Infosec Architect-SR
Listed on 2026-01-17
-
IT/Tech
Cybersecurity, IT Consultant
Information Security Architect – SR (Remote)
Working hours:
8-5 EST
- Communication
- Cyber Controls Expertise
- Security Architecture and Design
- PCI Compliance
- Audit Background
- IT Engineering
- Degree Requirements (Experience in Lieu of Degree)
- CISSP, CRISC, AI Certifications
A security‑based certification
Years of Experience10+ years
Day in the LifeWorking with IT partners to understand current and new solutions, how security controls are embedded, and discussing needed improvements to the IT products. Working with team members on process improvements to ensure consistent delivery of security consulting.
Interaction LevelWeekly and potentially daily interactions with team members.
Top Priority for First Few Weeks/MonthsLearn our internal systems and standards. Begin shadowing existing team members to understand how processes are executing today. Transitioning to taking the lead on security consulting among IT teams.
Biggest ChallengeLearning the complex environment that is BFH and understanding who they will need to work with across the business in order to get the needed information.
Essential Job Functions- Security Architecture Development and Maintenance – Assists the Sr. and Principal Architects with the creation of security designs and frameworks for technology systems, monitors security intelligence sources for emerging industry security technologies, technology issues, regulatory issues and practices, provides oversight of new development efforts to ensure adherence to security policies, standards, and reference architectures, actively participates in decision‑making processes related to adoption of new hardware and software technologies, provides advisory services as needed to information security teams, utilizes planning and organization tools to develop project/action plans, meets deliverable deadlines as directed.
- Information Security Strategy – Assists the Principal and Sr. Information Security Architects with the development of the annual Information Security Strategy, including strategy development, formalized road‑map documentation, and continued maintenance.
- Cyber Security Tooling and Processes – Possesses intermediate knowledge of company Cyber Security tools and affiliated operational processes, utilizes knowledge when advising to determine residual risk of identified threats or control weaknesses, champions the use of Cyber Security tooling through education and awareness of constituents.
- Regulatory Requirements and Control Frameworks – Foundational knowledge of regulatory bodies and corresponding compliance requirements including, but not limited to: PCI‑DSS, SOX, GLBA, CCPA, GDPR, intermediate knowledge of control frameworks including, but not limited to: FFIEC Examination Handbooks, NIST 800‑53, ISO 27001, advanced knowledge of Cyber Security Maturity Frameworks such as NIST‑CSF and FFIEC Cyber Assessment Tool.
- General Information Technology – Intermediate knowledge of IT tools and practices including, but not limited to:
Networking, LDAP Directories, Vulnerability/Patch Management, Change Management, Incident Management, Server and Desktop Management, Mainframe Technologies, Encryption and Key Management, Cloud Architecture and Computing, Software Application General Computing Controls, Business Continuity/Disaster Recovery, Software Development Lifecycle, Access Management, and Cyber Security Tooling. - Human Relations – Ability to diffuse problematic situations and manage through conflict resolution, utilizes soft skills such as selective agreement, reflective listening, voice inflection, and empathy, can break down complex concepts into layman’s terms or analogies, viewed as an enabling partner that provides options or information when saying no to business or IT requests, seen by leadership and peers as credible, trustworthy and respectful, utilizes subject matter expertise to guide and coach less experienced team members.
- Reports to:
Manager or Director of Information Security - Working Conditions/
Physical Requirements:
Normal office environment. As the need of the…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).