Security Architect
Hexion
Company OverviewHexion is a global leader in specialty chemicals, delivering innovative solutions that improve performance, sustainability, and efficiency across industries. Our manufacturing operations span multiple continents, integrating complex Operational Technology (OT) environments with enterprise IT systems and a growing footprint in Microsoft Azure and Amazon Web Services. As the business adopts cloud platforms and artificial intelligence at scale, Hexion is investing in a security architecture function capable of designing defensible systems across every environment we operate — on-premises data centers, public cloud, the plant floor, and the physical perimeter that protects both. Position OverviewThe Security Architect is a senior technical practitioner responsible for designing the security architecture of Hexion’s enterprise environment: on-premises infrastructure, Azure and AWS cloud platforms, AI and machine learning systems, and the interfaces between enterprise IT, Operational Technology, and physical security systems. This role owns reference architectures, security design patterns, and architectural standards — and holds the authority to review, challenge, and approve designs before they are built. This is an architecture role, not a compliance role. The successful candidate uses ISO/IEC 27001, 27017, 27018, 42001, and 27019 as the frameworks that shape control selection and design rationale, then works alongside engineering teams to make those controls real in configuration, code, and network design. This role ensures: Security is designed into systems at inception rather than assessed after deployment On-premises, Azure, and AWS environments share a coherent identity, network, and data protection architecture Cloud services are architected against ISO/IEC 27017 and 27018 expectations for cloud security and PII protection AI and machine learning systems are designed with governance and technical controls aligned to ISO/IEC 42001 and recognized AI threat models OT and process control architectures are secured in partnership with engineering, informed by ISO/IEC 27019 and IEC 62443 Physical security systems and controls are treated as part of the security architecture, not a separate disciplineArchitectural decisions are documented, defensible, and traceable to risk Job Responsibilities1. Enterprise & On-Premises Architecture Own the security architecture of Hexion’s on-premises estate: Design and maintain reference architectures for network segmentation, zero trust access, remote access, and data center securityArchitect identity and access management across Active Directory, Entra ID, privileged access management, and federation to cloud and SaaS platformsDefine security architecture standards for endpoints, servers, virtualization, backup, and disaster recoveryLead the architectural review function — evaluate new systems, integrations, and infrastructure changes against defined standards and document exceptions with compensating controlsDesign detection and logging architecture in partnership with security operations, ensuring telemetry coverage across on-premises and cloud estatesMaintain the enterprise security architecture roadmap, sequencing capability investments against risk reduction 2. Cloud Security Architecture (Azure and AWS) Serve as the design authority for multi-cloud security: Architect landing zones, subscription and account structures, network topology, and guardrails for both Azure and AWSDesign cloud identity architecture — workload identity, federation, conditional access, least-privilege IAM policy models, and secrets managementApply ISO/IEC 27017 cloud security controls to define Hexion’s architectural obligations as a cloud service customer, and where applicable as a cloud service providerApply ISO/IEC 27018 controls for protection of personally identifiable information in public cloud, including data residency, encryption, and processor boundary designDefine encryption and key management architecture across Azure Key Vault, AWS KMS, and on-premises HSM or key storesEstablish policy-as-code and infrastructure-as-code security patterns, embedding controls into Terraform, Bicep, or CloudFormation pipelinesArchitect CSPM, CWPP, and cloud-native detection coverage; define the standards those tools measure againstDesign secure connectivity between cloud platforms, on-premises data centers, and plant networks 3. AI Security Architecture (ISO/IEC 42001) Design the security architecture for Hexion’s adoption of artificial intelligence: Define reference architectures for enterprise AI use — hosted LLM services, retrieval-augmented generation, agentic workflows, and AI-enabled SaaSApply ISO/IEC 42001 as the governance framework for AI management, translating its requirements into architectural controls rather than paperworkDesign controls against recognized AI threat models — prompt injection, training and inference data poisoning, model and data exfiltration, insecure output handling, and excessive agency (OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF)Architect data protection boundaries for AI systems: what data may reach which model, under what tenancy, with what retention and residency guaranteesDefine identity, authorization, and audit architecture for AI agents and non-human identities acting on enterprise systemsEstablish security review patterns for AI use cases, model selection, and third-party AI vendorsAdvise on secure use of AI within OT and engineering contexts, where model outputs may influence physical processes Job Responsibilities continued...4. OT & Process Control Security Architecture Partner with engineering and plant operations to secure industrial environments: Design IT/OT boundary architecture — segmentation, DMZ patterns, unidirectional gateways where warranted, and secure remote access for vendors and engineersApply ISO/IEC 27019 and IEC 62443 concepts to zone and conduit design, asset inventory, and control selection for process control systemsDefine architectural standards for OT monitoring, passive asset discovery, and safe patching and change practicesSupport architecture for plant modernization, connected sensor, and industrial IoT initiatives without compromising safety or availabilityTranslate enterprise security standards into requirements that are implementable on the plant floor, respecting availability and safety constraints 5. Physical Security Architecture Treat physical and logical security as one architecture: Define security architecture for physical access control, video surveillance, intrusion detection, and visitor management systems Architect the convergence of physical security platforms with enterprise identity — provisioning, deprovisioning, and access review across badge and logical systems Address the network and lifecycle security of physical security devices, which frequently share infrastructure with OT and enterprise networks Define physical security requirements for data centers, control rooms, network closets, and cloud colocation or interconnect facilities Support site risk assessments and design layered protection appropriate to facility criticality 6. Standards, Patterns & Technical Governance Maintain the architectural artifacts the organization builds against: Author and maintain security standards, design patterns, and hardening baselines mapped to ISO/IEC 27001 Annex A and the extension standards named above Provide architectural input to the ISMS and AI management system, including risk treatment design, Statement of Applicability rationale, and control implementation evidence Conduct threat modeling and architectural risk assessments for major programs and high-impact changes Contribute security architecture requirements to vendor selection, third-party integrations, and M&A technical due diligence Mentor engineers and analysts, raising the architectural fluency of the broader security and IT organization CompetenciesDesign authority — you produce architectures that engineering teams can build from, and you defend them with reasoning rather than mandate Breadth with depth — you move credibly between a cloud IAM policy, a plant network diagram, and a badge reader VLAN without losing precision Standards as tools — you use the ISO family to sharpen design decisions, not to generate documentation for its own sake Pragmatic risk judgment — you know which theoretical risks matter in a chemical manufacturing environment and which do not Engineering credibility — you have built things, and technical teams recognize it within the first conversation Clarity in writing — your diagrams and design documents are the artifacts other people work from for years Forward posture — you track how cloud, AI, and OT threat landscapes are moving and adjust architecture before incidents force it Leadership Expectations:Serve as the enterprise technical authority on security architecture across IT, cloud, AI, OT, and physical security domains Influence without direct authority — secure architectural outcomes from teams that do not report to security Partner with the Compliance and Risk function so that architecture and control frameworks reinforce rather than duplicate each other Represent security architecture in enterprise architecture forums, capital project reviews, and vendor evaluations Make and document architectural decisions under uncertainty, revisiting them as conditions change rather than defending them indefinitely Raise the security design capability of the wider organization through mentoring, review, and reusable patterns Minimum QualificationsBachelor’s degree in Computer Science, Information Security, Engineering, or related field (or equivalent practical experience) 8+ years in information security with at least 4 years in a dedicated security architecture or senior security engineering role Demonstrated experience architecting security for both on-premises infrastructure and public cloud at enterprise scale Hands-on architectural depth in both Microsoft Azure and Amazon Web Services — identity, networking, encryption, and native security services in each Working fluency with ISO/IEC 27001 and Annex A controls as an architectural framework, including practical application of ISO/IEC 27017 and 27018 to cloud designs Familiarity with ISO/IEC 42001 and the AI security threat landscape, with experience designing controls for AI or machine learning systems Understanding of OT and industrial control system architecture, including ISO/IEC 27019, IEC 62443, or NIST SP 800-82 concepts Experience with physical security systems and the integration of physical and logical access control Strong identity architecture skills — Active Directory, Entra ID, SAML and OIDC federation, privileged access management, and non-human identity models Network security design depth — segmentation, zero trust architecture, firewalls, proxies, and secure connectivity across hybrid environments Proficiency with threat modeling methodologies (STRIDE, PASTA, attack trees) and the ability to produce clear architectural documentation and diagrams Strong written and verbal communication — able to defend a design to engineers and explain the same decision to executives Preferred QualificationsExperience with: Manufacturing, chemical, energy, or other process industry environments Infrastructure-as-code and policy-as-code (Terraform, Bicep, CloudFormation, OPA, Sentinel) Secure software development lifecycle, application security, and CI/CD pipeline security Data security architecture — classification, DLP, tokenization, and data governance platforms Third-party and supply chain risk architecture, including SBOM and vendor integration patterns Global operations across multiple regulatory jurisdictions (GDPR, CCPA, NIS2, or similar) Certifications (any of the following valued): CISSP or CISSP-ISSAP (Information Systems Security Architecture Professional) SABSA, TOGAF, or equivalent architecture credential Azure Solutions Architect Expert or Azure Security Engineer Associate AWS Solutions Architect Professional or AWS Certified Security – Specialty GICSP, ISA/IEC 62443 Cybersecurity Specialist, or equivalent OT credential ISO/IEC 27001 Lead Implementer or ISO/IEC 42001 Lead Implementer CCSP, PSP (Physical Security Professional), or AI security credentials Work Environment & TravelThis is a remote-first position with periodic travel to Hexion manufacturing facilities, data center and colocation sites, and partner or vendor engagements as required (~15–20%). Site visits are an expected part of the role — OT and physical security architecture cannot be designed entirely from a network diagram. OtherWe are an Equal Opportunity, Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to gender, minority status, sexual orientation, gender identity, protected veteran status, status as a qualified individual with a disability or any characteristic protected by law.In order to be considered for this position candidates are required to submit an application for employment through our career site, be at least 18 years of age, willing to take a drug test , submit to a background investigation as part of the selection process, as well as additional periodic background checks as required by the Chemical Facility Anti-Terrorism Standards (CFATS) or regulations adopted by the Department of Homeland Security or other regulatory agenciesCandidates are required to have unrestricted authorization to work in the United States.If currently an employee of the Company, you must have current satisfactory work performance and in most cases, have been in your current role 18 months.Disclaimer: We are not accepting unsolicited assistance from search firms/employment agencies for this employment opportunity. Please, no phone calls or emails to any employee about this position. All resumes submitted by search firms/employment agencies to any employee of the Company via email, the Internet or in any other form and/or method without a valid written search firm agreement in place for this position will be deemed the sole property of the Company; no fee will be paid in the event a candidate is hired by the Company as a result of the unsolicited referral or through other means.
- About this role:Wells Fargo is seeking a Lead Systems Architect - Application Security to join the Security Architecture organization. This role will provide security architecture leadership across application development, APIs, DevSecOps, and emerging technologies, helping...SuggestedFull timeWork experience placement
$77 - $88 per hour
...Security Solution Architect Location: Columbus, OH Work Model: Hybrid — Tuesday through Thursday onsite, Monday and Friday remote Rate: $77–$88/hour Contract Term: August 17, 2026 – August 13, 2027 Contract-to-Hire: Yes Employment Type: W-2 Only...SuggestedContract workWork experience placementLocal areaRemote workVisa sponsorshipMonday to Friday$130.4k - $187.6k
...a brighter, more sustainable future while tackling the most pressing challenges of the 21st century.We are looking for an OT Security Architect to join our team in one of today’s most exciting technologies. This role will report to Chief Security Officer based in Newark...SuggestedFull timeWork at officeRemote workWorldwide- ...Berkley Corporation and its operating units. The company focuses on secure, modern, and scalable technology capabilities that enable the... ...opportunity employer. Responsibilities The Principal Architect & Program Lead is responsible for defining, governing, and delivering...Suggested
- ...~ Location: 100% Remote. -Security Architect - Consultant 9309 . Employment Type: W2 Only (No Subcontractors)Contract Duration: 12-Month Contract Our direct client is seeking an experienced This client is located in Columbia, SC. 5+ years of experience and expert...SuggestedContract workWork experience placementFor subcontractorRemote work
$100k - $150k
...career growth potential. Job Title: Enterprise Integration Architect Location: 100% Remote (U.S.) Position Type: Full-time,... ...~ Strong understanding of identity, OAuth, and integration security. ~ Salesforce Certified Integration Architect credential....Full timeH1bLocal areaImmediate startRemote work$214.51k
...world. Job Description CDM Smith is seeking a Senior Enterprise Architect to join our Corporate Business Technology team. This role is... ...reusable patterns that connect business capabilities with scalable, secure, and integrated technology solutions. This individual will...Work experience placementH1bRemote work$123.4k - $176.3k
...coordinate stakeholders and enable business change, with consideration of application, information, technology and security architecture. A Senior Enterprise Architect is a strategic technology leader who aligns enterprise architecture with Cardinal Health's business...Full timeTemporary workWork experience placementLocal areaImmediate startRemote workWork from homeFlexible hours- ...every day. We turn ideas into reality.Accenture SecurityAccenture Security delivers continuous, rapid-fire innovation and new business... ...currently looking for professionals for our Security Solution Architect team with extensive experience in the following:·Proven...Full timeWork experience placementLive inWork at officeLocal area
$70 - $80 per hour
...Job Description Job Description Overview CTG is seeking to fill a SAP S/4HANA Finance Enterprise Architect position for our client. Location: Columbus, OH Duration: 8 months Duties: Lead SAP S/4HANA Finance architecture and transformation programs...- ...Network Security Engineer Anywhere Type: Consulting Category: Development Industry: Other Workplace Type: Remote Standard Hours: Open Reference ID: JN -092026-108525 Date Posted: 09/08/2026 Shortcut: Description Recommended Jobs...Hourly payLocal areaRemote workWeekend workAfternoon shift
$120k - $140k
...Overview GovCIO is seeking a highly experienced Senior Network & Security Engineer to lead the design, operation, troubleshooting, and... .../OT devices, data-center workloads, and cloud resources. Architect, configure, test, and troubleshoot Palo Alto High Availability...Full timeRemote workFlexible hours- ...Network Security Engineer The Network Security Engineer (DC and Cloud) is responsible for ensuring the security, stability, and integrity of our organization's network infrastructure, with a dual focus on both data center (DC) and cloud environments. This role involves...Work experience placement
- ...Job Description Job Description Title: Enterprise Data Architect Reports to: Chief Technology Officer Supervises: Business... ...studies, and other tasks Creates strategies and plans for data security, backup, disaster recovery, business continuity, and archiving...Temporary workWork experience placementRemote work
- DescriptionTitle: Senior Infrastructure, Security & Operations Architect Location: New Albany, OhioJob Type: Full TimeMake a Difference—And Own Your Future Join Wallick, a 100% employee-owned company with over 55 years of experience in providing affordable housing and...Work at office
$128.4k - $192.6k
Senior Security Engineer - IS07FEWe’re determined to make a difference and are proud to be an insurance company that goes well beyond... ...solutions using AWS cloud services, following cloud-native, well‑architected, and security principles.Apply hands-on AI/ML capabilities (...Full timeTemporary workWork at office3 days per week$128k - $216k
...connect financial institutions, corporations, merchants and consumers to one another millions of times a day - quickly, reliably, and securely. Any time you swipe your credit card, pay through a mobile app, or withdraw money from the bank, we're involved. If you want to...Full timeContract workTemporary workH1b$126k - $188k
...helping protect Indeed's applications and services by identifying security risks early, partnering closely with product and engineering... ...security issues in Indeed's systems and processes. Evaluate, architect, build, monitor and support security infrastructure for use by...Work experience placementLocal areaRemote work$40k
Maximus is a trusted federal partner supporting mission-critical programs across national security, defense, and public service delivery. Our work focuses on sustaining, operating, and improving essential government systems and services, with proven operational excellence...Contract workRemote work$61k - $101k
...Salary: $61,000 - 101,000 per year Requirements: We expect formal training or certification in security engineering concepts, along with 5+ years of applied experience. We require 7+ years of hands-on engineering experience with Hardware Security Modules, including...Full time- ...Vision insurance SarelaTech is seeking a Cybersecurity Engineer to support the Defense Logistics Agency (DLA) Enterprise Cyber Security Service Provider (CSSP). The selected candidate will provide technical expertise in the development, implementation, and...
- Responsibilities Build an identity engine that powers the whole company and supercharges our security program Create applications that enable and enforce our identity framework across the company Develop integrations that unify identities across IdPs, cloud providers,...
- ...Business consulting services. We are in search of a highly motivated candidate to join our talented Team. Job Title: Enterprise Architect Location(s): Wilmington, DE Job Description:A Enterprise Architect within the Global Issuer organization is laser-focused on go...Interim role
$70 - $79 per hour
...Job Title: Senior Security Engineer – Web Application & Network Protection (Contract to Hire) Location: Columbus, OH (Local Candidates only) Rate: $70–$79/hour Work Model: Hybrid (Onsite Tuesday–Thursday, Remote Monday & Friday) Contract Length: July 27,...Contract workLocal areaRemote workVisa sponsorshipMonday to Friday$139.8k - $223.7k
...tools and support to create your own success story. Be challenged. Be heard. Be valued. Be you ... be here.Job SummaryThe Staff Cyber Security Engineer is a senior individual contributor who will provide technical leadership in the design and advancement of cyber security...Full timeTemporary workWork at officeLocal areaImmediate startRemote workWork visaFlexible hours- ...Title: IAC Security Engineer Location: Charlotte, NC, Irving, TX, Minneapolis, MN, Chandler, AZ, Des Moines, IA, Columbus, OH, Raleigh, NC, San Antonio, TX, Washington (3 days onsite/2 Days Remote) Contract Duration: 12 months LinkedIn should be 5-6 years...Contract workRemote work
- Senior Enterprise Architect Location: Santa Clara CA, Bridgewater Township NJ, Princeton NJ, Charlotte, NC, Bellevue WA, Plano, TX, Dublin... ...implementation, and risk mitigation. Architect scalable, secure, and resilient data platforms using cloud-native and hybrid patterns...
- Physical Security Systems Engineer Columbus, OH - try for local candidates or who can relocate is ok- remote is last option but not closed option Deep hands-on experience with at least one enterprise PACS on your shortlist (Genetec, LenelS2 OnGuard, C•CURE 9000, or Pro...Local areaRemote workRelocation
$110k - $179k
About this role:Wells Fargo is seeking a Senior Information Security Engineer to join our Application Security Team.In this role, you will:Design and implement repeatable, scalable, and automated AppSec processesProvide hands-on technical leadership in tooling integration...Full timeWork experience placement$61k - $101k
...agile practices, including CI/CD, application resiliency, and security. We are seeking knowledge of software applications and technical... ...concepts, or custody workflows. We need experience architecting and building solutions with AWS cloud services. We are looking...Full time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Architect. Be the first to apply!



