Security Architect
Sorenson
Job Description
Job Description:\n\nJob Summary\nThe Security Architect serves as Sorenson’s senior security architecture authority and is responsible for defining, advancing, and overseeing the enterprise cybersecurity architecture strategy. Positioned within the Security organization, this role has enterprise-wide influence over security architecture practices across identity, application, cloud, infrastructure, network, data, security operations, resilience, Zero Trust, and emerging technologies.\nThe Security Architect establishes security principles, standards, reference architectures, technical guardrails, and reusable design patterns that guide the secure development, deployment, operation, and integration of enterprise technologies. The role establishes and leads the Security Architecture Review process for materially significant initiatives, helping ensure security is incorporated early in solution design and technology decision-making.\nThe role works in close partnership with Enterprise Architecture, Engineering, Product, Data, AI Governance, Legal, Privacy, Compliance, and Risk Management. The Security Architect represents and governs the security architecture domain while aligning with broader enterprise architecture and governance processes.\nArtificial intelligence is an important component of the role’s emerging-technology responsibilities. The Security Architect defines security architecture and control patterns for AI systems, models, agents, platforms, data pipelines, vector databases, and retrieval-augmented generation solutions while ensuring alignment with enterprise security, data governance, privacy, compliance, risk, and responsible AI objectives.\nSuccess is measured through increased adoption of approved security architecture standards, timely completion of architecture reviews for materially significant initiatives, improved threat-modeling and SSDLC coverage, reduction of systemic architectural risk and technical debt, advancement of Zero Trust and cyber-resilience maturity, and secure deployment of new and emerging technologies.\n \nEssential Duties and Responsibilities\nEnterprise Security Architecture Strategy and Standards\n\n Define, advance, and govern Sorenson’s enterprise cybersecurity architecture strategy, principles, standards, reference architectures, and design patterns.\n Develop reusable security architecture patterns and technical guardrails that accelerate secure delivery while maintaining consistency across enterprise systems, products, and platforms.\n Define architectural security requirements and implementation guidance that support business objectives, operational resilience, and risk management goals.\n Maintain alignment between security architecture strategy and Sorenson's enterprise technology strategy through partnership with Enterprise Architecture and technology leadership teams.\n\nSecurity Architecture Review & Decision Leadership\n\n Establish and lead the Security Architecture Review process for materially significant technology initiatives, including cloud platforms, enterprise applications, customer-facing products, AI systems, data platforms, third-party services, and major architectural changes.\n Define risk-based review criteria, engagement points, required architecture artifacts, security requirements, and exception-management processes.\n Ensure security is incorporated early in solution design, technology selection, procurement, and implementation planning.\n Document security architecture determinations, required security controls, approved patterns, design alternatives, exceptions, and material risk considerations.\n Provide architectural guidance and recommendations that balance security, operational effectiveness, business objectives, cost, and delivery timelines.\n\nApplication Security & Secure Software Architecture\n\n Define and maintain secure application architecture standards and reference patterns for:\n Authentication and authorization\n API security\n Microservices security\n Service-to-service trust\n Secure design principles\n Secrets management\n Secure session management\n Application threat modeling\n Partner with Application Security, Product, Engineering, and DevSecOps teams to integrate approved security architecture patterns throughout the software development lifecycle.\n Define architecture expectations and verification criteria that support consistent implementation of secure software development practices.\n Support engineering teams in resolving complex design challenges requiring security architecture expertise.\n\nZero Trust, Identity & Data Protection Architecture\n\n Establish and maintain the Zero Trust architecture strategy and roadmap across identity, device, network, application, workload, and data pillars.\n Architect identity and access management patterns including:\n Single Sign-On (SSO)\n Multi-Factor Authentication (MFA)\n Privileged Access Management (PAM)\n Role-Based Access Control (RBAC)\n Attribute-Based Access Control (ABAC)\n Federation\n Non-human and workload identities\n Define data protection architectures including:\n Data classification controls\n Encryption standards\n Key management\n Data loss prevention patterns\n Access control architectures\n Ensure security architectures support enterprise identity, API management, and governance frameworks.\n\nCloud, Infrastructure, Network & Cyber Resilience Architecture\n\n Design security reference architectures across public cloud, private cloud, hybrid, and on-premises environments.\n Define architecture standards for:\n Cloud landing zones\n Network segmentation\n Infrastructure-as-Code security\n Container security\n Workload protection\n Secrets and credential management\n Cloud security posture management\n Define architecture patterns that support operational resilience, recoverability, survivability, and security monitoring.\n Develop security modernization roadmaps that address legacy technology risks, architectural technical debt, cyber resilience capabilities, disaster recovery readiness, and strategic security transformation initiatives.\n Partner with Infrastructure, Operations, and Enterprise Architecture teams to prioritize long-term security modernization objectives.\n\nEnterprise Data, Analytics & AI Security Architecture\n\n Define security architecture patterns and controls for:\n Enterprise data platforms\n Analytics environments\n Data-sharing ecosystems\n AI data pipelines\n Vector databases\n Embedding pipelines\n Retrieval-Augmented Generation (RAG) architectures\n Develop security architecture standards and technical controls to protect AI systems, models, agents, platforms, and associated data.\n Define safeguards addressing:\n Prompt injection\n Tool misuse\n Data exposure\n Model abuse\n Excessive agent privilege\n Memory and context isolation\n AI observability and guardrails\n Ensure AI and data architectures align with enterprise security requirements, privacy requirements, data governance standards, and responsible AI principles.\n Partner with AI Governance, Data Governance, Legal, Privacy, Compliance, and Risk Management stakeholders to ensure secure and compliant adoption of AI capabilities.\n\nThird-Party & Technology Partner Security Architecture\n\n Partner with the SOC to define detection, logging, and response architecture (telemetry standards, SIEM/SOAR, detection engineering).\n Align defensive architecture to threat-informed defense using MITRE ATT&CK and emerging AI threat frameworks.\n Lead enterprise threat modeling for new and materially changed systems—including AI/agentic systems—ensuring mitigations are documented, tracked, and testable.\n Identify systemic architecture risk across the portfolio and drive roadmap items to reduce exposure.\n\nThreat Modeling, Security Operations & Security-by-Design\n\n Oversee threat modeling activities for new and materially changed systems, applications, services, and AI-enabled solutions.\n Apply frameworks such as:\n STRIDE\n MITRE ATT&CK\n MITRE ATLAS\n MAESTRO\n OWASP methodologies\n Ensure identified threats, mitigations, and security requirements are documented, assigned, tracked, and validated.\n Partner with Security Operations to define security monitoring, logging, telemetry, detection engineering, and response architecture patterns.\n Support Security-by-Design activities by ensuring architecture artifacts, system descriptions, diagrams, and technical documentation align with implemented solutions.\n\nCross-Functional Leadership, Metrics & Continuous Improvement\n\n Serve as Security’s senior architecture advisor for major technology initiatives and strategic programs.\n Partner closely with Enterprise Architecture to ensure alignment between enterprise technology direction and security architecture requirements.\n Chair or participate in security architecture governance activities including architecture reviews, standards development, exception management, and architectural decision-making forums.\n Define, track, and report security architecture effectiveness metrics including:\n Architecture review coverage\n Threat modeling coverage\n Security pattern adoption\n Exception trends\n Architectural technical debt reduction\n Security control adoption\n Security architecture maturity\n Mentor engineers, architects, and security professionals on architecture principles, emerging technologies, and secure design practices.\n Drive continuous improvement of security architecture capabilities, standards, and governance processes.\n\nOther duties as assigned.\n \nSupervisory Responsibility\nThis position has no direct supervisory responsibilities but does serve as a coach and mentor for other positions in the department.\n \nTravel Requirements\nTravel Requirements: Less than 25%\n \nEducation\nMinimum 4 Year / Bachelors Degree In Computer Science, Cybersecurity, Information Systems, Software Engineering, or related field.\nPreferred: Graduate Degree In Cybersecurity, Computer Science, Information systems or related discipline.\n \nExperience\nMinimum of 8 Years of Experience\n\n Demonstrated experience designing and governing security architectures across multiple domains including application, cloud, infrastructure, identity, data protection, and security operations.\n Experience conducting architecture reviews, threat modeling, and risk-based design assessments for complex enterprise environments.\n Experience evaluating emerging technologies and providing architecture recommendations that balance security, business objectives, and operational requirements.\n\n \nKnowledge, Skills, and Abilities\n\n Deep expertise in security architecture spanning application, cloud, infrastructure, network, identity, Zero Trust, security operations, and data protection domains.\n Strong understanding of secure application architecture, APIs, microservices, distributed systems, and secure software development practices.\n Experience establishing reusable security architecture standards, reference architectures, technical controls, and implementation patterns.\n Experience securing modern AI systems, machine learning solutions, agentic systems, AI orchestration platforms, and RAG implementations.\n Experience securing enterprise data platforms, analytics environments, and large-scale cloud-native systems.\n Knowledge of security architecture frameworks, governance processes, and risk-management practices.\n Ability to assess complex architectural risks and provide pragmatic, business-aligned recommendations.\n Ability to influence enterprise technology decisions through partnership, expertise, and architectural leadership.\n Strong written and verbal communication skills with technical and executive stakeholders.\n Strong analytical, strategic-thinking, and problem-solving capabilities.\n Professional attitude, team player, good interpersonal communication skills and able to work across company departments.\n Preferred\n Experience establishing and leading enterprise security architecture review functions.\n Experience implementing Zero Trust architectures at scale.\n Experience securing enterprise data platforms, analytics environments, AI systems, RAG architectures, and AI-enabled applications.\n Experience assessing SaaS platforms, cloud services, AI providers, and strategic technology vendors.\n Experience developing security modernization and cyber resilience strategies.\n Experience working within governance-heavy or compliance-driven regulated environments (e.g., HIPAA, PCI DSS, SOC 2).\n Relevant certifications such as CISSP, CISSP-ISSAP, SABSA, CCSP, AWS Security Specialty, Azure Security Engineer Associate, Google Professional Cloud Security Engineer, or other relevant security specialties.\n\n \nCome be a part of our mission and make a meaningful and positive impact with the industry leading provider of language services for the Deaf and hard-of-hearing!\nFull time Benefits \n\n Paid Vacation Time and Paid Sick Time and Paid Holidays\n 401k 6% match with immediate vesting\n Nationwide Medical Insurance plans and coverage (Medical, Dental/Orthodontia, Vision)\n \n TeleDoc\n HSA company match\n 3 Medical plan options including a Low Deductible PPO Medical Plan Offering\n \n Employee Assistance Program\n Engaged Employee Resource Groups\n Outstanding Learning and Career Development Opportunities\n\nPay Range: Actual pay may vary up or down depending on job-related factors which may include knowledge, skills, experience, and location. In addition, this position may be eligible for incentive compensation.\n* Applicants must be legally eligible to work in the United States to be considered. Visa sponsorship is not available for this role *\nCompany Summary\nOur Mission…Leveraging the Power of Language, we connect lives and enrich the human experience.\nOur Vision…To provide global language services that expand opportunities, nurture belonging, and empower the world to connect beyond words.\nAs one of the world’s leading language services providers, Sorenson combines patented technology with human-centric solutions. We strive to increase accessibility and inclusion through communication solutions for all: call captioning and video relay services, over-video and in-person sign language and spoken language interpreting, translation, real-time captioning, and post-production language services. Sorenson’s impact vision and plan extends to enhancing generational wealth and inclusive workplaces for our employees and the communities we serve.\nWe achieve great things together working “The Sorenson Way” with our employee values: Customer First, Can-Do Attitude, Collective Action, Growth Mindset, Ownership, and Connect Direct.\n \nEqual Employment Opportunity:\n Sorenson Communications is an Equal Opportunity, Affirmative Action Employer.
- Job SummaryThe Security Architect serves as Sorenson’s senior security architecture authority and is responsible for defining, advancing, and overseeing the enterprise cybersecurity architecture strategy. Positioned within the Security organization, this role has enterprise...SuggestedFull timeImmediate start
$140k - $175k
IAM Security ArchitectHybrid (In office 3 days/week) within Oregon, Washington, Idaho or UtahBuild a career with purpose. Join our Cause... ...Looking For: Every day, Cambia's dedicated team of Security Architects are living our mission to make health care easier and lives...SuggestedFull timeWork at officeImmediate startWork from homeFlexible hours3 days per week- ...Metadata API, ChangeSet, and Ant.Best Practices understanding on Coding Standards, Deployment, Apex, VF, Salesforce Integration, Security implementationsExperience on Force.com Integration Technologies (WebServices, 3rd Party tool like CastIron/Boomi) to Integrate with...SuggestedPermanent employmentFull timeH1bFlexible hours
$60 - $65 per hour
...Volt - where your skills matter, your growth is our mission, and opportunity is just the beginning.Volt is immediately hiring Info Security Sys Engineer at Salt Lake City, UtahAs an Info Security Sys Engineer, you will be responsible for:Execute and support RMF...SuggestedFull timeContract workTemporary workWork experience placementImmediate start- ...extraordinary outcomes.Job Title: Enterprise Salesforce - Technical Architect You are the Salesforce Technical Architect responsible for... ...of Salesforce for integration, networking, infrastructure, security, data modeling and DevOps. * Knowledge of and experience using...SuggestedTemporary workLocal area
$112.5k - $202.5k
...Do you like building solutions to help improve the security of the company? Do you want to collaborate with industry-leading security experts? Join our Information Security Team! Akamai's Information Security team is responsible for safeguarding Akamai, its customers...Work experience placementWork at officeWorldwide- ...; Salt Lake City, Utah, United States Who We Are Legato Security is an information security firm founded upon the belief that every... ...(NCCSI - NSK200), Netskope Certified Cloud Security Architect (NCCSA - NSK300), or Netskope SASE Accredidation Cisco CCNA...Temporary workWork at officeRemote work
- ...capabilities, integrations, and reusable patterns that help clients adopt AI responsibly and effectively. You will collaborate with architects, consultants, developers, and client stakeholders to translate business needs into scalable, maintainable technical solutions.The...Temporary workLocal area
- ...workforce of the future, today. We are seeking an Enterprise Architect (SDLC) to join Zions Bancorporation. As an Enterprise Architect... ...IT operational domains (Engineering, Ops, ITSM, PMO, QA, Dev, Security, Risk, Change, Architecture)Strong understanding of software and...Work experience placementWork at officeWork from homeFlexible hours3 days per week
$98k - $147k
...San Francisco, New York, Seattle, Salt Lake City, London, Madrid, and Singapore. #### Opportunity for Impact The Corporate Security Engineer is a critical member of Taxbit’s growing Security organization. This role owns the design, deployment, and lifecycle management...Full timeRemote work- ...Job Description Job Description Celtic Bank is seeking a skilled Security Engineer to help protect the Bank’s systems, data, and technology environment. This role is responsible for identifying, reducing, and continuously managing internal and external security risks...Work at officeLocal area
$36 - $43 per hour
...Ultimate Staffing is partnering with an innovative technology organization seeking an experienced IT & Security Engineer to support and strengthen its global IT infrastructure and cybersecurity operations. This role is approximately 80% security-focused and 20%...Hourly payTemporary workPart timeLocal areaRemote workMonday to Friday- ...we are looking for IT Security and Sustems engineers for Part Time role . 20-30 hours per week, Monday-Friday. No weekend or on-call coverage is needed. Hybrid (2 days onsite) Location preference: Salt Lake City UT Time: 9am to 5PM The IT & Security Engineer...Full timeTemporary workPart timeLocal areaMonday to Friday
- ...Position Description & Qualifications Are you an Information System Security Engineer (ISSE) looking for a place where you can make an impact every day? Serco is the place for you! Join our Defense team supporting our CNIC program in this exciting role based out of...Full timeContract workPart timeInterim roleLocal areaFlexible hours
- ...Job Description Job Description Want to build security, not just maintain it? This isn’t a role where you’ll inherit a mature security program, spend your days updating policies, or stay buried in one narrow piece of the environment. We’re looking for an experienced...Weekend work3 days per week
- We are currently seeking a Senior Cyber Incident Response Engineer as part of our Enterprise Information Security department. Enterprise Information Security (EIS) is integrated with the Enterprise Technology and Operations division (1100+ technical people) at Zions Bancorporation...Work at officeWork from homeFlexible hours3 days per week
- ...Join to apply for the Application Security Engineer role at Priority Dispatch Corporation Direct message the job poster from Priority Dispatch Corporation Job Summary We are seeking an experienced Application Security Engineer to secure our web and desktop...Full time
- ...Senior Security Engineer NOVVA Data Centers is seeking a highly skilled Senior Security Engineer to lead the design, implementation, and operation of cybersecurity technologies that protect our enterprise, customer-facing systems, and mission-critical data center environments...
- ...Tactical, and other companies. We have a shared IT function that serves all businesses, and we are looking for the person who will drive security across all of them. You will be the subject matter expert for security and compliance company-wide, working under our Senior IT...Full time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Architect. Be the first to apply!



