Security Architect
Newton, MA - USA
Job Summary
This role is based in our Newton MA office.
We are seeking a strategic Security Architect to define and drive our cloud and enterprise security architecture. You will own the security architecture vision establish governance frameworks and partner with Product Engineering and Infrastructure teams to embed security throughout our technology ecosystem.
Core Responsibilities
- Strategic Architecture & Governance
- Own and evolve the enterprise security architecture including long-term roadmap and reference architectures for cloud hybrid and on-premises environments
- Define organizational security principles frameworks and standards that align with business objectives and regulatory requirements
- Develop and present security strategy roadmaps and strategic initiatives to executive leadership and stakeholders
- Establish security metrics and KPIs to measure architecture effectiveness and communicate security posture to senior leadership
- Ensure compliance with industry regulations and standards including ISO 27001 SOC 2 GDPR and SOX
- Lead security audits and assessments driving remediation plans and continuous improvement initiative
Cloud & Infrastructure Security
- Own cloud security architecture across AWS and GCP including Cloud Security Posture Management (CSPM) Cloud Infrastructure Entitlement Management (CIEM) and Wiz remediation strategies
- Design and implement Identity and Access Management (IAM) architecture based on least privilege principles and Zero Trust security models
- Architect secure network segmentation strategies and defense-in-depth controls across all infrastructure layers
- Own the architecture and strategic direction for key security platforms including SIEM vulnerability management endpoint security and threat detection systems
- Manage and optimize internal security platforms to ensure robust protection of organizational assets
- Design secure cloud infrastructures and hybrid environment protections that scale with business growth
- Conduct threat modeling and risk analyses to identify infrastructure vulnerabilities and recommend mitigation strategies
Application & Development Security
- Lead Secure Software Development Lifecycle (SDLC) and DevSecOps initiatives across the organization
- Integrate security controls into CI/CD pipelines championing shift-left security practices in collaboration with DevOps leadership
- Ensure software architecture and applications are designed to mitigate vulnerabilities and prevent exploits
- Provide technical guidance and mentorship to development and DevOps teams on secure coding practices and emerging threats
- Collaborate with cross-functional teams to embed security throughout the system development lifecycle
- Define security requirements and controls that support agile development while maintaining strong security posture
Innovation & Technical Leadership
- Lead security architecture for emerging technologies including AI/LLM initiatives ensuring responsible and secure implementation
- Serve as the technical authority on security architecture advising on security-related technologies and assessing risks associated with proposed changes
- Stay current with emerging security threats vulnerabilities and technologies to drive continuous innovation in security practices
- Inspire and influence engineering teams to execute security principles and adopt security-first mindsets
- Mentor and provide technical guidance to DevOps operations and development teams on security best practices
- Partner strategically with Product Engineering and Infrastructure leaders to align security architecture with business innovation
- Drive thought leadership through security documentation architecture diagrams design specifications and security control matrices
Additional Responsibilities
- Lead incident response management and develop security policies that protect organizational assets from cyber threats
- Identify organizational vulnerabilities and weaknesses through systematic security assessments
- Recommend and implement security controls and solutions that balance security requirements with business enablement
Qualifications :
- Bachelors or masters degree in computer science information technology or a related field
- 7 years of cybersecurity experience with deep cloud security expertise
- Proven track record leading enterprise security architecture in multi-cloud environments
- Deep understanding of cloud service provider security best practices around (AWS GCP)
- Organization Policies
- Automated threat detection tools
- Central logging/Siem practices
- Lest privilege architecture
- VPC design/perimeter controls
- Data Exfiltration prevention
- Encryption/Key Management design
- Identity and Access Management (IAM) best practices.
- Web application security testing: Expertise in identifying and mitigating vulnerabilities in web applications leveraging tools and methodologies like OWASP.
- Network vulnerability scanning: Skilled in detecting and addressing vulnerabilities in network configurations and infrastructure.
- Container and Kubernetes security: Proficiency in securing containerized environments including Docker and Kubernetes using best practices and tools like Trivy or Aqua Security.
- Experience with security testing tools and platforms: Familiarity with industry-standard tools for vulnerability scanning penetration testing and security auditing.
- Ability to lead security discussions with system architects and business leaders.
- Strong analytical and computer skills
Expert level understanding of cybersecurity and how it affects the modern business world.
- Thorough understanding of Unix operation systems
- Awareness of frameworks such as NIST COBIT ISO and Soc2
- Certifications: CISSP CCSP AWS Security Specialty or Google Professional Cloud Security Engineer
Additional Information :
TechTarget Inc. doing business as Informa TechTarget including its subsidiaries is an equal opportunity employer and complies with all applicable federal state and local fair employment practices laws. We strictly prohibit and do not tolerate discrimination against employees applicants or any other covered persons because of race color sex (including pregnancy) age national origin or ancestry ethnicity religion creed sexual orientation gender identity or expression status as a veteran and basis of disability or any other federal state or local protected class. This policy applies to all terms and conditions of employment including but not limited to hiring training promotion discipline compensation benefits and termination of employment. If you would like to request reasonable adjustments or accommodations to assist your participation in the hiring process and or in the advertised position please inform the appropriate Talent Acquisition Partner for the role once they have been in touch. Your request will be reviewed and considered in confidence.
Informa TechTarget complies with the Americans with Disabilities Act (ADA) as amended by the ADA Amendments Act and all applicable federal state or local law.
We believe that great things happen when people connect face-to-face. Thats why we work in-person with each other or with customers and partners three days a week or more. When youre not spending time together in one of our offices or other workplaces like at an Informa event you get the flexibility and support to work from home or remotely.
Our benefits include:
- Great community: a welcoming culture with in-person and online social events our fantastic Walk the World charity day and active colleague groups and networks promoting a positive supportive and collaborative work environment
- Broader impact: take up to four days per year to volunteer with a philanthropic organization
- Career opportunity: the opportunity to develop your career with bespoke training and learning mentoring platforms and on-demand access to thousands of courses on LinkedIn Learning. When its time for the next step we encourage and support internal job moves
- Time out: Open Vacation plus 10 national holidays and the chance to work from (almost!) anywhere for up to four weeks a year
- Competitive benefits including a 401k match health vision and dental insurance parental leave and an ESPP offering company shares at a minimum 15% discount
- Strong wellbeing support through EAP assistance mental health first aiders free access to a wellness app and more
- Recognition for great work with global awards and kudos programs
- As an international company the chance to collaborate with teams around the world
The salary range for this role is $175K-$200K/YR based on experience.
This posting will automatically expire on September 4 2026.
Remote Work :
No
Employment Type :
Full-time
About Company
Informa is a leading international events, digital services and academic research group. We're here to champion the specialist. Through hundreds of brands and a range of products and services, we connect businesses and professionals with the knowledge they need to learn more, know m ... View more