Compensation: base salary in the range of $148,500.00 - $247,500.00, with potential eligibility for additional incentive compensation.
The Senior Lead Cybersecurity Architect is responsible for defining the principles, standards, and design patterns to build secure products and enterprise tools for Cox Automotive’s multi‑cloud and on‑premises environments. The focus is on securing multi‑cloud infrastructure and services as well as on‑premises infrastructure.
What You’ll Do
- Identify and recommend relevant cybersecurity policies, standards, procedures, and guardrails.
- Drive the definition of cybersecurity guidelines across the product and enterprise architecture group by leading working groups focused on cybersecurity.
- Develop secure design patterns in conjunction with the product and enterprise architecture group based on standards that can be adopted and implemented by engineering teams.
- Contribute to the development of non‑cyber architecture‑related governance patterns, policies, and standards.
- Provide complex analysis of potential risks to information systems’ security and recommend innovative solutions.
- Work with cross‑functional technical, development and delivery teams to ensure the application of smooth, efficient and scalable release processes.
- Engage with business teams and engineering teams to define cybersecurity guardrails that promote efficient and seamless adoption of secure design patterns.
- Participate in security events and incident response to identify gaps in current design and propose solutions to prevent threats from reoccurring.
- Research and evaluate emerging security trends, threats, and technologies, and recommend appropriate solutions and enhancements.
- Collaborate with data users, software and other technical stakeholders to ensure security considerations are factored into and underpin development and operational decision making.
- Collaborate with cybersecurity peers to incorporate vulnerability management, governance, risk and compliance, cyber defense, continuous controls monitoring, and identity governance into cybersecurity standards as a cohesive cybersecurity organization.
Who You Are
- Minimum qualifications include a bachelor’s degree in a related discipline and at least 8 years of experience, or equivalent combinations (e.g., master’s degree and 6 years, Ph.D. and 3 years, or 12 years of experience).
- At least 4 years of focused cybersecurity experience.
- Practical expertise in AWS cloud infrastructure and services as well as on‑premises infrastructure.
- Ability to clearly articulate the objectives of specific cybersecurity policies and procedures to technical and non‑technical stakeholders.
- Excellent customer service, writing, and executive‑presentation skills.
- Capability to develop a strong and productive working environment with key stakeholders and collaborate closely with other Cox entities’ cybersecurity teams.
- Consultative nature to work through controversial or complex topics with employees, leaders, and senior leadership.
- Skill in evaluating risks and recommending actions based on impact and likelihood to the business.
- Knowledge of current cybersecurity and technology architectures such as zero trust, IaaS, PaaS, SaaS, virtualization, and containerization.
- Ability to creatively solve complex cybersecurity challenges while exhibiting solid, pragmatic business acumen.
- Experience utilizing Agile methodologies.
- Experience initiating change and deploying solutions in Fortune 1,000 companies.
- Knowledge of cybersecurity frameworks (e.g., ISO 27000, NIST, FFIEC) and industry‑relevant regulations that guide architectural requirements (e.g., GDPR, FFIEC, GLBA).
- Ability to collaborate with AI agents to create, validate, and assess architectural artifacts; lead cross‑functional teams in designing AI‑enhanced solutions; establish standards for AI integration; assess AI technologies within solution architectures; implement AI‑driven architectural governance and compliance by defining robust AI governance frameworks and reference architectures; improve vendor tool assessments using AI to speed evaluations and minimize mistakes and unknowns.
- Proficiency in Python, .NET, Java, Spring frameworks, Oracle, serverless, cloud patterns, cloud service and user authentication or similar.
- Experience with firewalls, web application firewalls, and other edge services as well as deep understanding of DMZ and other network architectures.
- Experience with the AWS Well‑Architected Framework.
- Ability to establish strategy for and implement cloud enterprise solutions in AWS, GCP, or Azure.
- Strong understanding of cloud containers and/or serverless platforms (e.g., EKS, ECS, Lambda, Fargate).
- Big Four consulting or Fortune 500 company experience.
- Relevant industry certifications (e.g., CISSP, CEH, OSCP, Azure, AWS, CISM, CISA).
Preferred Qualifications
- Experience developing and designing cybersecurity standard methodologies across all layers of hosting and application stack in cloud and on‑premises environments.
- Relevant experience with application security, SaaS, network security, DevSecOps, and software‑defined networking across diverse environments.
- Knowledge of identity and access management (IAM), cryptography / key management, secrets management, access controls and security protocols (e.g., multi‑factor, SAML, OAuth, OIDC).
- Experience with application security implementations and standard methodologies.
- Extensive technology knowledge and recognized expertise in Python, .NET, Java, Spring frameworks, Oracle, serverless, cloud patterns, cloud service and user authentication or similar.
- Experience with firewalls, web application firewalls, and other edge services; deep understanding of DMZ and other network architectures.
- Experience with the AWS Well‑Architected Framework.
- Experience establishing strategy for and implementing cloud enterprise solutions in AWS, GCP, or Azure.
- Strong understanding of cloud containers and/or serverless platforms (EKS, ECS, Lambda, Fargate).
- Big Four consulting or Fortune 500 company experience.
- Relevant industry certification (CISSP, CEH, OSCP, Azure, AWS, CISM, CISA).
Drug Testing
Applicants must clear a pre‑employment drug test. Cox is a drug‑free workplace and prohibits possession, use, or influence of illegal drugs during work hours.
Benefits
Employees are eligible for flexible vacation, seven paid holidays, up to 160 hours of paid wellness annually, and additional paid time off for bereavement, voting, jury duty, volunteer time off, military leave, and parental leave. Benefits include health insurance (medical, dental, vision), retirement planning (401(k)), and paid days off.
Equal Employment Opportunity
Cox is an Equal Employment Opportunity employer. All qualified applicants/employees will receive consideration for employment without regard to age, race, color, religion or creed, national origin, sex, sexual orientation, gender identity, disability, veteran status, genetic information, ethnicity, citizenship, or any other characteristic protected by law. Cox provides reasonable accommodations when requested by a qualified applicant or employee with disability, unless such accommodations would cause an undue hardship. EOE, including disability/vets. Applicants must be authorized to work in the United States for any employer without current or future sponsorship. No OPT, CPT, STEM/OPT, or visa sponsorship now or in the future.