Information Security Architect

Ryder System, Inc.

Denver (CO)

On-site

USD 140,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Ryder System, Inc. is seeking a Network Security Architect in Denver to design and implement network security architecture across on-prem and cloud, collaborating with engineering through build and cutover.

You will translate complex requirements into concrete configurations, document architectures, and stay current on threats and technologies to protect critical systems.

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or related field.
  • 7+ years of experience in an Information Security Architect role.
  • 7+ years of experience with regulatory compliance and information security frameworks (NIST CSF, ISO 27001, COBIT).
  • Network technologies including protocols, design concepts, and access control (advanced).
  • Security technologies including encryption, data protection, access privileges (advanced).
  • Experience with cloud platforms and IaC tools (Azure, AWS, GCP) and DevSecOps practices.
  • One or more Palo Alto Network certifications (PCNSA, PCNSE, PCCSE, PCSAE).

Responsibilities

  • Designs network security architecture from the ground up, including firewall policy, segmentation, Zero Trust, and cloud architecture in Azure.
  • Leads end-to-end migrations: assess current state, design target, build configuration, and manage cutover.
  • Collaborates with engineering through build and cutover, adapting design as needed.
  • Reviews existing architecture to identify gaps and remediation, addressing legacy configurations.
  • Documents and diagrams architecture with configuration details, not just high-level diagrams.
  • Handles RSA tickets in ServiceNow and related security architecture efforts.
  • Stays current on emerging network security technologies and threats and integrates them as needed.

Skills

Network security architecture
Firewall configuration
Zero Trust design
Cloud network architecture
DevSecOps
Engineering collaboration

Education

Bachelor's degree in Computer Science or related field
CISSP or equivalent certification

Tools

Terraform
CloudFormation
Azure Resource Manager
GCP Deployment Manager
Palo Alto certifications (PCNSA/PCNSE)

Job description

The Network Security Architect will design and build the network security architecture our environment runs on, from firewall and segmentation design through cloud network architecture, and will stay engaged through implementation alongside engineering, not hand off a design and move on.

The Network Security Architect role sits within the Chief Information Security Officer Office, reporting to the Director of Security Architecture and Engineering (SA&E).

Essential Functions
  • Designs network security architecture from the ground up: firewall policy and configuration, network segmentation, Zero Trust access design, and cloud network architecture in Microsoft Azure.
  • Leads technical migrations end to end: assesses the current environment, designs the target state, builds the configuration, and manages the cutover.
  • Works directly alongside engineering through the build and implementation phase of every project they design, adjusting the design in real time when engineering encounters something the design did not account for. This role is expected to close the gap between architecture and engineering, not operate on one side of it.
  • Reviews existing network security architecture, identifies gaps, and designs the remediation, including hands on work to resolve technical debt in legacy configurations.
  • Assesses, scopes, and estimates the work and hours required to deliver security architecture components of larger projects and programs.
  • Serves as the technical expert and trusted advisor to engineering, IT, and business partners on network security design questions.
  • Documents and diagrams architecture in both conceptual and physical form, including the underlying configuration, not just high level diagrams.
  • Works assigned Request Security Architecture (RSA) tickets and related efforts in ServiceNow.
  • Stays current on emerging network security technologies and threats and incorporates them into architecture as needed.
Additional Responsibilities
  • Performs other duties as assigned.
Skills and Abilities
  • Demonstrated ability to take a loosely defined problem, perform the discovery work independently, and produce an implementable design, not just a conceptual recommendation.
  • Advanced, hands on knowledge of network technologies: protocols, design concepts, segmentation, and access control.
  • Advanced, hands on knowledge of security technologies: encryption, data protection, access privilege design.
  • Direct configuration experience with firewall platforms, not solely policy or diagram level experience.
  • Comfortable working side by side with engineers through build and cutover, including off hours implementation windows when required.
  • Strong communication skills, able to explain technical design decisions clearly to both engineers and non technical stakeholders.
Qualifications
  • Bachelor's degree required Computer Science, Information Security, or related field
  • Seven (7) years or more Experience in an Information Security Architect role required
  • Seven (7) years or more Experience with regulatory compliance and information security frameworks (NIST 800/CSF, ISO 27001, COBIT, etc.) required
  • Network technologies including protocols, design concepts, and access control advanced required
  • Security technologies including encryption, data protection, access privileges advanced required
  • Knowledge of Microsoft Windows and Linux systems intermediate required
  • Knowledge of both regular expressions (regex) and JSON intermediate required
  • Other Information Security Certification (CISSP, GIAC, etc.)
  • Experience using APIs
  • Experience with CloudFormation, Terraform, Azure Resource Manager, or GCP Cloud Deployment Manager Templates
  • In-depth experience in one or more of the following CSP - Microsoft Azure, AWS, and GCP installation configuration and administration of security features and services
  • Expertise in architecting and working in a DevSecOps environment
  • Security skills should include areas such as access control, runtime defense /anti-malware, and vulnerability management and etc.
  • Experience working with internal business customers, architecting, deploying, configuring, and troubleshooting infrastructure security products
  • One or more Palo Alto Network certifications required such as – PCNSA, PCNSE, PCCSE, PCSAE.

Travel: 0-10%

DOT Regulated: None

Job Category: Information Security

Our Culture & Commitment

At Ryder, you’re trusted to make an impact—while enjoying room to grow and having a voice that’s heard. Our culture is built on respect, collaboration, and shared pride in doing great work rooted in innovation and safety.

Your Voice. Your Success. The Future We Build Together.

Compensation Information

The compensation offered to a candidate may be influenced by a variety of factors, including the candidate’s relevant experience; education, including relevant degrees or certifications; work location; market data/ranges; internal equity; internal salary ranges; etc. The position may also be eligible to receive an annual bonus, commission, and/or long-term incentive plan based on the level and/or type. Compensation ranges for the position are below:

Pay Type

Salaried

Minimum Pay Range:

$140,000.00

Maximum Pay Range:

$150,000.00

Benefits Information

For all Full-time positions only: Ryder offers comprehensive health and welfare benefits, to include medical, prescription, dental, vision, life insurance and disability insurance options, as well as paid time off for vacation, illness, bereavement, family and parental leave, and a tax-advantaged 401(k) retirement savings plan.

For more information about benefits, click here (https://ryder.icims.com/icims2/servlet/icims2?module=AppInert&action=download&id=4022345&hashed=256118533) to download the comprehensive benefits summary.

Ryder is proud to be an Equal Opportunity Employer and Drug Free workplace.

All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, sex, sexual orientation, gender identity, age, status as a protected veteran, among other things, or status as a qualified individual with disability.

Important Note

Some positions require additional screening that may include employment and education verification; motor vehicle records check and a road test; and/or badging or background requirements of the customer to which you are assigned.

Security Notice for Applicants

Ryder will only communicate with an applicant directly from a [@ryder.com] email address and will never conduct an interview online through a chat type forum, messaging app (such as WhatsApp or Telegram), or via an online questionnaire. During an interview, Ryder will never ask for any form of payment or banking details and will never solicit personal information outside of the formal submitted application through www.ryder.com/careers .

Should you have any questions regarding the application process or to verify the legitimacy of an interview or Ryder representative, please contact Ryder at careers@ryder.com .

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Architect
Information Security Architect

Ryder System, Inc. • Des Moines (IA)

On-site
USD 140,000 - 150,000
Medical, dental, vision benefits
401(k) retirement plan
Paid time off
Information Security Architect
Information Security Architect

Ryder System, Inc. • Helena (MT)

On-site
USD 140,000 - 150,000
Health Insurance
401(k) retirement plan
Paid Time Off
Information Security Architect
Information Security Architect

Ryder System, Inc. • Indianapolis (IN)

On-site
USD 140,000 - 150,000
Health and welfare benefits
Paid time off
401(k) retirement plan
+1
Information Security Architect
Information Security Architect

Ryder System, Inc. • Hagåtña (GU)

On-site
USD 140,000 - 150,000
Health benefits
401(k) plan
Paid time off
Information Security Architect
Information Security Architect

Ryder System, Inc. • Trenton (NJ)

On-site
USD 140,000 - 150,000
Health benefits
401(k) plan
Paid time off
Information Security Architect
Information Security Architect

Ryder System, Inc. • Providence (RI)

On-site
USD 140,000 - 150,000
Health and welfare benefits
401(k) retirement savings plan
Paid time off
Information Security Architect
Information Security Architect

Ryder System, Inc. • Boise (ID)

On-site
USD 140,000 - 150,000
Information Security Architect
Information Security Architect

Ryder System, Inc. • Columbus (OH)

On-site
USD 140,000 - 150,000
Health benefits
401(k) retirement plan
Paid time off
Information Security Architect
Information Security Architect

Ryder System, Inc. • Saint Paul (MN)

On-site
USD 140,000 - 150,000
Health benefits
401(k)
Information Security Architect
Information Security Architect

Ryder System, Inc. • Columbia (SC)

On-site
USD 140,000 - 150,000