> Markdown version of [/jobs/ext/2834656-senior-associate-security-strategist](https://www.wearedevelopers.com/jobs/ext/2834656-senior-associate-security-strategist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Associate, Security Strategist - **Company:** Publicis Groupe - **Location:** Boston, MA, United States - **Experience:** Expert - **Salary:** $90,000.0 - $120,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Data Analysis, Microsoft Azure, Cloud Computing Security, Cyber Security, Data Security, Decision Support Systems, Identity and Access Management, Image Quality, Systems Development Life Cycle, Cloud Services, Zero Trust Network Access, Google Cloud, Mitre Att&ck, Security Orchestration, Automation & Response - **Published:** September 10, 2026 - **Apply:** https://www.careerjet.com/job/usd2519ba783acdb2ff89273a33415b5d7/eaa ## About the Role * 5 to 8 years of experience in security strategy, enterprise security architecture, risk management, or related security roles. * Strong understanding of cloud security across Azure, AWS, and GCP at the capability and control-design level, including common failure modes. * Experience with capability assessment, target-state architecture, threat modeling, and risk analysis. * Working knowledge of ISO 27001, NIST CSF, and MITRE ATT&CK. * Strong written and verbal communication, with the ability to present concise recommendations to leadership and partner teams., * Experience in defining security capability roadmaps or operating models across multiple teams. * Experience with security automation, analytics, or AI-supported security workflows. * Background in incident response, forensics, threat intelligence, or compliance coordination. * Familiarity with zero trust principles, identity and access management, secure SDLC, and privacy-aligned control design. * Experience working across global teams with multiple stakeholders and competing priorities. Working Relationships * Reports to: Director of Security Strategy and Innovation. * Partners with: Solution and Operational Architecture, Security Operations, Incident Response, Compliance, Privacy, Legal, Engineering, IT, and Business teams. ## Description The Senior Security Strategist reports to the Director of Security Strategy and Innovation and helps drive enterprise security architecture governance, capability strategy, risk assessment, and security innovation. This role extends strategic capacity. It translates security priorities into target-state capability direction, gap and redundancy analysis, and roadmap recommendations that business and technical stakeholders can act on. It operates at the security ecosystem level, not at the level of individual application, solution, or cloud deployment review. Core Purpose This role shapes and helps execute security strategy in a global, fast-moving environment where security decisions must align with business goals, platform risk, and regulatory expectations. The position suits a practitioner who can move between strategic analysis and capability-level architecture governance: defining where the security ecosystem needs to go, where it overlaps or has gaps, and how the capability portfolio should evolve over time. Responsibilities Security Strategy * Support the Director of Security Strategy and Innovation in executing strategic security priorities across programs, platforms, and business initiatives. * Prepare briefing materials, maturity assessments, and decision support content for leadership audiences. * Track strategic initiatives, capability gaps, and roadmap commitments to support program execution and follow-through. Enterprise Security Architecture Governance * Operate at the security ecosystem or urbanism level: define target-state security capabilities and how they fit together across the enterprise. * Identify capability gaps, overlaps, and redundancies across the security portfolio, and recommend what to add, enhance, consolidate, or retire. * Shape and maintain the strategic roadmap for security capabilities, aligned to business needs, risk priorities, and technology trends. * Ensure the overall security architecture evolves coherently, rather than reviewing individual applications, solutions, or cloud deployments, which sit with the solution and operational architecture function. * Apply structured analysis using frameworks such as ISO 27001, NIST, and MITRE ATT&CK to support capability and roadmap decisions. Operating Model and Capability Strategy * Help define the operating model for strategic initiatives, including how capabilities move from strategy into ongoing operations. * Develop RACIs and end-to-end process definitions that span the teams involved in running each capability. * Translate target-state capability decisions into clear ownership, sequencing, and dependencies for the teams that execute them. Innovation Workstreams * Support the evaluation of new security technologies, AI-enabled tools, automation opportunities, and process improvements relevant to current risk priorities. * Contribute to pilot efforts that test security tooling, operating models, or analytical methods before broader rollout. * Assess whether proposed innovations reduce measurable risk, improve visibility, or strengthen program maturity at the capability level. Threat and Stakeholder Support * Monitor threat trends and adversary behaviors that may affect enterprise, cloud, identity, API, and data security capabilities. * Work with security operations, incident response, compliance, privacy, legal, and business teams to align capability strategy with operational lessons and regulatory obligations. * Communicate capability gaps, risks, and roadmap recommendations clearly to both technical and non-technical stakeholders., This job description in no way states or implies that these are the only duties to be performed by the employee(s) currently in this position. Employee(s) will be required to follow any other job related instructions and to perform any other job-related duties requested by any person authorized to give instructions or assignments. A review of this position has excluded the marginal functions of the position that are incidental to the performance of fundamental job duties. All duties and responsibilities are essential job functions and requirements and are subject to possible modification to reasonably accommodate individuals with disabilities. To perform this job successfully, the incumbent(s) will possess the skills, aptitudes, and abilities to perform each duty proficiently. Some requirements may exclude individuals who pose a direct threat or significant risk to the health or safety of themselves or others. The requirements listed in this document are the minimum levels of knowledge, skills, or abilities. This document does not create an employment contract, implied or otherwise, other than an ""at-will"" relations. Success Profile The strongest candidate writes clearly, analyzes capability and risk with discipline, and turns broad security goals into a coherent target-state roadmap. This person is comfortable handling ambiguity, working at the ecosystem level, and supporting security strategy with structured analysis, clear ownership, and steady execution., Position Summary The Senior MRI Technologist performs complex MRI procedures, ensures patient safety, mentors staff, and assists with operational duties while maintaining high-qua… + 1 month ago, Position Summary This role performs both routine and complex diagnostic radiology imaging procedures while ensuring patient safety, image quality, and compliance with departmental… + 1 month ago ## Related Videos - [Data Science in Retail](https://www.wearedevelopers.com/videos/586-data-science-in-retail) - [Lessons learned from observing a billion API requests](https://www.wearedevelopers.com/videos/1574-lessons-learned-from-observing-a-billion-api-requests) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cloud Run- the rise of serverless and containerization](https://www.wearedevelopers.com/videos/106-cloud-run-the-rise-of-serverless-and-containerization) - [Data Science on Software Data](https://www.wearedevelopers.com/videos/162-data-science-on-software-data) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j)