Enterprise Security Architect (IAM, Network Security, SOC, GRC & AI Security)
Seattle, WA (Hybrid)
Job Description:
Job Summary
We are seeking an experienced Enterprise Security Architect to design, implement, and oversee enterprise-wide cybersecurity strategies across Identity and Access Management (IAM), Network Security, Security Operations Center (SOC), Governance, Risk & Compliance (GRC), and AI Security. The ideal candidate will align security architecture with business objectives, regulatory requirements, and emerging technologies while driving security transformation initiatives across hybrid cloud and on-premises environments.
Key Responsibilities
Security Architecture
Develop and maintain enterprise security architecture aligned with business and IT strategies.
Create security standards, reference architectures, and technical roadmaps.
Review and approve security designs for enterprise applications, cloud platforms, and infrastructure.
Define Zero Trust architecture and security best practices.
Identity & Access Management (IAM)
Design and implement IAM strategies for enterprise environments.
Architect Single Sign-On (SSO), Multi-Factor Authentication (MFA), Privileged Access Management (PAM), and Identity Governance & Administration (IGA).
Implement Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC).
Support identity lifecycle management and access certification.
Network Security
Design secure enterprise network architectures.
Implement segmentation, micro-segmentation, VPN, SD-WAN, NAC, IDS/IPS, WAF, DDoS protection, DNS security, and secure remote access.
Develop cloud network security architecture across AWS, Azure, and GCP.
Evaluate and implement Zero Trust Network Access (ZTNA).
Security Operations Center (SOC)
Define enterprise detection and response strategies.
Design SIEM, SOAR, XDR, and Threat Intelligence integration.
Develop incident response frameworks and playbooks.
Improve threat detection using automation and behavioral analytics.
Collaborate with SOC teams on security monitoring and incident investigations.
Governance, Risk & Compliance (GRC)
Develop enterprise security policies, standards, and procedures.
Conduct enterprise risk assessments and security maturity assessments.
Ensure compliance with ISO 27001, NIST CSF, CIS Controls, PCI DSS, SOC 2, GDPR, HIPAA, and other applicable regulations.
Support internal and external audits.
Track risk mitigation initiatives and compliance metrics.
AI Security
Develop governance for secure AI adoption.
Assess AI/ML risks including prompt injection, model poisoning, data leakage, adversarial attacks, and model theft.
Secure GenAI applications and AI pipelines.
Establish AI risk management and responsible AI controls.
Evaluate AI security tools and frameworks.
Cloud Security
Design secure architectures for AWS, Azure, and Google Cloud.
Implement CSPM, CWPP, CNAPP, CASB, and Kubernetes security.
Secure containers, serverless, APIs, and cloud-native applications.
Ensure encryption and key management best practices.
Risk Management
Perform threat modeling and security architecture reviews.
Identify technology risks and recommend mitigation strategies.
Support Business Continuity (BCP) and Disaster Recovery (DR) planning.
Leadership & Collaboration
Provide technical leadership to security engineers and architects.
Partner with IT, DevOps, Cloud, Infrastructure, and Application teams.
Present security strategies and risk updates to executive leadership.
Mentor junior security professionals.
Required Qualifications
Bachelor's degree in Computer Science, Information Security, Cybersecurity, or related field.
10–15+ years of experience in enterprise cybersecurity.
5+ years of experience in security architecture.
Experience designing enterprise-scale security solutions.
Strong understanding of cloud security, IAM, network security, SOC operations, and GRC.
Technical Skills
Identity Security
Azure AD / Microsoft Entra ID
Okta
Ping Identity
SailPoint
CyberArk
BeyondTrust
SSO
MFA
PAM
IGA
Network Security
Palo Alto
Fortinet
Cisco
Check Point
Zscaler
F5
Netskope
Cisco ISE
VPN
SD-WAN
NAC
SOC Technologies
Microsoft Sentinel
Splunk
IBM QRadar
Google Chronicle
Microsoft Defender XDR
CrowdStrike Falcon
Cortex XSOAR
Cloud Security
AWS Security Services
Microsoft Azure Security
Google Cloud Security
Kubernetes Security
Docker Security
Terraform Security
GRC
ISO 27001
NIST CSF
CIS Controls
PCI DSS
SOC 2
GDPR
HIPAA
Risk Management
Security Audits
AI Security
OWASP Top 10 for LLM Applications
Secure AI Development
AI Governance
Prompt Injection Mitigation
AI Model Security
AI Risk Assessment
Security Engineering
PKI
Encryption
HSM
API Security
DevSecOps
Secure SDLC
Threat Modeling
Vulnerability Management
Preferred Certifications
CISSP
CCSP
CISM
SABSA
TOGAF
GIAC (GSEC, GCIH, GCIA, GPEN)
Azure Security Engineer (AZ-500)
AWS Certified Security – Specialty
Google Professional Cloud Security Engineer
CRISC
ISO 27001 Lead Implementer or Lead Auditor
Certified Identity and Access Manager (CIAM) or equivalent IAM certifications
Soft Skills
Strong analytical and problem-solving abilities
Excellent communication and stakeholder management
Executive presentation skills
Leadership and mentoring capabilities
Strategic thinking and business alignment
Cross-functional collaboration
Decision-making under pressure
Key Performance Indicators (KPIs)
Reduction in enterprise security risk
Security architecture review completion rate
Compliance and audit success rate
Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR)
IAM compliance and privileged access governance
Security incident reduction
AI governance and security maturity
Cloud security posture improvement
Vulnerability remediation SLA adherence
Security control effectiveness and coverage
This role is ideal for senior cybersecurity professionals who combine deep technical expertise with architectural leadership, enabling secure digital transformation across identity, networks, operations, governance, cloud, and AI systems.
Key Skills:
- Security Architecture