Security Architect
Brooksource
Denver, New York, or Los Angeles - Hybrid
Contract-to-Hire
The Lead Security Engineer / Architect is the firm’s principal technical authority for information security and the Chief Information Security Officer’s most trusted technical partner. The role owns the technical blueprint that protects the firm’s and our clients’ confidential information.
This is a high-visibility, high-trust position for a seasoned practitioner ready to operate as the firm’s go-to technical expert across detection engineering, incident response, and security architecture. Working in close partnership with the CISO, you will shape the firm’s technical roadmap, lead the engineering execution behind the security strategy, and influence how the firm uses its security investments.
If you are energized by the prospect of serving as the principal architect and lead technical defender for an organization where confidentiality is non-negotiable, and you want a role where your judgment carries weight at the leadership table alongside the CISO, we would like to meet you.
Key Responsibilities
Security Architecture and Strategy
- Provide architectural oversight across the firm’s security stack, ensuring that identity, endpoint, network, data, and cloud controls are designed and implemented coherently and in line with best practices.
- Own the design, deployment, and continuous improvement of security controls and capabilities across Microsoft Entra ID, Conditional Access, Microsoft, Azure, and the broader Microsoft Defender suite (Endpoint, Identity, Cloud, Cloud Apps), driving appropriate utilization of the broader Microsoft security suite so that the firm consistently realizes the full value of its licensed protections and stays at the leading edge of Microsoft’s evolving security platform.
- Serve as the CISO’s primary technical advisor on security design, investment, and risk decisions; partner on business case development and contribute to executive presentation of major initiatives.
- Lead the technical evaluation of security technologies, including proof-of-concept design and vendor assessment, and develop recommendations that inform the CISO’s decisions on the firm’s security stack.
- Partner with infrastructure, identity, and application teams to embed security into every project lifecycle, leading design reviews, threat modeling, and risk-based recommendations.
Detection and Response Engineering
- Own the detection engineering lifecycle in the firm’s enterprise SIEM platform: develop, tune, and retire analytics rules; build and refine workbooks; and curate connectors and data sources to ensure high-fidelity visibility across the environment.
- Design and thoughtfully implement User and Entity Behavior Analytics (UEBA) capabilities, baselining normal activity for users, service accounts, and entities, and tuning anomaly detections to surface meaningful risk while minimizing analyst fatigue.
- Set the strategy for SIEM log onboarding, parsers, filters, and ingestion pipelines; balance signal fidelity against cost, and align telemetry with detection priorities.
- Build and curate advanced KQL libraries, hunting notebooks, and automations (Logic Apps, playbooks, SOAR-style workflows) that elevate the entire team’s capability and accelerate triage, enrichment, and response.
- Continuously benchmark detection coverage against current adversary tradecraft, with particular emphasis on threats targeting law firms and professional services organizations.
Threat Hunting and Threat Intelligence
- Lead the firm’s proactive, hypothesis-driven threat hunting program: define methodology, set cadence, and own outcomes across endpoints, identity, email, cloud workloads, and SaaS, leveraging Sentinel, Defender XDR Advanced Hunting, and other tools.
- Serve as the firm’s authority on adversary behavior relevant to legal services, translating industry, sector, and geopolitical threat intelligence into actionable detections, hunts, and architectural improvements.
- Mature the firm’s threat hunting program over time, ensuring documented hypotheses, tracked coverage gaps, and a durable feedback loop into detection engineering and architecture.
Incident Response and Resolution
- Serve as the lead technical responder during significant security incidents, directing investigation, containment, eradication, and recovery activities under the CISO’s overall incident leadership and in close partnership with IT leadership, outside counsel, and external IR partners as appropriate.
- Lead deep-dive forensic analysis across Microsoft 365, Entra ID, Azure, endpoints, email, and network telemetry; reconstruct attacker activity; and produce clear, defensible findings suitable for executive, legal, and client audiences.
- Author and maintain the firm’s incident response playbooks; co-lead executive tabletop exercises and after-action reviews with the CISO; and ensure lessons learned become durable engineering and architectural improvements.
Identity, Access, and Data Protection
- Lead the technical execution of the firm’s identity security strategy, guiding architectural decisions across Entra ID, including Conditional Access, Privileged Identity Management, Identity Protection, and risk-based authentication, all aligned to a Zero Trust strategy.
- Partner on the design and operation of data protection controls such as Microsoft Purview information protection, DLP, insider risk management, and eDiscovery considerations appropriate for a law firm environment.
- Drive secure configuration baselines for Microsoft 365 and Azure workloads, including CIS, Microsoft Secure Score, and firm-specific hardening standards.
Program Leadership and Mentorship
- Serve as the senior technical voice within the security team; mentor analysts and engineers, raise the bar on detection, hunting, and response, and contribute to hiring decisions for the function.
- Support the CISO in client security reviews, third-party audits, and regulatory inquiries; act as the firm’s primary technical voice during high-stakes external engagements.
- Help shape the firm’s security culture through clear, credible, and confident communication with non-technical audiences.
Qualifications
- Ten or more years of progressive experience in information security, including substantial time as a senior individual contributor in security engineering, detection engineering, or threat analysis roles.
- Relevant certifications are valued and, in some cases, may substitute for portions of the experience requirements. Strong candidates will typically hold one or more of the following: CISSP, GCIH, GCDA, GCFA, OSCP, and/or related Microsoft certifications such as SC-100/200/300 and AZ-500.
- A documented track record of leading security architecture and detection engineering initiatives end-to-end with measurable improvements to an organization’s security posture.
- Deep, hands‑on mastery of the Microsoft enterprise security stack, including Entra ID, Conditional Access, Microsoft 365, Azure, Microsoft Sentinel, and the Microsoft Defender suite.
- Demonstrated experience setting detection engineering strategy in a modern SIEM, including authoring and tuning high‑fidelity analytics rules, implementing and tuning UEBA, and managing log sources and ingestion economics at scale; advanced proficiency with KQL is required.
- Proven experience serving as the lead technical responder or incident commander on significant security incidents, including investigations spanning cloud identity, email, endpoints, and SaaS.
- Fluency with adversary tradecraft and frameworks including MITRE ATT&CK, the cyber kill chain, and Zero Trust architectural principles.
- Recognized strength across core security architecture domains: identity, endpoint, network, email, data protection, and cloud security.
- Scripting and automation depth in PowerShell and at least one general‑purpose language (Python preferred) for detection, enrichment, response, and analytics workflows.
- Sound judgment, discretion, and the ability to handle highly confidential client and firm information with care.
- Exceptional written and verbal communication skills.
EEO Statement:
Brooksource is an equal opportunity employer that does not discriminate on the basis of actual or perceived race, color, creed, religion, national origin, ancestry, citizenship status, age, sex or gender (including pregnancy, childbirth, lactation and related medical conditions), gender identity or gender expression, sexual orientation, marital status, military service and veteran status, physical or mental disability, protected medical condition as defined by applicable state or local law, genetic information, or any other characteristic protected by applicable federal, state, or local laws and ordinances.
Benefits & Perks: Brooksource offers competitive medical, dental, vision, Health Savings Account, Dependent Care FSA, and supplemental coverage with plans that can fit each employee’s needs. We offer a 401k plan that includes a company match and is fully vested after you become eligible, paid time off, sick time, and paid company holidays. We also offer an Employee Assistance Program (EAP) that provides services like virtual counseling, financial services, legal services, life coaching, etc.
Pay Disclaimer:
The pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
#J-18808-Ljbffr$143.25k - $179.04k
...trust, teamwork, and opportunity at OD. As the Cybersecurity Architect at Old Dominion Freight Line, you will play a critical role in... ...strategies, provide expert guidance on technical security solutions, and ensure the effective implementation of security...SuggestedFull timeTemporary workWork experience placementLocal areaImmediate startShift workDay shift$140k
...Seekers can review the Job Applicant Privacy Policy by clicking here ( . Job Description : Job Description The Network Security Architect will design and build the network security architecture our environment runs on, from firewall and segmentation design...SuggestedFull timeWork at office$112.9k - $338.3k
...of lives every day. We turn ideas into reality. Accenture Security Accenture Security delivers continuous, rapid-fire innovation... ...currently looking for professionals for our Security Solution Architect team with extensive experience in the following:· Proven...SuggestedFull timeWork experience placementLive inWork at officeLocal area- ...of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us! The Senior Security Architect serves as one of the lead technical architects for strategic Security Operations & Threat Response initiatives and is responsible...SuggestedWork at officeFlexible hoursShift workDay shift
- ...Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us! AI Security Standards Architect Key Responsibilities: • Define and lead the AI security strategy, including standards, to secure AI/ML systems across...SuggestedWork at officeFlexible hoursShift workDay shift
- ...least one in-person interview, which may include a live whiteboarding or technical assessment session. EchoStar requires robust security across its digital ecosystem to mitigate risks associated with unauthorized access, supply chain exposure, and identity...Local areaFlexible hours
$156k - $187k
...Start date: May 19, 2026. About The Role The Enterprise Architect defines and evolves our enterprise technology strategy to support... ...‑driven energy production business. This role shapes scalable, secure, and cost‑effective platforms that enable growth, operational...Temporary work$133.56k - $165k
...that keep the business running. We are looking for an Enterprise Architect to be the design authority across three pillars-Data... ...pillars, aligned to business strategy, IT cost objectives, and the security strategy. Publish and apply reference architectures, design patterns...Full timeTemporary workLocal area$160k - $210k
...Overview Title: Senior Enterprise Architect - Databricks & Multi-Cloud Location: Denver, CO - In the office 4 days a week - Must currently reside in Denver, CO area Duration: Direct Hire Compensation Range (pending experience): Base Salary $160k-210k +...Work at office$165k - $185k
...About The Role We’re looking for an experienced Enterprise Architect to play a critical role in shaping the future-state architecture... ...partnering with senior stakeholders to drive practical, scalable, and secure solutions. What You’ll Do Define enterprise...Relocation$80.4k - $266.3k
...and transformations, helping them creating and delivering next generation solutions. We are looking for experienced Enterprise Architects with strong delivery experience and deep understanding of how new technologies and the emerging new delivery approaches and...Full timeWork experience placementLive inWork at officeLocal area- ...Network Security Engineer LOCATION Aurora, CO 80014 CLEARANCE TS/SCI Full Poly (Please note this position requires full U... ...Network Security Administrator, Cyber Defense Analyst, Security Architect, Penetration Tester, etc. DEGREE (Level Desired) Bachelor...Temporary workFor contractorsImmediate startFlexible hours
$140k
...professional who excels in communication and cross-functional collaboration. The ideal candidate will possess a deep understanding of modern security practices and technologies, combined with a service-focused attitude and the ability to work independently in a fast-paced setting...Full timeWork at officeLocal areaMonday to FridayFlexible hours- ...Security Engineer / Architect — Identity, Authorization & Platform Security Location: Denver, CO — 100% Onsite Job Type: Contract Duration: Contract / Long-Term Engagement Position Overview We are seeking a hands-on Security Engineer / Architect...Contract work
$109.19k - $163.78k
...The Cybersecurity Engineeris responsible forsupporting the protection and security of critical systems and data related to the City’s technology infrastructure, business systems, and water management and distribution environments. The position works closely with Information...Work experience placementLocal area- ## Cyber Security Engineer IIIApply: Denver, CO: Greater Seattle Area: Full time: Posted 3 Days Ago: R71998Application close date:Applications will be accepted on an ongoing basis until the requisition is closed.At Blue Origin, we envision millions of people living and...Permanent employmentFull timeTemporary workWork experience placementLocal areaRemote work
$180k - $220k
...ForeFlight builds mission‑critical navigation and aviation data software used by pilots and operators worldwide. As Principal Security Architect, you’ll own the technical security strategy across our enterprise IT and SaaS environments, partnering closely with...Immediate startRemote workWorldwide- ...experience, skills, and education among other factors. In addition, this position is eligible for an incentive bonus. The Sr. Cyber Security Engineer will lead the design, implementation, administration, and support of complex enterprise security initiatives across Johns...Temporary workRemote workFlexible hours
$140k
...communicator with executive presenceable to tailor messaging for admins, architects, and senior business stakeholders. ~ Brings deep domain... ...but not required. Technical certifications (e.g., CISSP, Security+, cloud architecture) are a plus. About Us NinjaOne...Full timeRemote workWork from homeRelocationFlexible hoursShift work- ...System Security Engineer LOCATION Aurora, CO 80014 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.... ...Security Engineer, Incident Response Engineer, Secure Systems Architect, Security Automation Engineer, etc. DEGREE (Level Desired)...Temporary workFor contractorsImmediate startFlexible hours
- ...interesting challenges, innovative minds, and emerging technologies.Title: Enterprise - ServiceNow SAM ArchitectWhat You'll Do:As a SAM Architect, you will serve as a subject matter expert and thought leader for ServiceNow Software Asset Management (SAM) engagements and pre-...Contract workTemporary workLocal areaFlexible hours
- ...Description ARES has an exciting new opportunity for an Enterprise Architect for the Engineering, Professional, and Administrative Support... ...; and/or ensuring the rigorous application of information security/cybersecurity policies, principles, and practices to all...Full timeContract workFor contractorsWork at officeLocal areaRemote work
$148k - $235.75k
...A leading technology company is looking for a Senior Systems Software Security Engineer in Denver, Colorado. This role involves delivering essential security features for Data Center systems, engaging with teams to drive implementations, and innovating security solutions...$155k - $180k
...talented subject matter experts, work on complex projects, and contribute to the value Chatham delivers every day. We are seeking a Security Engineering Manager to lead and evolve our security engineering function within a growing financial risk and advisory SaaS...Immediate startShift work$90k - $125k
...Application Security EngineerNelnet is a diversified and innovative company committed to enriching lives through the power of service as a student loan servicer, professional services company, consumer loan originator and servicer, payments processor, renewable energy...Contract workTemporary workLocal area$121k - $148.9k
...inclusion Recognize a fellow associate through our GEM awards Job Description Join CoBank's high-performing Application Security team and help protect the applications, cloud services, and data that support our business. You will collaborate with engineering...Work experience placementWork at officeWork visaFlexible hours$150k - $185k
...hour at peak. Job Description As an Enterprise Software Architect you will be responsible for the ongoing design of our... ...Management and Technical Leadership teams, ensuring alignment and securing organizational buy-in. Providing rigorous support and governance...Hourly payLocal areaWorldwideShift work$175k - $225k
...process. About the Role: As the Enterprise Applications AI Architect, you will lead the integration of AI and automation across... ...context aware, and self improving platforms, while ensuring security, compliance, and measurable impact. This role combines hands-...Remote jobFull timeWork at officeLocal areaShift work2 days per week3 days per week- ...and change the world.To be eligible for this position, you must be a U.S. Citizen. This position requires an active U.S. Government security clearance, applicants who do not currently hold the required clearance will not be eligible for consideration. Employment for...
- ...Security EngineerAt PNC, our people are our greatest differentiator and competitive advantage in the markets we serve. We are all united... ...by default. You will interact and engage with PNC Cloud Architects and PNC's SOC team to understand potential vulnerabilities and...Shift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Architect. Be the first to apply!

