Lead Security Architect
Listed on 2026-07-24
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Systems Engineer
Overview
We are Collaborative. Respectful. A place to dream and do. These are just a few words that describe what life is like one of the world’s most admired brands, Toyota is growing and leading the future of mobility through innovative, high-quality solutions designed to enhance lives and delight those we serve. We’re looking for talented team members who want to Dream.
Do. Grow. with us.
An important part of the Toyota family is Toyota Financial Services (TFS), the finance and insurance brand for Toyota and Lexus in North America. While TFS is a separate business entity, it is an essential part of this world‑changing company—delivering on Toyota’s vision to move people beyond what’s possible. At TFS, you will help create best‑in‑class customer experience in an innovative, collaborative environment.
Toyota does not offer support or sponsorship of job applicants for employment‑based visas or any other work authorization for this role now or in the future. You must have the right to work in the United States and not require Toyota support or sponsorship for immigration‑related employment (e.g., H‑1B, O‑1, E‑3, H‑1B1, TN, F‑1 OPT, F‑1 STEM OPT, F‑1 CPT, TN, ‘job flexibility benefits’ (also known as I‑140 or Adjustment of Status portability), etc.)
now or in the future. You should not apply for this role if you will require Toyota to assist with immigration support or sponsorship now or in the future.
Toyota Financial Services (TFS) Technology is seeking a highly experienced and outcome‑driven Lead Security Architect to define, govern, and advance a threat‑informed, data‑centric security architecture across enterprise platforms and business services. This role is accountable for embedding Data‑Centric Threat Modeling (NIST SP 800‑154) into the architecture lifecycle ensuring that security decisions are driven by how data is created, processed, stored, and exposed, rather than relying solely on perimeter or technology‑centric controls.
The ideal candidate will operate as a senior technical authority, influencing design decisions, enforcing architectural standards, and driving measurable improvements in control effectiveness across TFS environments.
- Lead Data‑Centric Threat Modeling: own and operationalize Data‑Centric Threat Modeling (NIST SP 800‑154) across application, cloud, and enterprise architectures.
- Identify threats, attack paths, and control gaps based on data flows, sensitivity, and business impact.
- Integrate threat modeling into solution design, architecture reviews, and delivery pipelines.
- Drive consistency through standardized methodologies and tooling (e.g., Threat Modeler, Irius Risk).
- Define and enforce security architecture standards, patterns, and reference models aligned to TFS policy and risk tolerance.
- Lead architecture design reviews and provide binding security decisions for critical initiatives.
- Ensure solutions align to Zero Trust principles, least privilege access, and data protection requirements.
- Translate threat models and architectural assessments into actionable risk insights for executives and stakeholders.
- Support risk acceptance, exception handling, and architectural trade‑offs with clear business impact articulation.
- Identify control gaps and redundancies across security tooling; recommend optimization and rationalization strategies.
- Collaborate with engineering, infrastructure, data, and application teams to embed security early in the development lifecycle.
- Influence third‑party and vendor design reviews using threat‑informed architecture criteria, not just checklist‑based assessments.
- Align with risk and compliance teams to ensure regulatory expectations (e.g., financial services controls) are integrated into design.
- Move beyond artifact review (e.g., SOC2, ISO
27001) to assess real‑world control effectiveness against identified threats. - Correlate assurance evidence with actual attack scenarios and data exposure risks.
- Drive continuous improvement in architecture based on evolving threats and control performance.
- Deep expertise in enterprise security architecture across cloud, application, identity (Identity and Access…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).