Cybersecurity Architect
Baltimore, MD - USA
Job Summary
Architecture & Solution Design
Develop enterprise-wide security architectures aligned to NIST standards (e.g. NIST CSF SP 800-53 SP 800-171 SP 800-207).
Design scalable secure solutions that address identified risks and business objectives across cloud on-premises and hybrid environments.
Translate business and technical requirements into secure solution blueprints.
Contribute to the development of reference architectures and security patterns.
Leverage hands on engineering implementation experience to provide prescriptive guidance on best practices and possible pitfalls.
Solution Review & Risk Mitigation
Lead architecture and security reviews for new technologies applications and systems.
Identify gaps and weaknesses in proposed solutions and advise on appropriate risk mitigation strategies.
Collaborate with engineering and infrastructure teams to ensure secure deployment of systems and services.
Provide technical guidance to project and product teams throughout the system development lifecycle.
Governance & Standards
Develop and maintain security architecture standards policies and control frameworks in alignment with NIST and industry best practices.
Participate in or lead internal security governance boards and architecture review boards.
Ensure solutions meet internal risk compliance and regulatory requirements (e.g. CCPA NYDFS PCI DSS).
Contribute to maturity assessments and continuous improvement efforts for cybersecurity architecture.
Collaboration & Leadership
Act as a subject matter expert on cybersecurity architecture for stakeholders across IT engineering compliance and risk teams.
Mentor junior architects and security engineers.
Communicate complex technical and risk concepts clearly to business leaders and non-technical audiences.
Stay up to date on emerging threats technologies and changes to the NIST ecosystem.
Required Qualifications
710 years of experience in cybersecurity with 3 years in a security architecture or similar role.
Deep working knowledge of NIST frameworks (CSF SPZero Trust).
Demonstrated experience designing and reviewing secure architectures for enterprise systems and cloud environments (e.g. AWS Azure).
Practical experience translating security architecture requirements into implemented controls technical configurations and operational procedures.
Strong understanding of cybersecurity domains including identity and access management (IAM) network security data protection and application security.
Strong understanding of LLMs AI and GenAI solutions including agentic AI and MCP hardening.
Experience validating control effectiveness through testing monitoring evidence collection or audit support.
Experience working in a regulated environment and aligning technical controls to compliance frameworks. Excellent communication collaboration and documentation skills.
Preferred
Industry certifications such as CISSP CISM CISA SABSA or AWS Certified Security.
Experience with Zero Trust Architecture and modern security models.
Experience with security automation control orchestration policy-as-code or continuous control monitoring.
Experience implementing security controls in cloud-native hybrid and complex enterprise-scale environments.
Familiarity with DevSecOps and infrastructure-as-code security.
OneMain Holdings Inc. is an Equal Employment Opportunity (EEO) employer. Qualified applicants will receive consideration for employment without regard to age ancestry citizenship status color creed culture disability ethnicity gender gender identity or expression genetic information or history marital status military status national origin nationality pregnancy race religion sex sexual orientation socioeconomic status transgender or on any other basis protected by law.
Required Experience:
Staff IC
About Company
Sometimes unexpected costs occur, so trust OneMain to provide personal loans for home improvement, debt consolidation, car purchases, & more.