Job Description
Company: State Street
Location: Devon, US
Job Overview
The Head of Security Architecture, Managing Director is a senior cybersecurity leader responsible for establishing and scaling a secure‑by‑design operating model that embeds cybersecurity requirements directly into technology design, engineering, and delivery processes across the enterprise. The role reports to the Deputy CISO, SVP.
Key Responsibilities
• Drive the vision, strategy, and mission accomplishment of the entire Security Architecture organization.
• Establish and scale an enterprise security architecture model that embeds secure‑by‑design principles into technology development, engineering, and operational processes.
• Define and maintain enterprise security baselines, architecture standards, and design guardrails that enable consistent implementation of security controls across cloud, SaaS, infrastructure, application, API, data, and AI environments.
• Develop and operationalize reference architectures and reusable security patterns that accelerate technology delivery while reducing cyber risk and architectural complexity.
• Establish and lead a Security Architecture Center of Excellence responsible for security design guidance, threat‑informed architecture practices, technology standards, and cybersecurity innovation.
• Drive adoption of threat modeling as a foundational design discipline, ensuring security risks are identified and addressed before deployment and operationalization.
• Lead security architecture and design reviews for strategic technology initiatives, enabling informed risk decisions and alignment with enterprise cybersecurity requirements.
• Partner with technology product owners, engineering organizations, and enterprise architects to ensure security is designed into platforms, applications, services, and infrastructure rather than applied through downstream controls.
• Establish target‑state architecture and drive integration across cyber defense, threat intelligence, vulnerability management, analytics, engineering, and operational response capabilities.
• Drive the design and evolution of integrated security architectures that improve visibility, detection, investigation, and response across the enterprise.
• Lead architecture strategy for frontier technologies including cloud‑native platforms, AI‑enabled solutions, automation technologies, APIs, advanced analytics, and autonomous systems.
• Ensure security architectures address dynamic risks associated with emerging technologies, third‑party integrations, cloud adoption, and evolving threat actor capabilities.
• Collaborate closely with Fusion & Security Operations, Platform Security, enterprise architecture, and technology infrastructure teams to ensure cohesive, end‑to‑end protection across the technology ecosystem.
• Define clear accountability models, governance structures, and performance metrics that enable technology teams to effectively manage cyber risk while aligning to enterprise standards and regulatory expectations.
Desired Outcomes
• Secure‑by‑design principles are consistently embedded across technology development and engineering practices, reducing reliance on downstream security intervention.
• Security baselines, architecture standards, reference architectures, and approved security patterns are broadly adopted across technology environments, resulting in more consistent and resilient security outcomes.
• Threat modeling becomes a standard component of the technology lifecycle, improving identification and mitigation of design‑stage risks before deployment.
• A Security Architecture Center of Excellence serves as the authoritative source for architecture standards, engineering guidance, threat‑informed design practices, and secure technology enablement.
• Enterprise security technologies, cybersecurity data platforms, analytics capabilities, and detection systems operate within an integrated architecture that accelerates threat detection and response.
• Security requirements are incorporated earlier in the technology lifecycle, reducing remediation effort, operational friction, and overall cyber risk exposure.
• Cybersecurity data, telemetry, and intelligence sources are effectively connected to improve situational awareness and risk‑informed decision making.
• Architecture standards and secure design patterns reduce technology complexity while improving resilience, scalability, and operational efficiency.
• Emerging technologies, including AI‑enabled capabilities and automation platforms, are adopted through repeatable security architectures that balance innovation, risk management, and regulatory obligations.
• Strong alignment exists between cybersecurity strategy, enterprise architecture, technology transformation initiatives, and business objectives, resulting in more resilient an
Source: BeBee