Cybersecurity Architect

OneMain FinancialBaltimore, MD

About The Position

The Cybersecurity Architect will be responsible for developing enterprise-wide security architectures aligned to NIST standards. This role involves designing scalable, secure solutions for cloud, on-premises, and hybrid environments, translating business and technical requirements into secure solution blueprints, and contributing to reference architectures and security patterns. The architect will leverage hands-on engineering experience to provide guidance on best practices and potential pitfalls. Key responsibilities include leading architecture and security reviews for new technologies, identifying risks, and advising on mitigation strategies. The role also involves developing and maintaining security architecture standards, policies, and control frameworks, participating in governance boards, and ensuring solutions meet internal risk, compliance, and regulatory requirements. Collaboration and leadership are essential, acting as a subject matter expert, mentoring junior staff, and communicating complex concepts to various audiences. Staying current with emerging threats and technologies is also a critical aspect of this position.

Requirements

  • 7–10 years of experience in cybersecurity, with 3+ years in a security architecture or similar role.
  • Deep working knowledge of NIST frameworks (CSF, SP 800-53, 800-171, 800-207 Zero Trust).
  • Demonstrated experience designing and reviewing secure architectures for enterprise systems and cloud environments (e.g., AWS, Azure).
  • Practical experience translating security architecture requirements into implemented controls, technical configurations, and operational procedures.
  • Strong understanding of cybersecurity domains including identity and access management (IAM), network security, data protection, and application security.
  • Strong understanding of LLMs, AI, and GenAI solutions including agentic AI and MCP hardening.
  • Experience validating control effectiveness through testing, monitoring, evidence collection, or audit support.
  • Experience working in a regulated environment and aligning technical controls to compliance frameworks.
  • Excellent communication, collaboration, and documentation skills.

Nice To Haves

  • Industry certifications such as CISSP, CISM, CISA, SABSA, or AWS Certified Security.
  • Experience with Zero Trust Architecture and modern security models.
  • Experience with security automation, control orchestration, policy-as-code, or continuous control monitoring.
  • Experience implementing security controls in cloud-native, hybrid, and complex enterprise-scale environments.
  • Familiarity with DevSecOps and infrastructure-as-code security.

Responsibilities

  • Develop enterprise-wide security architectures aligned to NIST standards (e.g., NIST CSF, SP 800-53, SP 800-171, SP 800-207).
  • Design scalable, secure solutions that address identified risks and business objectives across cloud, on-premises, and hybrid environments.
  • Translate business and technical requirements into secure solution blueprints.
  • Contribute to the development of reference architectures and security patterns.
  • Leverage hands-on engineering implementation experience to provide prescriptive guidance on best practices and possible pitfalls.
  • Lead architecture and security reviews for new technologies, applications, and systems.
  • Identify gaps and weaknesses in proposed solutions and advise on appropriate risk mitigation strategies.
  • Collaborate with engineering and infrastructure teams to ensure secure deployment of systems and services.
  • Provide technical guidance to project and product teams throughout the system development lifecycle.
  • Develop and maintain security architecture standards, policies, and control frameworks in alignment with NIST and industry best practices.
  • Participate in or lead internal security governance boards and architecture review boards.
  • Ensure solutions meet internal risk, compliance, and regulatory requirements (e.g., CCPA, NYDFS, PCI DSS).
  • Contribute to maturity assessments and continuous improvement efforts for cybersecurity architecture.
  • Act as a subject matter expert on cybersecurity architecture for stakeholders across IT, engineering, compliance, and risk teams.
  • Mentor junior architects and security engineers.
  • Communicate complex technical and risk concepts clearly to business leaders and non-technical audiences.
  • Stay up to date on emerging threats, technologies, and changes to the NIST ecosystem.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service