HOM1007HSUC

Senior Cybersecurity Architect

Norwalk, Connecticut · Hybrid · Posted today

Opens recruiting.ultipro.com

Get a version of your resume written for this job.

Salary
Not listed
Job type
Full-time
Work mode
Hybrid
Source
UKG (employer's hiring system)

Skills mentioned

AWS, Cybersecurity, IAM, Zero Trust, Kubernetes, CI/CD, Serverless, DevOps

About the role

Position Overview:

This role serves HomeServe’s senior security architecture authority, responsible for designing, reviewing, and governing secure architecture for new and existing services, applications, and integrations before they reach production. The position creates business value by reducing the likelihood and blast radius of security incidents, accelerating secure delivery through reusable patterns and paved-road guardrails, and helping HomeServe meet customer, regulatory, and contractual obligations. Reporting to the VP of Information Security, this role leads formal security architecture reviews—producing risk-rated assessments and tracked remediation or exception plans—and acts as a design authority at key delivery gates (e.g., permission-to-build and permission-to-operate). It champions Zero Trust and secure-by-design principles across identity, network, application, and data security, and partners with Product, DevOps, Cloud, and Legal/Privacy to embed those practices into cohesive, scalable patterns adopted by delivery teams. The role owns and advances the security architecture roadmap and strategy—with particular focus on hybrid/multicloud (AWS primary), API/integration, and emerging AI-driven systems—and provides technical oversight and security architecture guidance for incident response while mentoring members of the information security team.

 

Responsibilities:

  • Serve as the security architecture review and design authority for new solutions, integrations, and major changes—evaluate solution designs at permission-to-build and permission-to-operate gates, produce formal InfoSec assessments with risk-rated findings, and drive remediation or formal, time-boxed exceptions to closure.
  • Champion and operationalize Zero Trust architecture: identity-centric access, least-privilege enforcement, micro segmentation, and continuous verification across on-premises, cloud, and containerized environments.
  • Develop enterprise security reference architectures, reusable design patterns, and secure-by-design standards and “paved-road” guardrails that delivery teams can adopt through self-service.
  • Design and review cloud security architecture across hybrid/multicloud (AWS primary): least-privilege IAM, serverless/Lambda hardening, S3/KMS encryption strategy (customer-managed vs. AWS-managed keys), Secrets Manager and key-rotation practices, VPC placement, and secure network egress.
  • Embed security into the SDLC and DevSecOps toolchain: CI/CD pipeline security, infrastructure-as-code scanning, container/Kubernetes security, and shift-left practices in partnership with Product and DevOps.
  • Assess and guide the secure design of data and AI system data protection and classification, plus AI-specific controls such as human-in-the-loop and confidence-threshold gating, audit logging and rollback, and model/vendor data-handling and retention.
  • Review API and integration security across platforms such as MuleSoft and Akamai (WAF, rate limiting, request validation) and third-party SaaS integrations.
  • Conduct third-party and vendor security risk assessments, including data-retention, consent, call-recording, and PII-handling obligations; partner with Legal/Privacy on regulatory determinations.
  • Map controls and findings to recognized frameworks (NIST CSF 2.0, NIST 800-53, ISO 27001) and recommend and enforce minimum security baselines for IT platforms and technologies.
  • Enforce Privileged Access Management (PAM) standards for service-account and credential handling across integrations and data pipelines.
  • Participate in and, where appropriate, act as an approver for the Architectural Review Board (ARB) and Change Advisory Board (CAB); manage pre-CAB security-related requests.
  • Perform risk analysis for corporate functional and technical areas relevant to data security, including networks, applications, and 3rd-party service providers.
  • Create and maintain security architecture documentation, standards, patterns, and procedures.
  • Provide technical oversight and security architecture guidance for incident identification, response, investigation, and remediation, including support during off hours as needed.
  • Research and maintain a knowledge base of information security and emerging-technology trends, advisories, and applicable laws and regulations; identify and communicate current and emerging security threats.
  • Create solutions that balance business requirements with information and cyber security requirements; influence peers, partners, and project teams toward security-minded decisions.
  • Enable and coach delivery teams and information security staff to adopt secure design patterns and self-service guardrails; answer technical and procedural questions to improve processes.
  • All other duties as assigned.

Essential Functions:

Essential Job Function

% of Time on Function

Security architecture, design reviews & patterns

40%

Risk management, third-party & compliance

20%

Cloud, DevSecOps & integration security

20%

Security strategy, governance & roadmap

10%

Mentorship & security operations advisory

10%

Total

100%

Job Requirements:

  • Bachelor’s degree in information technology, computer science, or a related field, or equivalent work or education-related experience.
  • 7+ years’ experience in IT Security, with demonstrated experience in security architecture and solution design review.
  • Demonstrated experience designing Zero Trust and secure-by-design architectures, including reusable security patterns and reference architectures adopted across delivery teams.
  • Hands-on experience securing hybrid/multicloud environments (AWS strongly preferred; Azure/GCP a plus): IAM, serverless/Lambda, S3, KMS, Secrets Manager, VPC design, and cloud-native security controls.
  • Experience integrating security into DevSecOps and the secure SDLC: CI/CD pipeline security, infrastructure-as-code scanning, and container/Kubernetes security.
  • Experience with API and integration security (e.g., API gateways, WAF, MuleSoft/Akamai or equivalent) and securing third-party SaaS integrations.
  • Exposure to securing data and AI/ML or automation/agentic systems—data protection, autonomy controls, human-in-the-loop design, and model/vendor data-handling risk (increasingly required).
  • Experience must include security standards development, risk assessment, third-party/vendor risk, and compliance testing; penetration-testing and vulnerability-assessment familiarity expected.
  • Proficient knowledge of information security standards, controls, and frameworks (e.g., NIST CSF 2.0, NIST 800-53, ISO 27001, PCI DSS) for desktops, servers, applications, databases, and network devices.
  • Working knowledge of key security technologies: cloud security services, IAM, cryptography/encryption and key management, DLP, SIEM, IDS/IPS, endpoint protection, firewalls, and Active Directory.
  • Strong analytical and problem-solving skills; excellent verbal, written, and interpersonal communication skills; ability to interact with and influence all levels of the organization.
  • Effective time-, project-, and organizational-management skills; ability to handle multiple projects within established time constraints.
  • Must be able to work independently as well as in a team environment and maintain confidentiality.
  • Industry certifications preferred: CISSP required or strongly preferred; Microsoft SC-100 (Cybersecurity Architect Expert) and/or CISSP-ISSAP highly desirable for architecture depth; CCSP and AWS Certified Security – Specialty highly desirable for cloud depth; CISM, CISA, CEH, or GIAC a plus.

Minimum Physical Requirements: 

The physical demands described represent those that must be met by an employee to successfully perform the essential functions of this position. Reasonable accommodations may be made to enable individuals with disabilities to perform the functions of the position for which they work. While performing the duties of this position, the employee is regularly required to listen, talk and hear. The employee frequently is required to use hands or fingers, handle or feel objects, tools, or controls while executing tasks like working on a computer or talking on the telephone.  The employee is occasionally required to stand; walk; sit; and reach with hands and arms. The employee must occasionally lift and/or move up to 15 pounds. Specific vision abilities required by this position include close vision, distance vision, and the ability to adjust focus. The noise level in the work environment is usually moderate to low.

This job description is intended to provide guidelines for job expectations and the employee's ability to perform the position described. It is not intended to be construed as an exhaustive list of all functions, responsibilities, skills, and abilities. Additional functions and requirements may be assigned by supervisors as deemed appropriate.   

Salary Range (Norwalk, CT): $157,592.85 – $210,123.80
Annual Bonus Eligibility: 15%

HomeServe USA is an equal opportunity employer.

#HUSA #LI-NM1 #LI-ONSITE

Job ID up-recruiting-ultipro-com-hom1007hsuc-04366c17-7ee4-499a-a9e9-38ae46d03ef6-1782cec1-f0f9-4658-8cf4-df86632811b7 · Original posting ↗