What are the responsibilities and job description for the Security Architect position at Brotherhood Mutual?
Job Title: Security Architect
FLSA Status: Exempt
Job Family: Information Technology
Department: Information Security
Location: Corporate Office (Fort Wayne, IN)
***Please note that this position is not eligible for sponsorship.
JOB SUMMARY
Design, build, and oversee technical implementation of security projects, integrations, and
enhancements. Responsible for designing, building and overseeing implementation of network, cloud,
identity, endpoint and application security based on management's objectives, in accordance with
business needs of the company; providing technical, project, thought leadership, and prioritization;
providing solutions to advanced problems for the security team. Collaborate with architects in other areas
to plan and build the company's technical architecture.
POSITION ESSENTIAL FUNCTIONS AND RESPONSIBILITIES
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily.
Reasonable accommodations may be made to enable individuals with disabilities to perform the essential
functions.
- Collaborate with engineers and architects in other areas to design the company's technical IT and
security architecture. Provide architectural supervision with cybersecurity and IT projects. - Develop security strategy plans, procedures and roadmaps based on sound enterprise
architecture practices for all environments including cloud and on-premise infrastructure. - Develop and maintain security architecture artifacts (e.g. solutions, patterns, diagrams, models,
templates, standards and procedures) that can be used to leverage security capabilities and
mitigate security risks in projects and operations. - Evaluate statements of work (SOWs) for projects to ensure that adequate security protections are
in place. Assess the providers' audit reports for security-related deficiencies and required "user
controls" and report any findings to the CISO and vendor management teams. - Determine baseline security configuration standards for operating systems (e.g., OS hardening),
network segmentation and identity and access management (IAM). - Perform security reviews, identifies gaps in security architecture and security best practices,
recommend changes, and develop a security risk management plan. - Track developments and changes in the digital business and threat environments to ensure that
they're adequately addressed in security strategy plans and architecture artifacts. Stay up-to-date
on the latest security technologies, trends, and best practices. - Conduct or facilitate threat modeling of services and applications that tie to the risk and data
associated with the service or application; design mitigation strategies. - Document data flows of sensitive information in the organization (e.g., PII or ePHI) and
recommend controls to ensure that this data is adequately secured (e.g., encryption and
tokenization). - Review and approve configurations for network components such as firewalls, IDS/IPS, VPN
gateways, load balancers, SIEMs, WAFs, encryption and more. - Review vulnerability and penetration test results to identify exposure and improve network
security posture. - Contribute to technical and business discussions for security strategy with an emerging threat
landscape. - Oversee enforcement of vulnerability management mitigation in technical teams’ operational
responsibilities. - Define key performance indicators, objectives and key results, and metrics to illustrate reduction
in risk and/or increase in resiliency. - Complete other duties as assigned.
KNOWLEDGE, SKILLS, AND ABILITIES
The requirements listed below are representative of the knowledge, skills, and/or abilities required to perform
each essential duty satisfactorily. Reasonable accommodations may be made to enable individuals with
disabilities to perform the essential functions.
- Must possess strong written, verbal, and presentation skills.
- Must have proven ability to coach and mentor others, as well as manage projects well.
- Must possess a strong desire for continuous learning and mentoring regarding security
technologies and tools. - Must be self-motivated with strong interpersonal, communication, and analytical skills.
- Must have proven project leadership skills within a team-oriented environment.
- Must possess a bias toward urgency of completing work.
- Must be an expert across most of: network security controls (Firewall, WAF, IDS/IPS), endpoint
security controls (EPP, EDR, DLP, application control), cloud security controls, and IAM controls. - Must possess a familiarity with cyber security regulations: NAIC Insurance Data Security Model
Law, New York DFS Cyber Security Regulations. - Must possess a familiarity with NIST Cyber Security Framework (NIST CSF).
- Must possess a familiarity with Service Delivery and Controls Frameworks (COBIT, NIST, ITIL).
- Must possess a familiarity with privacy regulations (e.g. GDPR, CCPA).
- Effectively interface with external contacts, Brotherhood employees, managers, and department
staff members.
EDUCATION AND/OR EXPERIENCE
List Degree Requirement, Years' Experience, and Certifications
- Bachelor's degree, preferably in IT, Business, or Information Security required.
- Seven years of experience working in the information security field is required.
- Advanced security certifications (SecurityX, GSEC, CISA, OSWE, OSCP, DSOE or equivalent or
advanced cloud security certification) is required. CISSP, CISM, CRISC or equivalent certification
is required. - Five to seven years of experience working in the information technology field is desired.
- Ten to fifteen years of experience working in the information security field is desired.
- Master’s degree in an Information Security or Information Technology related field is highly
desired. - Experience with application development, SQL databases, DevOps/DevSecOps, and CI/CD
platforms is highly desired. - An insurance background is highly desired.
Terms and Conditions
This description is intended to describe the general content of and requirements for the
performance of this position. It is not to be construed as an exhaustive statement of duties,
responsibilities, or requirements.
Because the company’s niche is the church and related ministries market, and because effective
service requires a thorough understanding of this market, persons in this position must be
familiar with church operations and must conduct themselves in a manner that will neither
alienate nor offend persons within this target niche.
Brotherhood Mutual Insurance Company reserves the right to modify, interpret, or apply this
position description in any way the company desires. This job description in no way implies that
these are the only duties, including essential duties, to be performed by the employee occupying
this position. This position description is not an employment contract, implied or otherwise. The
employment relationship remains “at-will”.