We are looking for an Enterprise Security Architect to join AlphaSense's Corporate Technology organization. Reporting directly to the VP of Secure IT, this is a senior individual contributor role responsible for defining and driving the security architecture strategy across our entire enterprise technology landscape — spanning Zero Trust, identity, network, SaaS, endpoint, internal infrastructure, mobile, and operational technology.
You won't be handed a finished program. You will design it. Working at the intersection of security engineering, enterprise architecture, and business strategy, you will establish the frameworks, reference architectures, and technical standards that govern how AlphaSense builds and operates its technology environment securely at scale.
At the Staff level, you will:
- Own the architecture: Define and maintain the enterprise security architecture across Zero Trust, identity, network, endpoint, SaaS, infrastructure, mobile, and OT domains.
- Set the standard: Author and govern security architecture principles, reference designs, and technical standards adopted across the organization.
- Lead without authority: Drive alignment across Security Operations, Corporate Technology, Information Engineering, and Integrated IT teams through technical credibility and structured decision-making.
- Anticipate risk: Identify architectural gaps and emerging threat vectors before they become incidents, and prescribe remediation roadmaps.
- Accelerate programs: Provide architecture leadership for strategic security initiatives including Zero Trust maturity, identity consolidation, SaaS governance, and device trust.
Responsibilities:
- Zero Trust & Network Security Architecture: Define and own the Zero Trust and Device Trust architecture strategy, including network segmentation, ZTNA policy design, and enforcement model across corporate and remote environments. Architect Cloudflare WARP/Access and equivalent controls. Design network security architecture for office and data center environments including Meraki SD-WAN, firewall policy, 802.1X, and DNS security.
- Identity & Access Architecture: Own the enterprise identity architecture spanning Okta, SAML/OIDC federation, SCIM provisioning, MFA, Privileged Access Management (PAM), and lifecycle governance. Design device trust and certificate-based authentication frameworks integrating MDM (Kandji, Intune), Okta FastPass, TPM/Secure Enclave.
- Endpoint & Mobile Security Architecture: Define the enterprise endpoint security architecture across macOS, Windows, and mobile platforms, including EDR (CrowdStrike Falcon), MDM policy standards, and patch management architecture.
- SaaS & Cloud Security Architecture: Define the SaaS security architecture program: vendor risk tiering, security review criteria, integration security standards, and ongoing posture monitoring frameworks. Architect CASB, SSPM, and SaaS access governance controls.
- Internal Infrastructure Security Architecture: Define security architecture standards for on-premise and cloud-hosted internal infrastructure including IDF/MDF environments, server rooms, physical access control systems (Brivo), and AV infrastructure.
- Operational Technology (OT) Security: Develop OT security architecture standards for physical and building systems including access control hardware, environmental sensors, and network-connected facility equipment.
- Architecture Governance & Engineering Enablement: Maintain a living enterprise security architecture document and domain-level reference architectures. Conduct security architecture reviews for new technology programs and vendor onboarding.
Qualifications:
Required:
- 8+ years of experience in information security with at least 4 years in a security architecture, security engineering lead, or equivalent senior technical role.
- Demonstrated expertise designing and implementing Zero Trust architectures in enterprise environments, including ZTNA, identity-aware access, and microsegmentation.
- Deep knowledge of identity and access management — Okta (or equivalent), SAML, OIDC, SCIM, MFA, PAM, and certificate-based authentication.
- Strong endpoint security architecture experience across macOS and Windows, including EDR (CrowdStrike preferred), MDM (Kandji/Intune), and patch management.
- Experience architecting SaaS security programs including vendor risk frameworks, CASB/SSPM tooling, and OAuth/API integration controls.
- Solid understanding of network security architecture: firewalls, SD-WAN, 802.1X, DNS security, and network segmentation principles.
- Familiarity with OT/IoT security architecture concepts.
- Proven ability to produce high-quality security architecture documentation including reference architectures, design patterns, and ADRs.
- Strong communicator capable of presenting complex security topics to both technical peers and senior non-technical stakeholders.
Nice to Have:
- Professional certifications: CISSP, SABSA, CCSP, or equivalent architecture/security credentials.
- Experience operating in a post-M&A environment with multi-tenant identity and infrastructure consolidation challenges.
- Familiarity with Cloudflare Access/WARP, Meraki, CrowdStrike Falcon, Kandji, Qualys VMDR, or Drata/GRC tooling.
- Experience designing AI governance and shadow SaaS controls for enterprise environments.
- Background working in a regulated industry or supporting compliance frameworks (SOC 2, ISO 27001, FedRAMP).
8+ years of experience in information security, 4+ years in a security architecture, security engineering lead, or equivalent senior technical role, Expertise in designing and implementing Zero Trust architectures (ZTNA, identity-aware access, microsegmentation), Deep knowledge of IAM: Okta, SAML, OIDC, SCIM, MFA, PAM, and certificate-based authentication, Strong endpoint security architecture experience (macOS, Windows, EDR/CrowdStrike, MDM/Kandji/Intune), Experience architecting SaaS security programs (vendor risk frameworks, CASB/SSPM, OAuth/API controls), Solid understanding of network security: firewalls, SD-WAN, 802.1X, DNS security, and segmentation, Familiarity with OT/IoT security architecture concepts, Ability to produce high-quality architecture documentation (reference architectures, design patterns, ADRs), Strong communication skills for technical and non-technical stakeholders