> Markdown version of [/jobs/ext/570964-lead-information-security-architect-governance](https://www.wearedevelopers.com/jobs/ext/570964-lead-information-security-architect-governance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Information Security Architect - Governance,... - **Company:** Lumen Inc - **Location:** Salt Lake City, UT, United States (Remote available) - **Experience:** Expert - **Salary:** $105,786.0 - $141,047.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Cloud Platform System - **Published:** June 12, 2026 - **Apply:** https://www.juju.com/job/00000000g7f61d ## About the Role This candidate must be able to work independently and as a team leader to consult with internal clients on security topics, providing designs, reviews, and recommendations., + 7+ years of relevant experience, including threat modeling, security design reviews, and security architecture + Ability to architect solutions that balance security, compliance, usability, and business requirements. + Strong knowledge of regulatory frameworks, standards, and risk management methodologies + Experience performing risk assessments and implementing risk mitigation strategies + Excellent verbal and written communication skills + Strong organizational skills + Excellent interpersonal skills and a collaborative working style. + High ethical standards, integrity, and commitment to confidentiality. + Demonstrated leadership abilities in cross-functional teams + Analytical mindset and strong problem-solving skills + Demonstrate knowledge of security technologies, trends, leading practices, and regulatory requirements and government security standards such as FedRAMP and Controlled Unclassified Information (CUI) standards, along with best practices such as NIST + Cybersecurity Framework (CSF), NIST 800-171, NIST 800-53, ISO 27001-27002 and other applicable security and privacy laws. + Strong teamwork and communication skills to collaborate with development, operations, and security teams. Ability to instill a security-first mindset throughout the organization. + Commitment to stay up to date with emerging industry updates, trends, security vulnerabilities, and new tools that can enhance security. Willingness to experiment with and adopt innovative solutions to improve security posture. + Stay abreast of emerging threats, technologies, and regulatory changes impacting information security and GRC. ## Description The Lead Information Security Architect with a focus on Governance, Risk and Compliance within the Global Security Services organization is responsible for conducting security risk assessments in coordination with the Lumen business owners, the Governance, Risk, and Compliance team, and the Product and Platform Security team. The purpose is to ensure compliance with corporate policy, standards, procedures, and industry best practices. The deliverables include metrics, reports, and mitigations associated with potential findings, issues, and risks that could impact Lumen or its customers., + Lead comprehensive risk assessments of information systems, infrastructure, and business processes. Identify, quantify, and prioritize security risks utilizing industry-standard methodologies such as ISO/IEC 27005 and NIST. + Advise on remediation strategies for identified risks and monitor ongoing mitigation activities. + Consult as a GRC security subject matter expert with architects, engineers, third parties and others on potential solutions. + Provide architectural guidance for incident detection, response, and post-incident reviews to strengthen control frameworks and prevent recurrences. + Lead initiatives to embed Governance, Risk, and Compliance principles into security architecture. Align architectural frameworks with relevant standards (e.g., ISO 27001, NIST, GDPR, HIPAA, SOX). + Recommend security policies, standards, and procedures that support GRC objectives and reflect current threat landscapes. + Consult with internal clients on GRC security topics and policy interpretation. + Collaborate across IT, legal, compliance, risk management, audit, and business units to ensure unified approaches to risk management and compliance.Mentor junior security staff, fostering a culture of security awareness and compliance. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Cloud Vendor Lock-In - Is it just a new version of the Database Abstraction Layers?](https://www.wearedevelopers.com/videos/1185-cloud-vendor-lock-in-is-it-just-a-new-version-of-the-database-abstraction-layers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Beyond the Hype: Building Trustworthy and Reliable LLM Applications with Guardrails](https://www.wearedevelopers.com/videos/1594-beyond-the-hype-building-trustworthy-and-reliable-llm-applications-with-guardrails) - [Giving AI eyes: How to build a dashboard you can't see](https://www.wearedevelopers.com/videos/100193-giving-ai-eyes-how-to-build-a-dashboard-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)