About the Role
This role is responsible for designing and governing security architectures for enterprise integrations, APIs, messaging platforms, event-driven architectures, managed file transfer services, and third-party connectivity solutions. It is critical for protecting the firm's applications, data, cloud platforms, and technology services in an increasingly API-driven and cloud-centric world.
Responsibilities
- Design and maintain security architectures, standards, and reference patterns for APIs, messaging platforms, event streaming services, file transfers, and third-party integrations.
- Conduct security architecture reviews for enterprise integration solutions across cloud, SaaS, hybrid, and on-premises environments.
- Define security requirements for API gateways, service-to-service communications, machine identities, partner connectivity, and integration platforms.
- Provide subject matter expertise on authentication, authorization, encryption, tokenization, secrets management, and secure integration design patterns.
- Partner with engineering and architecture teams to embed security controls into enterprise integration platforms and services.
- Assess integration security risks and recommend mitigation strategies aligned with enterprise security standards and regulatory requirements.
- Evaluate emerging integration technologies and industry trends to support future-state architecture and secure technology adoption.
Requirements
- Degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related discipline.
- 14 years or more of experience in security architecture, application security, integration architecture, middleware technologies, or related technology disciplines with at least 8 years of hands-on cybersecurity experience preferred.
- Demonstrated experience designing and securing enterprise integration platforms, APIs, messaging environments, and cloud-native services.
- Deep expertise in API security, OAuth, OpenID Connect, SAML, JWT, mTLS, PKI, secrets management, and machine identity security.
- Experience with enterprise messaging and integration technologies such as IBM MQ, Kafka, Solace, Event Hubs, RabbitMQ, MuleSoft, Apigee, Kong, Azure Integration Services, or equivalent platforms.
- Strong understanding of cloud-native architectures, microservices, containers, Kubernetes, serverless technologies, and modern application architectures.
- Experience conducting security architecture reviews, threat modeling, and risk assessments for integration and data exchange solutions.
- Knowledge of Zero Trust principles, data protection requirements, encryption technologies, and secure communication architectures.
- Professional certifications such as CISSP, CCSP, GIAC, TOGAF, SABSA, AWS Security Specialty, Azure Security Engineer, or equivalent certifications are highly desirable.
- Experience within financial services or other highly regulated industries is preferred.
- Experience supporting enterprise API programs, cloud transformation initiatives, and third-party connectivity solutions.
- Ability to work effectively with application, cloud, infrastructure, engineering, and cybersecurity teams in a global environment.
- Limited travel may be required based on business needs.
Skills
- API security
- Application integration
- Messaging security
- Service-to-service communications
- Modern integration architectures (APIs, microservices, event-driven architectures, cloud integrations, SaaS connectivity)
- Authentication and authorization frameworks (OAuth 2.0, OpenID Connect, SAML, JWT, mTLS, machine-to-machine authentication)
- Analytical skills
- Problem-solving skills
- Risk assessment skills
- Communication skills
- Stakeholder management skills
Location
- Hybrid
Work Type
- Hybrid
- Full-time
Experience Level
- 14 years or more of experience in security architecture, application security, integration architecture, middleware technologies, or related technology disciplines
- At least 8 years of hands-on cybersecurity experience preferred
Education Level
- Degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related discipline.
Salary/Compensations
- $120,000 - $202,500 Annual
Benefits
- Retirement savings plan (401K) with company match
- Insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages
- Paid-time off including vacation, sick leave, short term disability, and family care responsibilities
- Access to Employee Assistance Program
- Incentive compensation including eligibility for annual performance-based awards
- Eligibility for certain tax advantaged savings plans
- Inclusive development opportunities
- Flexible work-life support
- Paid volunteer days
- Vibrant employee networks
About the Company
- Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability.
- We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.
- We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential.
- As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most.
- Join us in shaping the future.
Equal Opportunity
- As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.
