Security Risk Architect

L.E.K. Consulting

Boston (MA)

Hybrid

USD 130,000 - 150,000

Full time

37 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

L.E.K. Consulting is seeking a Security & Risk Architect to advance the firm’s cybersecurity strategy across infrastructure, cloud, applications, and AI security.

You will partner with IT, engineering, and business stakeholders to manage security operations, vulnerability management, incident response, and secure software development practices. The role emphasizes governance under NIST and ISO 27001, with a focus on Active Directory, Azure, Entra ID, and cloud security, while supporting a

Qualifications

  • Bachelor’s degree or equivalent experience required.
  • 3+ years in Information Security and 6+ years in IT overall.
  • Experience with enterprise security technologies and cloud security platforms.
  • Familiarity with NIST and ISO 27001.
  • Knowledge of SAST, DAST, SCA and secure coding practices.
  • AI security governance understanding and experience preferred.

Responsibilities

  • Lead Security Operations and Risk Management activities.
  • Architect and optimize enterprise security tooling and platforms.
  • Oversee vulnerability management, reporting and remediation coordination.
  • Integrate security into the software development lifecycle and CI/CD pipelines.
  • Govern AI security practices and data governance with stakeholders.

Skills

Analytical skills
Communication
Leadership
Project management
Adaptability
Strategy execution

Education

Bachelor’s degree or equivalent experience
CISSP / Security+ / CEH preferred

Tools

Azure
Active Directory
Entra ID
Endpoint security

Job description

About L.E.K. Consulting

L.E.K. Consulting is a premier global strategy consulting firm that partners with clients to solve their most critical business challenges and deliver high-impact outcomes. We bring deep industry expertise and rigorous, evidence-based insight to global corporations, growth companies and private equity investors, helping them turn strategy into action.

About L.E.K. Consulting

L.E.K. Consulting is a premier global strategy consulting firm that partners with clients to solve their most critical business challenges and deliver high-impact outcomes. We bring deep industry expertise and rigorous, evidence-based insight to global corporations, growth companies and private equity investors, helping them turn strategy into action.

How do we deliver impact? It’s the people. We hire exceptional individuals and invest in their growth through hands‑on client work, close collaboration and a culture of ownership, inclusion and continuous learning. Across every level, curiosity unites us and challenge excites us.

Founded more than 40 years ago, L.E.K. employs more than 2,200 professionals worldwide and is consistently recognized as one of the industry's best firms to work for.

For more information, visit lek.com.

Overview Of Role

The Security & Risk Architect is a senior technical leader within the Information Security team, responsible for advancing the firm’s cybersecurity strategy and strengthening enterprise security capabilities across infrastructure, cloud platforms, applications, and emerging AI technologies.

This role partners closely with IT, engineering, and business stakeholders to manage security operations, vulnerability management, incident response, secure software development practices, and AI security governance. The position supports a global environment aligned to the NIST Cybersecurity Framework and ISO 27001 standards.

The IT team is prioritizing hiring in Boston and / or Chicago.

Responsibilities
Security Operations & Risk Management
  • Identify, assess, and respond to cybersecurity and privacy risks across the organization
  • Serve as a technical escalation point for security incidents, investigations, and threat response activities
  • Support incident response, digital forensics, and coordination during critical security events
  • Monitor threat intelligence and recommend proactive risk mitigation strategies
Security Architecture & Tooling
  • Lead the management and optimization of enterprise security tools and platforms
  • Evaluate security technologies, identify capability gaps, and recommend improvements
  • Manage security controls across Active Directory, Azure, Entra ID, endpoint security, and cloud environments
  • Ensure systems and infrastructure maintain secure and hardened configurations
Vulnerability & Compliance Management
  • Oversee vulnerability management processes, reporting, and remediation coordination
  • Configure and maintain security monitoring, reporting, and compliance metrics
  • Drive continuous improvement initiatives across security processes, tools, and policies
  • Support disaster recovery, backup oversight, and operational resilience efforts
Application Security & Secure Development
  • Integrate security requirements into the software development lifecycle
  • Partner with development teams to implement secure‑by‑design practices within CI/CD pipelines
  • Lead application security reviews, code analysis, and penetration testing activities
  • Promote secure coding standards aligned with OWASP, NIST, and ISO 27001 frameworks
  • Manage third-party and open‑source software risk, including supply chain security controls
AI Security & Governance
  • Support governance and security oversight for AI platforms and tools, including Microsoft Copilot and Azure OpenAI
  • Establish controls for AI usage, access management, and data governance
  • Monitor emerging AI security risks, including prompt injection, adversarial behavior, and data exposure threats
  • Partner with legal, compliance, and business stakeholders to develop responsible AI usage policies
Qualifications
  • Bachelor’s degree or equivalent experience
  • 6+ years of experience in Information Technology, including 3+ years in Information Security
  • Experience with enterprise security technologies and cloud security platforms
  • Familiarity with cybersecurity frameworks such as NIST and ISO 27001
  • Knowledge of application security concepts, including SAST, DAST, SCA, and secure coding practices
  • Understanding of AI/ML security risks and governance principles
  • Relevant certifications such as CISSP, Security+, or CEH are preferred
Skills & Competencies
  • Strong analytical and problem‑solving skills
  • Excellent communication and stakeholder management abilities
  • Ability to lead initiatives and mentor junior team members
  • Strong organizational and project management skills
  • Adaptability in a fast‑paced, evolving environment
  • Ability to influence technical strategy and drive cross‑functional security initiatives
Additional Information
  • The expected base salary range for this position is $130,000 – $150,000 annually. Actual compensation will be determined based on experience, qualifications, skills, and location. This position may also be eligible for discretionary bonus and a comprehensive benefits package.
  • L.E.K. Consulting offers a competitive total rewards package including medical, dental, vision,lifeand disability insurance, 401(k) with employer contribution, HSA contributions (where applicable), paid time off, and other firm-sponsored benefits.
  • This role is based in any of our U.S. office and follows our hybrid work model for U.S. offices.We require employees to be in their assigned home office Tuesday, Wednesday, and Thursday each week, as well as the first Friday of each month.
  • Applicants must be legally authorized to work in the United States on a permanent basis without the need for employer sponsorship. Unfortunately, we are unable to consider candidatesrequiringvisa sponsorship, including but not limited to H-1B, TN, F-1 (OPT/CPT/STEM), or other work authorization.
  • L.E.K. Consulting is an Equal Opportunity Employer. We are committed toprovidingequal employment opportunities to all qualified individuals regardless of race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law.
  • In accordance withapplicable state and local laws, we will provide reasonableaccommodationsfor qualified individuals with disabilities and forsincerely heldreligious beliefs, practices, or observances.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Data Engineer
Senior Data Engineer

L.E.K. Consulting • Boston (MA)

Hybrid
USD 135,000 - 165,000
Medical insurance
Dental insurance
Vision insurance
+5
Senior Security & Risk Architect: Cloud & AI Security
Senior Security & Risk Architect: Cloud & AI Security

L.E.K. Consulting • Boston (MA)

Hybrid
USD 130,000 - 150,000
Senior Security Client Solution Architect (Remote)
Senior Security Client Solution Architect (Remote)

Myriad360 • Chicago (IL)

On-site
USD 250,000 - 275,000
Unlimited Paid Time Off (PTO)
Incentive compensation plans
Company-funded 401k contributions
+3
U.S. Associate Consultant - Digital 2026
U.S. Associate Consultant - Digital 2026

L.E.K. Consulting • Boston (MA)

Hybrid
USD 130,000 - 200,000
Hybrid work model
Medical insurance
401(k) with employer contribution
+1
Associate Data & AI Analyst
Associate Data & AI Analyst

L.E.K. Consulting • Boston (MA)

Hybrid
USD 80,000 - 100,000
Medical, dental, vision insurance
401(k) with employer contribution
HSA contributions
+2
Information Security Architect
Information Security Architect

BrainWorks • California (MO)

Hybrid
USD 155,000 - 220,000
Relocation assistance
Equity eligibility
Comprehensive benefits
Security Architect
Security Architect

Koitecc Solutions • Reston (VA)

Hybrid
USD 154,000 - 278,000
Health and Wellness
Income Protection
Paid Leave
+1
Cyber - Enterprise Security Architect - Senior - Consulting
Cyber - Enterprise Security Architect - Senior - Consulting

EY • New Orleans (LA)

On-site
USD 120,000 - 190,000
Medical and dental coverage
Pension and 401(k) plans
Paid time off options
Security Engineer
Security Engineer

Sargent & Lundy • Chicago (IL)

Hybrid
USD 64,915 - 95,019
Health Plans: Medical, Dental, Vision
401(k)
Paid Annual Personal/Sick Time
+1
Cyber - Enterprise Security Architect - Senior - Consulting
Cyber - Enterprise Security Architect - Senior - Consulting

EY • Hartford (CT)

On-site
USD 105,000 - 192,000