Responsibilities
- Lead the development and governance of Zero Trust and device trust strategies, covering network segmentation, ZTNA policies, and enforcement mechanisms for both office and remote access scenarios.
- Design and implement Cloudflare WARP and Access solutions to enable secure, identity-driven remote connectivity, moving beyond traditional VPN models with context-aware controls.
- Create network security frameworks for offices and data centers, incorporating SD-WAN (Meraki), firewall policies, 802.1X authentication, and DNS protection measures.
- Define standards for microsegmentation, internal traffic monitoring, and prevention of lateral movement within the network.
- Own the enterprise identity architecture, integrating identity providers, federation protocols (SAML/OIDC), provisioning systems (SCIM), multi-factor authentication, privileged access management, and user lifecycle controls across multiple tenant environments.
- Build device trust models using certificate-based authentication, integrating mobile device management platforms, fast identity solutions, and hardware-rooted security features like TPM and Secure Enclave.
- Develop role-based access control frameworks and automate user lifecycle processes (onboarding, role changes, offboarding) to ensure consistent access enforcement across more than 200 business applications.
- Design identity federation solutions to support mergers and acquisitions, third-party integrations, and customer-facing platforms.
- Define endpoint security standards for macOS, Windows, and mobile devices, including EDR deployment (CrowdStrike Falcon), MDM policy baselines, and patching strategies.
- Architect mobile device management solutions for corporate-owned and bring-your-own-device use cases, setting enrollment rules, compliance requirements, and conditional access integrations.
- Establish security baselines for endpoint hardening, application control, data loss prevention, and restrictions on removable media usage.
- Provide oversight on remote monitoring and management tools, ensuring secure design principles prevent misuse and maintain control boundaries.
- Lead the SaaS security initiative, including vendor risk categorization, security evaluation criteria, integration safeguards, and continuous monitoring mechanisms.
- Implement cloud access security broker (CASB), SaaS security posture management (SSPM), and access governance controls to maintain visibility and policy enforcement across cloud applications.
- Design data classification and DLP frameworks tailored to SaaS platforms such as Google Workspace, Microsoft 365, Salesforce, and Workday.
- Develop governance models for AI and unsanctioned SaaS tools, incorporating browser isolation, OAuth permission controls, and approved AI platform policies.
- Define security standards for on-premises and cloud-based internal systems, including network closets, server rooms, physical access systems (Brivo), and audiovisual infrastructure.
- Architect centralized logging, SIEM integration, and telemetry collection to ensure end-to-end visibility across infrastructure, identity, network, and endpoint layers.
- Design disaster recovery and resilience plans for critical systems, including offline backups and isolated recovery procedures.
- Develop security standards for operational technology environments, covering physical access hardware, environmental sensors, and networked facility equipment.
- Implement network segmentation and monitoring controls to separate OT systems from corporate IT, minimizing exposure and unauthorized access risks.
- Create vulnerability management programs for OT assets, considering limited patching windows and operational uptime needs.
- Maintain an up-to-date enterprise security architecture repository, including domain-specific reference models that evolve with technology and threat trends.
- Conduct security architecture assessments for new projects, vendor integrations, and infrastructure changes, delivering practical recommendations rather than binary approvals.
- Define security requirements and validation criteria for strategic initiatives in collaboration with security, engineering, and technology teams.
Work Arrangement
Remote (Worldwide) — New York City, U.S., U.K., Finland, India, Singapore, Canada, Ireland