> Markdown version of [/jobs/ext/2219616-enterprise-cybersecurity-architect](https://www.wearedevelopers.com/jobs/ext/2219616-enterprise-cybersecurity-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Enterprise Cybersecurity Architect - **Company:** HF Sinclair - **Location:** Dallas, TX, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Data Analysis, Software as a Service, Cloud Computing, Cloud Computing Security, Cloud Engineering, Cyber Security, Software Design Patterns, Electronic Data Interchange (EDI), Network Segmentation, Remote Access Technology, Cloud Services, Zero Trust Network Access, Cyber-physical Systems, Sherwood Applied Business Security Architecture, Systems Integration, Web Platforms, Togaf, Information Technology, Data Management, DODAF - **Published:** August 25, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/18059112?backUrl=%2Fcareer%2F18059112%2FIt-Security-Analyst-Texas-Dallas ## About the Role A minimum of 8 years of experience in IT infrastructure, cybersecurity, cloud security, security engineering, enterprise architecture, solution architecture, OT security, or related technology domains. * Minimum of 4 years of experience in an architecture function, including development of standards, reference architectures, design patterns, architecture governance, or technology roadmaps. * Demonstrated experience translating business, risk, regulatory, and technical requirements into practical security architecture guidance. * Demonstrated ability to operate as a senior technical advisor across multiple teams, domains, and levels of leadership. * Experience leading architecture reviews, producing architecture decision records, documenting design tradeoffs, and influencing risk-informed discussions across technical and business stakeholders. * Experience working across multiple technology domains including some combination of identity, network, cloud, endpoint, data, application, SaaS, infrastructure, integrations, OT, or cyber-physical systems. * Experience supporting cyber risk reduction, control alignment, maturity improvement, or security roadmap development. Education Level A bachelor's degree in Information Technology, Information Security, Cybersecurity, Computer Science, Engineering, or a related field is required. Equivalent experience may be considered in lieu of a degree. Preferred Educational Level: Master's degree in Information Technology, Cybersecurity, Information Security, Engineering, Business Administration, or a related field. Required Skills * Enterprise security architecture and secure-by-design principles. * Architecture frameworks and methods such as TOGAF, SABSA, DoDAF, NIST, C2M2, SAFe for Architects, or similar approaches. * Architecture governance methods, including standards management, design review facilitation, architecture decision records, and architecture review forums. * Systems thinking and ability to analyze complex cross-domain dependencies. * Cyber risk analysis, control alignment, maturity assessment, and risk-informed roadmap development. * Ability to translate strategy, risk, and control requirements into practical architecture standards and engineering-ready guardrails. * Security architecture concepts across IT, OT, cyber-physical systems, cloud, SaaS, application, API, data, identity, network, monitoring, automation, and resilience domains. * Strong communication, facilitation, stakeholder management, and executive-facing presentation skills. * Continuous improvement mindset with ability to establish reusable patterns, feedback loops, and measurable outcomes. Preferred Skills: * Oil and gas, critical infrastructure, industrial cybersecurity, or OT security architecture experience. * Experience with NIST CSF, C2M2, CIS, ISO 27001, NERC CIP, TSA security directives, or other cybersecurity and regulatory frameworks. * Experience aligning security architecture to enterprise cyber taxonomies, capability models, maturity models, control libraries, or unified controls frameworks. * Experience supporting cyber portfolio planning, investment prioritization, roadmap development, OKRs, KPIs, KRIs, or value/risk-based planning. * Experience with security architecture for AI, analytics, automation, machine identities, APIs, data platforms, cloud-native architectures, and SaaS ecosystems. * Familiarity with SSE/SASE, Zero Trust, cyber-physical systems, and digital transformation security patterns. * Relevant certifications such as CISSP, CCSP, SABSA, TOGAF, GIAC, ISA/IEC 62443, cloud security, or similar credentials. Supervisory/Managerial Responsibility This role has no direct supervisory responsibilities but is expected to provide senior technical leadership, architecture direction, mentoring, and cross-functional influence across cybersecurity, IT, and OT. Work Conditions ## Description medical insurance, dental insurance, vision insurance, 401(k), retirement plan United States, Texas, Dallas Aug 24, 2026 Basic Function The IT Security Architect d efines and governs enterprise cybersecurity architecture standards and secure design practices across IT and OT environments. Provides strategic architecture guidance, aligns security decisions with business objectives and cyber risk priorities, and supports secure adoption of emerging technologies while driving risk reduction and operational resilience., Enterprise Cybersecurity Architecture Strategy and Standards * Define, maintain, and improve cybersecurity architecture principles, standards, guardrails, patterns, and reference architectures. * Establish reusable architecture patterns that enable secure-by-design delivery, reduce inconsistent solution decisions, limit architectural drift, and address avoidable control gaps. * Use the enterprise cybersecurity taxonomy to organize architecture decisions, standards, roadmaps, risks, controls, metrics, and capability maturity discussions. Security Architecture Governance and Design Reviews * Lead or facilitate security architecture reviews for major technology initiatives, cyber portfolio projects, OT modernization, cloud solutions, application modernization, identity patterns, data platforms, integrations, automation, and AI-enabled capabilities. * Identify architecture risks, design gaps, control weaknesses, and standards deviations; document tradeoffs, recommendations, decisions, and residual risk implications. * Define architecture dependencies, design constraints, runway needs, standards readiness, and risk reduction outcomes for major IT and cyber initiatives. Cyber Risk, Control, and Capability Traceability * Support risk register accuracy by mapping technology and architecture risks to affected capabilities, root-cause design gaps, maturity gaps, and practical mitigation approaches. * Advise on architecture implications of policy exceptions, control gaps, risk acceptances, third-party dependencies, and emerging technology adoption decisions. Technology Domain Architecture Guidance * Guide security architecture for IT/OT convergence, industrial digital platforms, cyber-physical systems, network segmentation, secure remote access, monitoring, identity, data exchange, cloud, SaaS, application, API, automation, and AI-enabled solutions. * Evaluate emerging technologies and industry trends for applicability, risk, architecture impact, control requirements, and adoption guardrails. Stakeholder Partnership and Continuous Improvement * Influence strategic initiatives by explaining architecture options, risk tradeoffs, design implications, and recommended paths forward. * Facilitate alignment where ownership is shared or ambiguous by clarifying architecture boundaries, decision rights, and execution expectations. * Support continuous improvement of architecture governance, standards adoption, exception management, security design quality, and measurable security outcomes. Special assignments or tasks may be assigned to the employee by their supervisor, as determined from timeto time in the supervisor's sole and complete discretion. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Data Science in Retail](https://www.wearedevelopers.com/videos/586-data-science-in-retail) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Data Science on Software Data](https://www.wearedevelopers.com/videos/162-data-science-on-software-data) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [The Innovation Formula: Fast Prototyping, Data Analysis, and Real User Insights](https://www.wearedevelopers.com/videos/1421-the-innovation-formula-fast-prototyping-data-analysis-and-real-user-insights) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)