Enterprise Security Architect
Listed on 2026-07-24
-
IT/Tech
Cybersecurity, Systems Engineer, Network Security
Job Title:
Enterprise Security Architect (IAM, Network Security, SOC, GRC & AI Security) (Telecom Domain Exp Must)
Location:
Seatle, WA – Hybrid Role Long Term Project Position Overview
We are seeking an experienced Enterprise Security Architect to design, govern, and evolve holistic cybersecurity architecture across our entire telecommunications enterprise — spanning network infrastructure, IT systems, applications, data, cloud, identity, and endpoints. This is a broad, cross‑domain security architecture role, not limited to network security: the successful candidate will own the security design of business applications, OSS/BSS/CRM platforms, customer data environments, cloud workloads, third‑party integrations, and corporate IT, in addition to the carrier‑grade network (RAN, Core, Transport, 5G).
TechnicalSkills
- Strong understanding of telecom platforms: OSS/BSS, 5G Core, RAN, IMS, VoLTE/VoNR, and signaling protocols.
- Expertise in IAM platforms (Okta, Azure AD, Cyber Ark, SailPoint, Ping).
- Knowledge of network security technologies (firewalls, IDS/IPS, NAC, microsegmentation, SD WAN).
- Familiarity with SOC operations (SIEM, SOAR, EDR/XDR, threat intelligence).
- Understanding of AI/ML systems and AI security governance.
- Experience with cloud environments (AWS, Azure, GCP) and Zero Trust frameworks.
- Telecom specific or network security certifications (e.g., CCNP Security, PCNSE, Juniper, Nokia, or GSMA programs).
- AI Security or AI Governance certifications (ISC2 AI+, NIST AI RMF programs).
- Own and evolve the enterprise cybersecurity architecture framework, covering applications, data, identity, endpoints, cloud, network, and OT/IoT — ensuring no domain is treated in isolation.
- Develop security reference architectures, patterns, and standards used across the enterprise, including for corporate IT, digital/customer‑facing platforms, OSS/BSS, and telecom network functions.
- Partner with enterprise architecture, application development, network engineering, and product teams to embed security‑by‑design and secure‑by‑default principles into all new initiatives.
- Lead architecture review boards, providing security sign‑off on major technology, product, and infrastructure investments.
- Build and maintain a multi‑year security architecture roadmap aligned to business strategy, risk appetite, and regulatory obligations.
- Architect security controls for enterprise applications, APIs, microservices, and customer‑facing digital channels (web, mobile, IVR, self‑service portals).
- Define data security and data protection architecture: classification, encryption (at rest/in transit), tokenization, DLP, and key management across structured and unstructured data.
- Design enterprise Identity and Access Management (IAM), Privileged Access Management (PAM), and Zero Trust architecture spanning employees, contractors, customers, and machine identities.
- Guide secure software development lifecycle (SSDLC) and Dev Sec Ops integration — threat modeling, secure code review gates, and automated security testing in CI/CD pipelines.
- Architect security for hybrid and multi‑cloud environments (AWS, Azure, GCP), including workload protection, container/Kubernetes security, CSPM, and cloud‑native security tooling.
- Evaluate and architect security controls for virtualized and cloud‑native network functions (NFV/VNFs/CNFs) alongside traditional IT infrastructure.
- Design security architecture for data centers, endpoints, email, and collaboration platforms as part of the broader enterprise estate.
- Extend enterprise security architecture principles into telecom‑specific domains: RAN, Core Network (4G/5G), Transport, IMS, and OSS/BSS.
- Address telecom‑specific attack surfaces (SS7/Diameter/GTP exploitation, SIM swapping, network slicing abuse, O‑RAN interfaces) within the broader enterprise risk model.
- Provide security architecture guidance for IoT, edge computing, 5G network slicing, and MEC deployments as extensions of enterprise risk, not standalone concerns.
- Conduct…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).