Westfield Insurance

Information Security Architect

Westfield Center, OH, US

$10
5 days ago
Save Job

Summary

The Information Security Architect is responsible for leading the design and implementation of comprehensive security architecture solutions. The role provides expertise in security frameworks, technologies, and best practices to assess security risks, define security requirements, and develop strategies to mitigate vulnerabilities. The role will involve designing secure network architectures, implementing access controls, and establishing encryption mechanisms. Additionally, the role plays a crucial part in conducting risk assessments, identifying gaps in security controls, and developing remediation plans. As a leader in the field, the role provides guidance, mentorship, and direction to the security team, fostering a culture of continuous improvement and ensuring compliance with industry regulations and standards. The role serves as a technical subject matter expert on moderate to high complexity initiatives, directly engaging in the selection, design, implementation and troubleshooting of security solutions.


Responsibilities

  • Develops and contributes to the implementation of the information security architecture strategy and roadmap, aligning it with business objectives, regulatory requirements, and industry best practices
  • Provides guidance to the security team, overseeing the design and integration of security solutions
  • Works with business units, IT teams, executive leadership, and vendors to communicate security risks and strategies
  • Recommends and implements new security technologies and tools
  • Defines and enforces security standards and frameworks
  • Collaborates with enterprise architects to integrate security controls into IT architecture
  • Develops and promotes security architecture processes and templates
  • Conduct security architecture reviews and risk assessments, identifying potential vulnerabilities, weaknesses, and gaps in existing systems and proposing effective solutions to mitigate risks
  • Serves as a mentor to junior security architects and team members
  • Participates in security forums and conferences
  • Provides technical leadership and guidance to the information security team and other stakeholders, overseeing the design, implementation, and integration of security solutions across the organization
  • Ensures collaboration of business units, IT teams, and vendors to assess security requirements, evaluate solution options, and architect secure systems and applications that meet business needs while maintaining a strong security posture
  • Defines and enforces information security standards, frameworks, and reference architectures, ensuring consistent and standardized security practices across all technology domains and projects
  • Oversees the conduct of security architecture reviews and risk assessments, identifying potential vulnerabilities, weaknesses, and gaps in existing systems and proposing effective solutions to mitigate risks
  • Oversees the design and implementation of security controls, such as firewalls, intrusion detection/prevention systems, encryption mechanisms, and secure network architectures, to protect the organization's assets and data
  • Collaborates with enterprise architects and IT stakeholders to integrate security controls and requirements into overall IT architecture frameworks, ensuring the security-by-design principle is followed throughout the development and implementation lifecycle
  • Provides subject matter expertise in security technologies and solutions, evaluating emerging security trends and products, and making recommendations for the adoption of new technologies to enhance the organization's security posture
  • Participate in security incident response and investigation activities, coordinating with internal teams and external entities to effectively respond to and mitigate security incidents, and providing guidance on post-incident remediation actions


Qualifications

  • 6-10 years of experience in Information Security or related field.
  • Bachelor’s degree in Computer Science, Information Technology or a related field and/or commensurate experience. Master's degree in related field is preferred.


Licenses and Certifications

  • Certified Information Systems Security Professional (CISSP) preferred.
  • Certified Information Security Manager (CISM) preferred.
  • Azure Solutions Architect (Preferred), AWS Certified Solutions Architect
  • TOGAF preferred
  • Other relevant certifications


Preferred Qualifications, Skills, and Capabilities:

Technology Knowledge:

  • Expertise in security practices and tools designed to protect containerized applications, including container image scanning, runtime protection, least-privilege configurations, and native container security measures.
  • Experience in the design, implementation, and ongoing reviews of security controls for one or more public cloud providers (e.g., Azure, AWS).
  • Skills in the design, assessment, and implementation of encryption security controls, including protections against emerging quantum computing threats.
  • Proficiency in assessing overall network security posture and vulnerabilities, and designing and implementing network security controls (e.g., Firewalls, IPS, ZTNA).
  • Background in application security and the software development lifecycle.

Frameworks:

  • Familiarity with the NIST Cybersecurity Framework.
  • Knowledge of ISO/IEC 27001 standards.
  • Understanding of the SABSA framework.

Regulatory:

  • Awareness of GDPR (General Data Protection Regulation) requirements.
  • Knowledge of New York Department of Financial Services (DFS) cyber security regulations.
  • Understanding of the California Consumer Privacy Act (CCPA).


Behavioral Competencies:

  • Strategic Mindset
  • Interpersonal Savvy
  • Effective Communications
  • Nimble Learning
  • Tech Savvy
  • Manages Ambiguity
  • Manages Complexity
  • Manages Conflict
  • Drives for results
  • Action Oriented


Location

Hybrid defined as three or more days per week in the office.


About Us

Founded in 1848, Westfield is a global leader in property and casualty insurance, delivering superior risk insights and innovative solutions to customers through a diverse portfolio of insurance products. Westfield underwrites commercial, personal, surety, and specialty lines of coverage through a network of leading independent agents and brokers in the United States and specialty products through Lloyd’s of London Syndicate 1200. As a mutual insurance company with more than 3,000 employees, Westfield has revenues in excess of $4 billion and more than $10 billion in assets. Learn more at www.westfieldinsurance.com.


Equal Opportunity Employer

United States: All applicants receive consideration for employment without regard to race, color, sex, religion, national origin, age, sexual orientation, gender identity, disability, or status as a protected veteran.

United Kingdom: Westfield is committed to equality of opportunity for all staff and applications from individuals are encouraged regardless of age, disability, sex, gender reassignment, sexual orientation, pregnancy and maternity, race, religion or belief and marriage and civil partnerships.

How strong is your resume?

Upload your resume and get feedback from our expert to help land this job

People also searched: