Enterprise Information Security Engineer/Architect
Listed on 2026-06-04
-
IT/Tech
Cybersecurity, Information Security
Location: New York
Church Pension Group (CPG) is a financial services organization that serves the Episcopal Church, located in Midtown Manhattan. CPG was founded in 1917 to provide pension benefits to eligible clergy of the Episcopal Church. Since then, its mission has expanded to include life and disability insurance, health benefits, property & casualty insurance, and publishing.
Enterprise Information Security Engineer / ArchitectThe Enterprise Information Security Engineer / Architect reports to the Enterprise Information Security Officer (EISO) and is responsible for designing secure enterprise solutions and implementing robust security measures to protect Church Pension Group’s information assets and employees. The position ensures that security is embedded across all technologies—on‑premises, cloud‑hosted, SaaS, and other vendor services—while managing operational security tasks, including monitoring, incident response, compliance, and vendor management.
Strong communication skills and the ability to lead collaboration efforts with other ITS teams and business units are required.
- Architect Systems and Solutions
- Plan and design security solutions that enable identification, protection, detection, response, and recovery from cyber threats.
- Define and develop security requirements from threat assessments, risk modeling, system analysis, and regulations, leveraging standard security frameworks.
- Create security integration plans for existing infrastructure and future solutions.
- Security Operations
- Implement and manage security technologies (e.g., firewalls, encryption, SIEM, DLP, IPS) directly, collaborate with other teams, and use MSSPs.
- Monitor networks and systems for security breaches, escalations, and anomalies to ensure optimal security and accurate metrics.
- Perform vulnerability assessments, penetration testing, and manage these services.
- Own several of the security tool vendor relationships.
- Governance and Compliance
- Develop and maintain security policies, standards, and procedures to ensure a secure environment and compliance with regulatory requirements.
- Present and manage compliance issues, remediation, and organizational conversations.
- Prepare action plans to harden systems, respond to security and DR events.
- Risk Management
- Identify, evaluate, and report on information security risks.
- Perform regular risk assessments and recommend mitigation strategies.
- Education and Awareness
- Educate staff on cybersecurity best practices and the security program.
- Acquire or develop training to address identified gaps and remediations.
- Manage IT compliance and collaborate on corporate compliance measures.
- Advise business units on secure configurations, vendors, and architectures.
- Support Leadership
- Support the EISO in security event management, group collaboration, and planning and budgeting.
- Maintain and develop both technical and management skills.
- Effective performance of the essential functions of this position requires regular in‑person, on‑site interaction with colleagues, both for purposes of relationship building and meaningful collaboration.
- Other duties may be assigned.
- Strong knowledge of cybersecurity principles, frameworks, and tools.
- Experience with a wide range of tools, including IDS, IPS, firewalls, and SEIMs.
- Deep understanding of Cloud Security and SaaS Vendor Security.
- Proficiency in risk assessment, incident response, and threat modeling.
- Excellent communication skills for cross‑functional collaboration.
- 6+ years of relevant Information Security experience.
- BA/BS in Computer Science, Engineering, or related field preferred. Combination of work and education considered.
- Preferred
Certifications:
CISSP, CISM, CCSP, CISA, multiple topical GIACs. - Experience with AWS, Azure M365, Entra , Splunk, Crowd Strike, Darktrace, and Tripwire is a plus.
- Extensive use of a computer keyboard is a demand of the position to perform the essential functions of this job successfully.
Currently, a hybrid work environment, which requires working in CPG’s office Tuesdays through Thursdays and flexibility to work remotely on Mondays and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).