Senior Enterprise Security Architect

AlphaSense Oy

Delhi

On-site

INR 2,500,000 - 4,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

AlphaSense Oy is seeking a Senior Enterprise Security Architect to define and drive security architecture strategy across the corporate technology landscape. You will own frameworks, reference architectures, and standards, guiding security programs from Zero Trust to device trust and identity across on‑prem and cloud environments.

You will influence executive stakeholders and partner with Security Operations, IT, and business teams to deliver secure, scalable solutions at enterprise scale.

Qualifications

  • 8+ years of information security experience.
  • Proven expertise designing and implementing Zero Trust architectures in enterprise environments.
  • Deep knowledge of identity and access management (Okta, SAML/OIDC, MFA, PAM).
  • Strong endpoint security architecture experience (EDR, MDM).
  • Experience architecting SaaS security programs (CASB/SSPM, OAuth/API controls).
  • Strong communication skills for technical and non-technical stakeholders.

Responsibilities

  • Define and own the Zero Trust and Device Trust architecture strategy across corporate and remote environments.
  • Architect cloud and on‑prem security designs including identity, network, and SaaS controls.
  • Lead architecture governance, ADRs, and security design patterns for reuse across programs.
  • Influence executive stakeholders and collaborate with Security Operations, IT, and business teams.

Skills

Zero Trust
IAM
EDR
MDM
SaaS Security
Cloud Security

Tools

Okta
SAML/OIDC
SCIM
MFA
PAM
CrowdStrike Falcon
Kandji
Intune
Meraki
Cloudflare Access/WARP

Job description

We are looking for an Enterprise Security Architect to join AlphaSense's Corporate Technology organization. Reporting directly to the VP of Secure IT, this is a senior individual contributor role responsible for defining and driving the security architecture strategy across our entire enterprise technology landscape — spanning Zero Trust, identity, network, SaaS, endpoint, internal infrastructure, mobile, and operational technology.

You won't be handed a finished program. You will design it. Working at the intersection of security engineering, enterprise architecture, and business strategy, you will establish the frameworks, reference architectures, and technical standards that govern how AlphaSense builds and operates its technology environment securely at scale.

This role requires deep technical expertise paired with the ability to influence executive stakeholders, shape cross-functional programs, and operate as a force multiplier across Security Operations, Integrated IT, Information Engineering, and the business.

At the Staff level, you will:
  • Own the architecture: Define and maintain the enterprise security architecture across Zero Trust, identity, network, endpoint, SaaS, infrastructure, mobile, and OT domains.
  • Set the standard: Author and govern security architecture principles, reference designs, and technical standards adopted across the organization.
  • Lead without authority: Drive alignment across Security Operations, Corporate Technology, Information Engineering, and Integrated IT teams through technical credibility and structured decision‑making.
  • Anticipate risk: Identify architectural gaps and emerging threat vectors before they become incidents, and prescribe remediation roadmaps.
  • Accelerate programs: Provide architecture leadership for strategic security initiatives including Zero Trust maturity, identity consolidation, SaaS governance, and device trust.
Responsibilities
Zero Trust & Network Security Architecture
  • Define and own the Zero Trust and Device Trust architecture strategy, including network segmentation, ZTNA policy design, and enforcement model across corporate and remote environments.
  • Architect Cloudflare WARP/Access and equivalent controls for secure remote access, replacing legacy VPN patterns with identity-aware, context-driven enforcement.
  • Design network security architecture for all office and data center environments including Meraki SD-WAN, firewall policy, 802.1X, and DNS security.
  • Establish architecture standards for microsegmentation, East-West traffic inspection, and lateral movement prevention.
Identity & Access Architecture
  • Own the enterprise identity architecture spanning Okta, SAML/OIDC federation, SCIM provisioning, MFA, Privileged Access Management (PAM), and lifecycle governance across AlphaSense and Tegus tenants.
  • Design device trust and certificate-based authentication frameworks integrating MDM (Kandji, Intune), Okta FastPass, TPM/Secure Enclave, and hardware-bound credentials.
  • Define role-based access control (RBAC) architecture and Joiner-Mover-Leaver (JML) automation patterns for consistent enforcement across 200+ enterprise applications.
  • Architect identity federation patterns for M&A integrations, third‑party partners, and customer‑facing systems.
Endpoint & Mobile Security Architecture
  • Define the enterprise endpoint security architecture across macOS, Windows, and mobile platforms, including EDR (CrowdStrike Falcon), MDM policy standards, and patch management architecture.
  • Design mobile device management architecture for corporate and BYOD scenarios, establishing enrollment profiles, compliance policies, and conditional access integration.
  • Establish architecture standards for endpoint hardening, application allow‑listing, DLP controls, and removable media policy.
  • Provide architectural oversight for RMM tooling and remote management capabilities, ensuring security boundaries and abuse‑resistance controls are embedded by design.
SaaS & Cloud Security Architecture
  • Define the SaaS security architecture program: vendor risk tiering, security review criteria, integration security standards, and ongoing posture monitoring frameworks.
  • Architect CASB, SSPM, and SaaS access governance controls to ensure visibility and enforcement across the business application portfolio.
  • Establish data classification and DLP architecture for SaaS environments including Google Workspace, Microsoft 365, Salesforce, and Workday.
  • Design AI/shadow SaaS governance architecture, including browser isolation, OAuth scope enforcement, and sanctioned AI tooling controls.
Internal Infrastructure Security Architecture
  • Define security architecture standards for on‑premise and cloud‑hosted internal infrastructure including IDF/MDF environments, server rooms, physical access control systems (Brivo), and AV infrastructure.
  • Architect logging, SIEM integration, and telemetry collection frameworks ensuring consistent visibility across infrastructure, identity, network, and endpoint layers.
  • Design disaster recovery and resilience architecture for critical corporate infrastructure, including offline backup strategies and clean‑room recovery playbooks.
Operational Technology (OT) Security
  • Develop OT security architecture standards for physical and building systems including access control hardware, environmental sensors, and network‑connected facility equipment.
  • Define segmentation and monitoring architecture to isolate OT environments from corporate IT networks, reducing blast radius and unauthorized access risk.
  • Establish a vulnerability management framework for OT assets, accounting for patching constraints and availability requirements unique to operational environments.
Architecture Governance & Engineering Enablement
  • Maintain a living enterprise security architecture document and domain‑level reference architectures, keeping them current with technology changes and threat landscape evolution.
  • Conduct security architecture reviews for new technology programs, vendor onboarding, and significant infrastructure changes — providing actionable guidance rather than just approval/denial.
  • Define security requirements and acceptance criteria for strategic projects in partnership with Product Security, Engineering, and Corporate Technology.
  • Produce architecture decision records (ADRs) and security design patterns that teams can reuse, reducing review cycle time and engineering rework.
Qualifications
Required
  • 8+ years of experience in information security with at least 4 years in a security architecture, security engineering lead, or equivalent senior technical role.
  • Demonstrated expertise designing and implementing Zero Trust architectures in enterprise environments, including ZTNA, identity‑aware access, and microsegmentation.
  • Deep knowledge of identity and access management — Okta (or equivalent), SAML, OIDC, SCIM, MFA, PAM, and certificate‑based authentication.
  • Strong endpoint security architecture experience across macOS and Windows, including EDR (CrowdStrike preferred), MDM (Kandji/Intune), and patch management.
  • Experience architecting SaaS security programs including vendor risk frameworks, CASB/SSPM tooling, and OAuth/API integration controls.
  • Solid understanding of network security architecture: firewalls, SD‑WAN, 802.1X, DNS security, and network segmentation principles.
  • Familiarity with OT/IoT security architecture concepts and the challenges of securing non‑traditional network‑connected assets.
  • Proven ability to produce high‑quality security architecture documentation including reference architectures, design patterns, and ADRs.
  • Strong communicator capable of presenting complex security topics to both technical peers and senior non‑technical stakeholders.
Nice to Have
  • Professional certifications: CISSP, SABSA, CCSP, or equivalent architecture/security credentials.
  • Experience operating in a post‑M&A environment with multi‑tenant identity and infrastructure consolidation challenges.
  • Familiarity with Cloudflare Access/WARP, Meraki, CrowdStrike Falcon, Kandji, Qualys VMDR, or Drata/GRC tooling.
  • Experience designing AI governance and shadow SaaS controls for enterprise environments.
  • Background working in a regulated industry or supporting compliance frameworks (SOC 2, ISO 27001, FedRAMP).

8+ years of experience in information security, 4+ years in security architecture, security engineering lead, or equivalent senior technical role, Expertise in designing and implementing Zero Trust architectures (ZTNA, identity‑aware access, microsegmentation), Deep knowledge of IAM: Okta, SAML, OIDC, SCIM, MFA, PAM, and certificate‑based authentication, Strong endpoint security architecture experience (macOS, Windows, EDR/CrowdStrike, MDM/Kandji/Intune), Experience architecting SaaS security programs (vendor risk, CASB/SSPM, OAuth/API controls), Solid understanding of network security: firewalls, SD‑WAN, 802.1X, DNS security, and segmentation, Familiarity with OT/IoT security architecture concepts, Ability to produce high‑quality architecture documentation (reference architectures, design patterns, ADRs), Strong communication skills for technical and non‑technical stakeholders

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Enterprise Security Architect
Senior Enterprise Security Architect

AlphaSense Oy • Pune District

On-site
INR 4,000,000 - 7,000,000
Senior Enterprise Security Architect
Senior Enterprise Security Architect

AlphaSense Oy • Bengaluru

On-site
INR 4,000,000 - 7,500,000
Professional certifications encouraged
Senior Enterprise Security Architect Delhi
Senior Enterprise Security Architect Delhi

AlphaSense, Inc. • Delhi

On-site
INR 3,500,000 - 6,000,000
Senior Enterprise Security Architect Pune
Senior Enterprise Security Architect Pune

AlphaSense, Inc. • Pune District

On-site
INR 2,500,000 - 6,000,000
Senior Enterprise Security Architect Bengaluru
Senior Enterprise Security Architect Bengaluru

AlphaSense, Inc. • Bengaluru

On-site
INR 4,500,000 - 7,000,000
Senior Enterprise Security Architect
Senior Enterprise Security Architect

AlphaSense • Delhi

On-site
INR 4,000,000 - 7,000,000
Senior Cybersecurity Architect
Senior Cybersecurity Architect

Aarushi Infotech • Chennai District

On-site
INR 3,500,000 - 7,000,000
Senior Cybersecurity Architect
Senior Cybersecurity Architect

Aarushi Infotech • Maharashtra

On-site
INR 900,000 - 1,260,000
Senior Cybersecurity Architect
Senior Cybersecurity Architect

Aarushi Infotech • Mumbai

On-site
INR 4,200,000 - 7,000,000
Senior Cybersecurity Architect
Senior Cybersecurity Architect

Aarushi Infotech • Bengaluru

On-site
INR 4,000,000 - 7,500,000