Enterprise Security Architect Azure
Skokie, IL - USA
Job Summary
Job Title: Enterprise Security Architect
Location of role: Hybrid - onsite 2 3x/week flexible across Skokie Warrenville Arlington Heights Glenviewc
Salary 160K to 185K some flex right person Depending on experience DOE
Job Description Details:
What you will do:
- Develops complex enterprise security architecture strategies to drive value for the organization while adhering to quality growth and risk management directives for the enterprise. Provides insight into a security function or specialty through analysis and knowledge of leading practices to solve complex problems driving thought leadership and innovation.
- Develops proposals responds to business requirements and provides subject matter expertise. Serves as a communication and collaboration bridge between various departments and external partners leading to better project outcomes and a more cohesive and secure work environment.
- Aligns security architecture and security engineering with the organizations business objectives IT strategies and Cybersecurity goals.
- Reduces costs and improves resource allocation by optimizing the IT and IT Security infrastructure while eliminating redundancies. Identifies secures and integrates new technologies to drive business growth and enable the organization to respond quickly to emerging threats new technologies and market changes.
- Contributes to the development of IT and security roadmaps driving the future state of security and technology for the enterprise in alignment with IT Security Enterprise Architecture and technical and application engineering teams as well as various clinical and non-clinical stakeholders. Aligns cybersecurity posture with business strategies and objectives. Explains emergent security technology trends cyber threats and threat actor techniques and procedures in terms appropriate for operational partners and business leaders. Stays current with IT and cybersecurity platform technologies architectures leading practices and methodologies.
- Participates in On-Call rotation and performs other duties as assigned.
- Education: Must have a Bachelors Degree or equivalent in a technical engineering or investigative academic discipline or an equivalent work history and educational background supported by expert-level security certifications relevant to the role.
- Certifications: Two or more expert-level security platform or capability certifications - Industry preferred certifications including but not limited to; CISSP CRISC TOGAF CCSP SABSA Microsoft SC-100 AWS (Solutions Architecture or Security). CISSP (a mainstay but isnt disqualifying if other certs and credentials are strong)
- Depth across at least 3 security domains - Network Security Architecture Application Security Architecture Identity & Access Management (IAM) Data Security Monitoring & Logging (incl. getting logs out of non-integrating systems into existing monitoring platforms) Cloud Security (Azure primary GCP secondary)
- Nine (9) years in a dedicated advanced or expert-level IT security engineering role with demonstrated consistent performance leading security initiatives and developing use cases ideally out of an Azure cloud environment and ideally out of some healthcare environment or highly regulated environment like banking.
- Minimum of four (4) years in security architect roles and Minimum of two (2) years in security project delivery roles including experience with contracting architecture design and implementation.
- Experience going through business applications requirements gathering making sure the security requirements are specified mapped to how they are going to be delivered and then once delivered go back and post validate whether or not they met what requirement intended.
- Experience building formal security service catalogs starting with IAM to enable future application requirements to be self-served instead of managed through ad hoc meetings and tiered architecture experience.
- Previous experience developing and contributing to a comprehensive enterprise cybersecurity strategy.
- Demonstrated experience instructing mentoring or developing junior team members.
- Comfortable being fully hybrid - no remote-only candidates considered
- Able to self-manage projects/timelines without a dedicated PM
- Azure cloud depth (GCP secondary) - AWS-only experience does not translate well and is a soft negative
- Healthcare or other highly-regulated industry background (banking/finance candidates considered but risk-tolerance philosophy differs - patient safety has zero acceptable risk tolerance unlike financial risk)
- Experience with tiered Active Directory architecture / PAM / zero-trust network segmentation (not full zero-trust - 30% of network cant be due to patient safety)
- Strong knowledge and experience with tier architectures service catalogues requirements gathering mapping post validation.
- Unique or Preferred Skills:
- Expertise in security frameworks and regulations such as HIPAA ITIL NIST PCI SDLC and Project Management principles.
- Previous healthcare experience a huge plus. Will consider a highly regulated environment.
- Excellent verbal and written skills essential for providing positive customer service and good communication with various business leaders and front-line staff.
- Experience with aligning business objectives to IT and IT Security initiatives and delivering security architecture solutions to support an enterprise mission vision and strategy.
- Has a comprehensive understanding of all aspects of cybersecurity within a healthcare or critical infrastructure environment including advanced threat landscapes and regulatory compliance.
- Expert at securing IT platforms according to recognized security and risk management frameworks.
- Demonstrates analytical and critical thinking for problem solving and issue resolution.
- A lean towards curiosity out-of-the-box thinking and innovative.
- Ability to manage multiple projects simultaneously.
- Personal and ethical accountability.
- A team player attitude.
- A valid drivers license is required if the incumbent is selected to perform related duties at an off-site location. If the incumbent uses his or her personal vehicle the incumbent must maintain automobile liability coverage as required by law and evidence of such coverage may be requested.
Company relocation - At this time client will NOT relocate for this role
Company sponsorship - At this time client will NOT sponsor for this role
Travel: This role may require 0% travel
Duration of role: Direct hire Role - Fulltime
If applying for this role - Please take each key point and provide number of years experience and what you would rate yourself 1 thru 10 (10 being expert) for each key point. Send your resume and notes on the role to expediate our recruiting services.