External Perimeter Security Architect
Job in
Chicago, Cook County, Illinois, 60290, USA
Listed on 2026-08-07
Listing for:
Judge Group, Inc.
Full Time
position Listed on 2026-08-07
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
Role Overview
We are seeking an experienced Security Architecture Lead to drive a strategic security transformation initiative focused on redesigning and modernizing our external perimeter across cloud, hybrid, and on-premises environments. This role will be responsible for reducing real-world risk exposure, strengthening security architecture, and delivering structured, milestone-driven remediation strategies that enable informed business and technology decisions.
Key Responsibilities
Perimeter & Network Security Architecture
- Lead the assessment, redesign, and modernization of the organization's external perimeter security architecture.
- Conduct feasibility analyses and develop phased remediation roadmaps, with comprehensive documentation maintained in Confluence.
- Perform detailed connection-by-connection reviews of high-risk network paths, identifying secure alternatives and prioritizing remediation activities.
- Design and implement security controls across on-premises, cloud, and hybrid environments while maintaining operational efficiency and minimizing business disruption.
- Establish scalable network segmentation and Zero Trust architectures to reduce attack surface and contain potential threats.
- Design and implement AWS Service Control Policies (SCPs), Resource Policies, and VPC Endpoint strategies to enforce security boundaries and workload isolation.
- Strengthen IAM architecture through secure access models, governance controls, and preventive guardrails.
- Implement encryption and secure data flow controls for data in transit and at rest.
- Assess and remediate security risks across multiple AWS accounts, prioritizing efforts based on business impact and risk exposure.
- Leverage AI-assisted security and automation tools to improve architecture review, analysis, and remediation workflows.
- Evaluate, design, and enhance the security of CI/CD pipelines and Infrastructure-as-Code implementations.
- Identify pipeline risks and implement security controls that support secure software delivery practices.
- Conduct ongoing security architecture reviews to ensure design integrity throughout the technology change lifecycle.
- Map security findings to adversary tactics, techniques, and procedures (TTPs) to improve detection coverage during remediation efforts.
- Identify, assess, and prioritize operational and architectural risks discovered throughout the engagement.
- Provide actionable recommendations and executive-ready reporting that supports strategic decision-making.
Core Security Architecture Expertise
- Deep expertise in network security architecture, including traditional perimeter security technologies and SD-WAN environments.
- Strong practical experience implementing Zero Trust security principles and architectures.
- Advanced knowledge of AWS security services and best practices, including:
- AWS Control Tower
- AWS Security Hub
- AWS Config
- Amazon Guard Duty
- Strong understanding of cloud networking, hybrid-cloud integration patterns, and multi-account AWS security management.
- Expertise in encryption technologies and secure data protection strategies for data at rest and in transit.
- Proven experience leading large-scale security architecture assessments and remediation programs.
- Working knowledge of Privileged Access Management (PAM) concepts and controls.
- Experience securing CI/CD platforms and automation frameworks such as Jenkins, Ansible, Git Hub Actions, Git Lab CI/CD, or similar technologies.
- Familiarity with threat modeling, attack path analysis, and security control validation methodologies.
- Hands-on experience using AI-powered development or security tooling, such as Claude Code, OpenAI Codex, Gemini CLI, or similar AI coding agents, in professional or personal projects.
- Ability to integrate AI-assisted solutions into security architecture, assessment, and remediation workflows.
- AWS Security Specialty, Solutions Architect, CISSP, CCSP, SABSA, or equivalent security certifications.
- Experience designing and implementing enterprise-scale Zero Trust transformation programs.
- Strong stakeholder management, documentation, and communication skills with the ability to present complex security concepts to both technical and executive audiences.
By providing your phone number, you consent to: (1) receive automated text messages and calls from the Judge Group, Inc. and its affiliates (collectively "Judge") to such phone number regarding job…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×