Job Summary
The Security Architect serves as Sorenson's senior security architecture authority and is responsible for defining, advancing, and overseeing the enterprise cybersecurity architecture strategy. Positioned within the Security organization, this role has enterprise-wide influence over security architecture practices across identity, application, cloud, infrastructure, network, data, security operations, resilience, Zero Trust, and emerging technologies.
The Security Architect establishes security principles, standards, reference architectures, technical guardrails, and reusable design patterns that guide the secure development, deployment, operation, and integration of enterprise technologies. The role establishes and leads the Security Architecture Review process for materially significant initiatives, helping ensure security is incorporated early in solution design and technology decision-making.
The role works in close partnership with Enterprise Architecture, Engineering, Product, Data, AI Governance, Legal, Privacy, Compliance, and Risk Management. The Security Architect represents and governs the security architecture domain while aligning with broader enterprise architecture and governance processes.
Artificial intelligence is an important component of the role's emerging-technology responsibilities. The Security Architect defines security architecture and control patterns for AI systems, models, agents, platforms, data pipelines, vector databases, and retrieval-augmented generation solutions while ensuring alignment with enterprise security, data governance, privacy, compliance, risk, and responsible AI objectives.
Success is measured through increased adoption of approved security architecture standards, timely completion of architecture reviews for materially significant initiatives, improved threat-modeling and SSDLC coverage, reduction of systemic architectural risk and technical debt, advancement of Zero Trust and cyber-resilience maturity, and secure deployment of new and emerging technologies.
Essential Duties and Responsibilities
Enterprise Security Architecture Strategy and Standards
- Define, advance, and govern Sorenson's enterprise cybersecurity architecture strategy, principles, standards, reference architectures, and design patterns.
- Develop reusable security architecture patterns and technical guardrails that accelerate secure delivery while maintaining consistency across enterprise systems, products, and platforms.
- Define architectural security requirements and implementation guidance that support business objectives, operational resilience, and risk management goals.
- Maintain alignment between security architecture strategy and Sorenson's enterprise technology strategy through partnership with Enterprise Architecture and technology leadership teams.
Security Architecture Review & Decision Leadership
- Establish and lead the Security Architecture Review process for materially significant technology initiatives, including cloud platforms, enterprise applications, customer-facing products, AI systems, data platforms, third‑party services, and major architectural changes.
- Define risk-based review criteria, engagement points, required architecture artifacts, security requirements, and exception‑management processes.
- Ensure security is incorporated early in solution design, technology selection, procurement, and implementation planning.
- Document security architecture determinations, required security controls, approved patterns, design alternatives, exceptions, and material risk considerations.
- Provide architectural guidance and recommendations that balance security, operational effectiveness, business objectives, cost, and delivery timelines.
Application Security & Secure Software Architecture
- Define and maintain secure application architecture standards and reference patterns for:
- Authentication and authorization
- API security
- Microservices security
- Service-to-service trust
- Secure design principles
- Secrets management
- Secure session management
- Application threat modeling
- Partner with Application Security, Product, Engineering, and DevSecOps teams to integrate approved security architecture patterns throughout the software development lifecycle.
- Define architecture expectations and verification criteria that support consistent implementation of secure software development practices.
- Support engineering teams in resolving complex design challenges requiring security architecture expertise.
Zero Trust, Identity & Data Protection Architecture
- Establish and maintain the Zero Trust architecture strategy and roadmap across identity, device, network, application, workload, and data pillars.
- Architect identity and access management patterns including:
- Single Sign-On (SSO)
- Multi-Factor Authentication (MFA)
- Privileged Access Management (PAM)
- Role-Based Access Control (RBAC)
- Attribute-Based Access Control (ABAC)
- Federation
- Non-human and workload identities
- Define data protection architectures including:
- Data classification controls
- Encryption standards
- Key management
- Data loss prevention patterns
- Access control architectures
- Ensure security architectures support enterprise identity, API management, and governance frameworks.
Cloud, Infrastructure, Network & Cyber Resilience Architecture
- Design security reference architectures across public cloud, private cloud, hybrid, and on‑premises environments.
- Define architecture standards for:
- Cloud landing zones
- Network segmentation
- Infrastructure-as‑Code security
- Container security
- Workload protection
- Secrets and credential management
- Cloud security posture management
- Define architecture patterns that support operational resilience, recoverability, survivability, and security monitoring.
- Develop security modernization roadmaps that address legacy technology risks, architectural technical debt, cyber resilience capabilities, disaster recovery readiness, and strategic security transformation initiatives.
- Partner with Infrastructure, Operations, and Enterprise Architecture teams to prioritize long‑term security modernization objectives.
Enterprise Data, Analytics & AI Security Architecture
- Define security architecture patterns and controls for:
- Enterprise data platforms
- Analytics environments
- Data‑sharing ecosystems
- AI data pipelines
- Vector databases
- Embedding pipelines
- Retrieval‑Augmented Generation (RAG) architectures
- Develop security architecture standards and technical controls to protect AI systems, models, agents, platforms, and associated data.
- Define safeguards addressing:
- Prompt injection
- Tool misuse
- Data exposure
- Model abuse
- Excessive agent privilege
- Memory and context isolation
- AI observability and guardrails
- Ensure AI and data architectures align with enterprise security requirements, privacy requirements, data governance standards, and responsible AI principles.
- Partner with AI Governance, Data Governance, Legal, Privacy, Compliance, and Risk Management stakeholders to ensure secure and compliant adoption of AI capabilities.
Third-Party & Technology Partner Security Architecture
- Partner with the SOC to define detection, logging, and response architecture (telemetry standards, SIEM/SOAR, detection engineering).
- Align defensive architecture to threat‑informed defense using MITRE ATT&CK and emerging AI threat frameworks.
- Lead enterprise threat modeling for new and materially changed systems‑including AI/agentic systems‑ensuring mitigations are documented, tracked, and testable.
- Identify systemic architecture risk across the portfolio and drive roadmap items to reduce exposure.
Threat Modeling, Security Operations & Security-by-Design
- Oversee threat modeling activities for new and materially changed systems, applications, services, and AI-enabled solutions.
- Apply frameworks such as:
- STRIDE
- MITRE ATT&CK
- MITRE ATLAS
- MA