecting-the-future-leveraging-ai-cloud-and-data-for-business-success) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [This App Reached 10,000 Users in One Week. Here's How.](https://www.wearedevelopers.com/videos/100329-this-app-reached-10-000-users-in-one-week-here-s-how) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [The New AI Security Stack: Observe, Detect, Protect](https://www.wearedevelopers.com/videos/100302-the-new-ai-security-stack-observe-detect-protect) - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) ## Related Articles - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)