Security Architect

The LaSalle Network Inc.
Rosemont, Illinois
$70-$80 an hour
Temporary

LaSalle Network is partnering with a client to seek an Enterprise Security Architect, who will play an integral role in defining and assessing the organization’s security strategy, architecture and practices.

The Enterprise Security Architect will be required to effectively translate business objectives and risk management strategies into specific security processes enabled by security technologies and services.

Security Architect Responsibilities :

  • Develop and maintain a security architecture process that enables the enterprise to develop and implement security solutions and capabilities that are clearly aligned with business, technology and threat drivers
  • Develop security strategy plans and roadmaps based on sound enterprise architecture practices
  • Develop and maintain security architecture artifacts (e.g., models, templates, standards and procedures) that can be used to leverage security capabilities in projects and operations
  • Track developments and changes in the digital business and threat environments to ensure that they’re adequately addressed in security strategy plans and architecture artifacts
  • Participate in application and infrastructure projects to provide security-planning advice
  • Determine baseline security configuration standards for operating systems (e.g., OS hardening), network segmentation, identity and access management (IAM) and endpoint protection
  • Conduct or facilitate threat modeling of services and applications that tie to the risk and data associated with the service or application
  • Coordinate with the privacy officer or office to document data flows of sensitive information in the organization (e.g.

PII or ePHI) and recommend controls to ensure that this data is adequately secured (e.g., encryption and tokenization)

  • Validate IT infrastructure and other reference architectures for security best practices and recommend changes to enhance security and reduce risks, where applicable
  • Liaise with the vendor management (VM) team to conduct security assessments of existing and prospective vendors, especially those with which the organization shares intellectual property (IP), as well as regulated or other protected data : Software as a service (SaaS) providers Platform as a service (PaaS) providers Cloud / infrastructure as a service (IaaS) providers Managed service providers (MSPs)
  • Evaluate the statements of work (SOWs) for these providers to ensure that adequate security protections are in place
  • Assess the providers’ SSAE 16 SOC 1 and SOC 2 audit reports (or alternative sources) for security-related deficiencies and required user controls and report any findings to the CISO and vendor management teams
  • Review security technologies, tools and services, and make recommendations to the broader security team for their use, based on security, financial and operational metrics
  • Coordinate with operational and facility management teams to assess the security of operational technology (OT) and Internet of Things (IoT) systems
  • Liaise with the business continuity management (BCM) team to validate security practices for BCM testing and operations when a failover occurs
  • Other projects or duties as assigned

Security Architect Requirements :

  • Bachelor’s degree in computer science, information systems, cybersecurity or a related field; master’s degree preferred
  • 8+ years direct, hands-on experience or strong working knowledge of : Managing security infrastructure (e.g., firewalls, intrusion prevention systems (IPSs), web application firewalls (WAFs), endpoint protection, SIEM and log management technology) Reviewing application code for security vulnerabilities Vulnerability management tools Methodologies to conduct threat-modeling exercises on new applications and services.
  • Full-stack knowledge of IT infrastructure : Applications Databases Operating systems Windows, Unix and Linux Hypervisors IP networks WAN and LAN Storage networks Fibre Channel, iSCSI and NAS Backup networks and media
  • Direct experience designing IAM technologies and services : Active Directory Lightweight Directory Access Protocol (LDAP) Azure Active Directory
  • Strong working knowledge of IT service management (e.g., ITIL-related disciplines) : Change management Configuration management Asset management Incident management Problem management
  • Experience designing the deployment of applications and infrastructure into public cloud services
  • Strategic planning skills; must interpret business, technology and threat drivers and develop practical security roadmaps to deal with these drivers
  • Communication skills; translate complex security-related matters into business terms that are readily understood by colleagues
  • Experience presenting analyses in person and in written formats.
  • Ability to quantify purchasing and licensing options, estimate labor costs for a given service or technology, and estimate the total cost of operation (TCO), the ROI or the payback period for services or technologies replacing existing capabilities
  • Solid project management skills
  • Experience drafting project plans for security service and technology deployments and coordinate with stakeholders across the organization
  • 30+ days ago
Related jobs
Promoted
VirtualVocations
Chicago, Illinois
Remote

A company is looking for a Principal Security Architect for a remote position in the USA or Canada. ...

Quantum Search Partners
Chicago, Illinois
Remote

The Cybersecurity Architect will develop and maintain security frameworks and architectures, technical standards and guidelines across the security domains of identity, network infrastructure and endpoints. Solid understanding of architecture-based security issues and network infrastructure security...

Promoted
VirtualVocations
Chicago, Illinois

A company is looking for a Senior Architect, Information Security. ...

CCC Information Services
Chicago, Illinois
Remote

CCC is looking for a IAM Security Architect on the Security team. As an influential member of the team, the IAM Security Architect is a primary liaison with the security, engineering and technology teams. Additionally, the IAM Security Architect establishes and executes against an IAM vision with sc...

Protiviti
Chicago, Illinois

Performing internal control reviews and user security risk assessments for customers running Microsoft Dynamics D365 for Finance, Microsoft Dynamics D365 for Supply Chain and/or Microsoft Dynamics AX2012. Microsoft Certified: Dynamics 365: Finance and Operations Apps Solution Architect Expert . ...

1872 Consulting
Chicago, Illinois

The IT Security Architect sits on our Security Operations team, to support global IT Security. Partners with stakeholders within IT and various departments on projects and initiatives to apply security requirements for projects, develop security architecture, develop detailed designs, and providing ...

JPMorgan Chase & Co.
Chicago, Illinois

Participates in evaluation sessions with external vendors and internal teams to drive outcomes-oriented probing of cybersecurity designs, technical approaches for integration with existing systems and cybersecurity architecture. Formal training or certification on architectural security patterns and...

Morningstar, Inc.
Chicago, Illinois

The Senior Application Security Architect will be part of the central information security team and act as a subject matter expert to all of Morningstar's product teams by providing security guidance and creating application security standards and patterns. The successful candidate will contribute t...

Bank of America
Chicago, Illinois

The Security Architect role is responsible for guiding on the design, development, and implementation of architectural principles to secure systems end to end. In this role, you will be required to understand foundational security requirements within existing Bank of America policies, architectural ...

Stardom Employment Consultants
Cicero, Illinois

As an Infrastructure SecurityArchitect you will be at the forefront of designing and enforcingsecurity architectures that protect our IT infrastructure. Oversee security events and incidentsproviding recommendations for response and recovery while ensuringcontinuous improvement in our securitypostur...