Senior Cybersecurity Architect

HomeServe USA•Norwalk, CT
•$157,593 - $210,124•Onsite

About The Position

This role serves HomeServe’s senior security architecture authority, responsible for designing, reviewing, and governing secure architecture for new and existing services, applications, and integrations before they reach production. The position creates business value by reducing the likelihood and blast radius of security incidents, accelerating secure delivery through reusable patterns and paved-road guardrails, and helping HomeServe meet customer, regulatory, and contractual obligations. Reporting to the VP of Information Security, this role leads formal security architecture reviews—producing risk-rated assessments and tracked remediation or exception plans—and acts as a design authority at key delivery gates (e.g., permission-to-build and permission-to-operate). It champions Zero Trust and secure-by-design principles across identity, network, application, and data security, and partners with Product, DevOps, Cloud, and Legal/Privacy to embed those practices into cohesive, scalable patterns adopted by delivery teams. The role owns and advances the security architecture roadmap and strategy—with particular focus on hybrid/multicloud (AWS primary), API/integration, and emerging AI-driven systems—and provides technical oversight and security architecture guidance for incident response while mentoring members of the information security team.

Requirements

  • Bachelor’s degree in information technology, computer science, or a related field, or equivalent work or education-related experience.
  • 7+ years’ experience in IT Security, with demonstrated experience in security architecture and solution design review.
  • Demonstrated experience designing Zero Trust and secure-by-design architectures, including reusable security patterns and reference architectures adopted across delivery teams.
  • Hands-on experience securing hybrid/multicloud environments (AWS strongly preferred; Azure/GCP a plus): IAM, serverless/Lambda, S3, KMS, Secrets Manager, VPC design, and cloud-native security controls.
  • Experience integrating security into DevSecOps and the secure SDLC: CI/CD pipeline security, infrastructure-as-code scanning, and container/Kubernetes security.
  • Experience with API and integration security (e.g., API gateways, WAF, MuleSoft/Akamai or equivalent) and securing third-party SaaS integrations.
  • Exposure to securing data and AI/ML or automation/agentic systems—data protection, autonomy controls, human-in-the-loop design, and model/vendor data-handling risk (increasingly required).
  • Experience must include security standards development, risk assessment, third-party/vendor risk, and compliance testing; penetration-testing and vulnerability-assessment familiarity expected.
  • Proficient knowledge of information security standards, controls, and frameworks (e.g., NIST CSF 2.0, NIST 800-53, ISO 27001, PCI DSS) for desktops, servers, applications, databases, and network devices.
  • Working knowledge of key security technologies: cloud security services, IAM, cryptography/encryption and key management, DLP, SIEM, IDS/IPS, endpoint protection, firewalls, and Active Directory.
  • Strong analytical and problem-solving skills; excellent verbal, written, and interpersonal communication skills; ability to interact with and influence all levels of the organization.
  • Effective time-, project-, and organizational-management skills; ability to handle multiple projects within established time constraints.
  • Must be able to work independently as well as in a team environment and maintain confidentiality.

Nice To Haves

  • Industry certifications preferred: CISSP required or strongly preferred; Microsoft SC-100 (Cybersecurity Architect Expert) and/or CISSP-ISSAP highly desirable for architecture depth; CCSP and AWS Certified Security – Specialty highly desirable for cloud depth; CISM, CISA, CEH, or GIAC a plus.

Responsibilities

  • Serve as the security architecture review and design authority for new solutions, integrations, and major changes—evaluate solution designs at permission-to-build and permission-to-operate gates, produce formal InfoSec assessments with risk-rated findings, and drive remediation or formal, time-boxed exceptions to closure.
  • Champion and operationalize Zero Trust architecture: identity-centric access, least-privilege enforcement, micro segmentation, and continuous verification across on-premises, cloud, and containerized environments.
  • Develop enterprise security reference architectures, reusable design patterns, and secure-by-design standards and “paved-road” guardrails that delivery teams can adopt through self-service.
  • Design and review cloud security architecture across hybrid/multicloud (AWS primary): least-privilege IAM, serverless/Lambda hardening, S3/KMS encryption strategy (customer-managed vs. AWS-managed keys), Secrets Manager and key-rotation practices, VPC placement, and secure network egress.
  • Embed security into the SDLC and DevSecOps toolchain: CI/CD pipeline security, infrastructure-as-code scanning, container/Kubernetes security, and shift-left practices in partnership with Product and DevOps.
  • Assess and guide the secure design of data and AI system data protection and classification, plus AI-specific controls such as human-in-the-loop and confidence-threshold gating, audit logging and rollback, and model/vendor data-handling and retention.
  • Review API and integration security across platforms such as MuleSoft and Akamai (WAF, rate limiting, request validation) and third-party SaaS integrations.
  • Conduct third-party and vendor security risk assessments, including data-retention, consent, call-recording, and PII-handling obligations; partner with Legal/Privacy on regulatory determinations.
  • Map controls and findings to recognized frameworks (NIST CSF 2.0, NIST 800-53, ISO 27001) and recommend and enforce minimum security baselines for IT platforms and technologies.
  • Enforce Privileged Access Management (PAM) standards for service-account and credential handling across integrations and data pipelines.
  • Participate in and, where appropriate, act as an approver for the Architectural Review Board (ARB) and Change Advisory Board (CAB); manage pre-CAB security-related requests.
  • Perform risk analysis for corporate functional and technical areas relevant to data security, including networks, applications, and 3rd-party service providers.
  • Create and maintain security architecture documentation, standards, patterns, and procedures.
  • Provide technical oversight and security architecture guidance for incident identification, response, investigation, and remediation, including support during off hours as needed.
  • Research and maintain a knowledge base of information security and emerging-technology trends, advisories, and applicable laws and regulations; identify and communicate current and emerging security threats.
  • Create solutions that balance business requirements with information and cyber security requirements; influence peers, partners, and project teams toward security-minded decisions.
  • Enable and coach delivery teams and information security staff to adopt secure design patterns and self-service guardrails; answer technical and procedural questions to improve processes.
  • All other duties as assigned.

Benefits

  • Annual Bonus Eligibility: 15%
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service