Cybersecurity Architect

OneMain Financial

Washington (District of Columbia)

On-site

USD 140,000 - 200,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

OneMain Financial, based in Washington, DC, seeks an experienced cybersecurity architect to develop enterprise-wide security architectures aligned to NIST standards and to design scalable security solutions across cloud, on-premises, and hybrid environments.

You will translate business and technical requirements into secure blueprints, lead architecture reviews, identify risks, and collaborate with engineering and risk teams to ensure compliant, secure deployments.

Qualifications

  • 7–10 years in cybersecurity with 3+ years in security architecture.
  • Deep knowledge of NIST CSF, SP 800-53, 800-171, 800-207.
  • Enterprise security design for cloud and on-premises environments (AWS/Azure).
  • Translate security requirements into implemented controls and procedures.
  • Strong IAM, network security, data protection, and application security.
  • Familiarity with GenAI, agentic AI, and MCP hardening.
  • Experience in regulated environments and mapping controls to compliance.
  • Excellent communication and documentation skills.

Responsibilities

  • Develop enterprise-wide security architectures aligned to NIST standards.
  • Design scalable, secure solutions across cloud, on‑premises, and hybrid environments.
  • Translate requirements into secure blueprints and reference architectures.
  • Lead architecture reviews and risk mitigation activities for new technologies.
  • Collaborate with engineering and risk teams to ensure secure deployments.
  • Mentor junior architects and security engineers.

Skills

Cybersecurity architecture
NIST frameworks
Cloud security (AWS/Azure)
IAM
Data protection
Application security
Governance & risk management
Leadership & mentoring

Education

CISSP
CISM
CISA
SABSA
AWS Certified Security

Job description

  • Develop enterprise-wide security architectures aligned to NIST standards (e.g., NIST CSF, SP 800-53, SP 800-171, SP 800-207).
  • Design scalable, secure solutions that address identified risks and business objectives across cloud, on-premises, and hybrid environments.
  • Translate business and technical requirements into secure solution blueprints.
  • Contribute to the development of reference architectures and security patterns.
  • Leverage hands on engineering implementation experience to provide prescriptive guidance on best practices and possible pitfalls.
  • Lead architecture and security reviews for new technologies, applications, and systems.
  • Identify gaps and weaknesses in proposed solutions and advise on appropriate risk mitigation strategies.
  • Collaborate with engineering and infrastructure teams to ensure secure deployment of systems and services.
  • Provide technical guidance to project and product teams throughout the system development lifecycle.
Architecture & Solution Design
  • Develop enterprise-wide security architectures aligned to NIST standards (e.g., NIST CSF, SP 800-53, SP 800-171, SP 800-207).
  • Design scalable, secure solutions that address identified risks and business objectives across cloud, on-premises, and hybrid environments.
  • Translate business and technical requirements into secure solution blueprints.
  • Contribute to the development of reference architectures and security patterns.
  • Leverage hands on engineering implementation experience to provide prescriptive guidance on best practices and possible pitfalls.
Solution Review & Risk Mitigation
  • Lead architecture and security reviews for new technologies, applications, and systems.
  • Identify gaps and weaknesses in proposed solutions and advise on appropriate risk mitigation strategies.
  • Collaborate with engineering and infrastructure teams to ensure secure deployment of systems and services.
  • Provide technical guidance to project and product teams throughout the system development lifecycle.
Governance & Standards
  • Develop and maintain security architecture standards, policies, and control frameworks in alignment with NIST and industry best practices.
  • Participate in or lead internal security governance boards and architecture review boards.
  • Ensure solutions meet internal risk, compliance, and regulatory requirements (e.g., CCPA, NYDFS, PCI DSS).
  • Contribute to maturity assessments and continuous improvement efforts for cybersecurity architecture.
Collaboration & Leadership
  • Act as a subject matter expert on cybersecurity architecture for stakeholders across IT, engineering, compliance, and risk teams.
  • Mentor junior architects and security engineers.
  • Communicate complex technical and risk concepts clearly to business leaders and non-technical audiences.
  • Stay up to date on emerging threats, technologies, and changes to the NIST ecosystem.
Required Qualifications
  • 7–10 years of experience in cybersecurity, with 3+ years in a security architecture or similar role.
  • Deep working knowledge of NIST frameworks (CSF, SP 800-53, 800-171, 800-207 Zero Trust).
  • Demonstrated experience designing and reviewing secure architectures for enterprise systems and cloud environments (e.g., AWS, Azure).
  • Practical experience translating security architecture requirements into implemented controls, technical configurations, and operational procedures.
  • Strong understanding of cybersecurity domains including identity and access management (IAM), network security, data protection, and application security.
  • Strong understanding of LLMs, AI, and GenAI solutions including agentic AI and MCP hardening.
  • Experience validating control effectiveness through testing, monitoring, evidence collection, or audit support.
  • Experience working in a regulated environment and aligning technical controls to compliance frameworks. Excellent communication, collaboration, and documentation skills.
Preferred
  • Industry certifications such as CISSP, CISM, CISA, SABSA, or AWS Certified Security.
  • Experience with Zero Trust Architecture and modern security models.
  • Experience with security automation, control orchestration, policy-as-code, or continuous control monitoring.
  • Experience implementing security controls in cloud-native, hybrid, and complex enterprise-scale environments.
  • Familiarity with DevSecOps and infrastructure-as-code security.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Architect
Cybersecurity Architect

Finezi Inc. • Rosemead (CA)

On-site
USD 130,000 - 160,000
Manager, Cyber Architecture
Manager, Cyber Architecture

Recru • Houston (TX)

On-site
USD 130,000 - 160,000
Cybersecurity Architect
Cybersecurity Architect

KIHOMAC • Colorado Springs (CO)

On-site
USD 160,000 - 195,000
Health Care Plan (Medical, Dental & Vision)
Retirement Plan (401k, IRA)
Paid Time Off (Vacation, Sick & Public Holidays)
+2
Cybersecurity Architect
Cybersecurity Architect

Ports North • Baltimore (MD)

On-site
Security Architect
Security Architect

Digital Global Connectors • McLean (VA)

Hybrid
USD 140,000 - 180,000
Security Architect
Security Architect

Digital-Global-Connectors • McLean (VA)

Hybrid
USD 130,000 - 180,000
Cybersecurity IAM Architect - Staff Engineer
Cybersecurity IAM Architect - Staff Engineer

OneMain Financial • Maryland

On-site
USD 140,000 - 190,000
Cybersecurity Architect
Cybersecurity Architect

AITS Defence • Augusta (GA)

On-site
USD 120,000 - 150,000
Medical, Dental and Vision Insurance
Life Insurance
Paid Time Off (PTO)
+2
Cybersecurity IAM Architect - Staff Engineer
Cybersecurity IAM Architect - Staff Engineer

OneMain Financial • Baltimore (MD)

On-site
USD 150,000 - 190,000
Cybersecurity Lead Architect
Cybersecurity Lead Architect

Jobtailor • North Carolina

On-site
USD 150,000 - 190,000