Senior Manager, Security Architecture at Simpson Thacher & Bartlett LLP | NY, US | Rezi

Senior Manager, Security Architecture at Simpson Thacher & Bartlett LLP

Senior Manager, Security Architecture

Simpson Thacher & Bartlett LLP · NY, US

1 months ago

Senior Manager, Security Architecture

Simpson Thacher & Bartlett LLP · NY, US

a month ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

Develop and lead a modern security architecture framework to ensure systems, applications, and data are secure by design. Drive the evaluation, integration, and governance of security solutions, including AI-enabled capabilities, aligning with business objectives and evolving threat landscapes. Establish enterprise technical standards, embed risk mitigation strategies, and leverage cyber threat intelligence to proactively identify, assess, and address emerging risks. This is an individual contributor role.

Responsibilities

  • Define, establish, and continuously evolve the enterprise security architecture framework aligned to business and technology strategy.
  • Develop and maintain target-state security architecture roadmaps, ensuring alignment with enterprise architecture and business objectives.
  • Participate in Firm’s IT architecture review board to ensure that new initiatives and related projects adhere to Firm security architecture strategy, including review and approval of key design documents.
  • Architect and guide secure implementations across hybrid environments, including on-premises, cloud, and containerized platforms.
  • Establish and enforce secure configuration management and system hardening standards.
  • Define standards and best practices for secure use of AI, including data protection, access controls, and safe consumption patterns.
  • Evaluate and secure enterprise adoption of AI-powered tools, platforms, and third-party services.
  • Partner with engineering teams to embed security controls into AI/ML lifecycles.
  • Create technical security standards and guidelines for all IT assets, including servers, endpoints, cloud platforms, hypervisors, mobile devices, network devices, and emerging technologies.
  • Conduct security architecture reviews to identify gaps, risks, and drive remediation strategies.
  • Document the impact of new systems and integrations on the Fim’s overall security posture.
  • Oversee the security tools portfolio, ensuring effective selection, deployment, and integration across the technology stack.
  • Lead proof of concepts, testing, and integration of new security tools, services, configurations, and risk mitigation strategies.
  • Design and implement cybersecurity solutions to prevent unauthorized access, detect threats, and mitigate cyber-attacks across IT systems.
  • Function as a trusted advisor to business, IT teams, and product organizations on security architecture and technology risk management.
  • Define, and report key performance indicators (KPIs) to measure security effectiveness and maturity.
  • Stay current on emerging threats, technologies, and industry trends to proactively reduce organizational risk.
  • Build strong cross-functional partnerships across global teams and external stakeholders.

Requirements

  • 10+ years of experience in an IT or Information Security role, with at least 5 years of experience in an enterprise or security architecture role
  • Strong technical knowledge of security frameworks, security tools, encryption standards, authentication and authorization standards and infrastructure security standards
  • Deep expertise across security domains – Infrastructure Security, Identity and Access Management, Data Protection and Application Security
  • Knowledge of AI/ML, cloud platforms, and hybrid architecture.
  • Experience planning and building enterprise cloud security at scale and mitigating security threats in the cloud.
  • Experience working in a global organization and broad knowledge of security domains, technology risk management concepts, and a working knowledge of security and risk frameworks.
  • Knowledge of common application architectures, design, protocols, and agile deployment methodology and best practices.
  • Hands-on engineering experience across servers, endpoints, networks, mobile, and cloud computing.
  • Knowledge of core networking concepts including TCP/IP, firewalls, and network security products.
  • Ability to create and execute a clear strategic vision for target state architecture that supports and enables businesses functions.
  • Ability to manage multiple concurrent projects and activities and make effective judgments in prioritizing and time allocation.
  • Must be able to execute with limited information and ambiguity.
  • Must have a continuous learning mindset and a demonstrated aptitude for understanding strategic investments and new technologies.
  • Must be able to build collaborative relationships and is comfortable interacting frequently with leadership and internal/external stakeholders

Skills

  • Security frameworks
  • Security tools
  • Encryption standards
  • Authentication standards
  • Authorization standards
  • Infrastructure security standards
  • AI/ML
  • Cloud platforms
  • Hybrid architecture
  • Enterprise cloud security
  • Technology risk management
  • Application architectures
  • Agile deployment methodology
  • Servers
  • Endpoints
  • Networks
  • Mobile
  • Cloud computing
  • TCP/IP
  • Firewalls
  • Network security products

Location

  • NY Only

Work Type

  • Hybrid

Experience Level

  • Senior
  • 10+ years of experience
  • 5 years of experience in an enterprise or security architecture role

Education Level

  • Bachelor’s degree in information security, IT, related discipline, or equivalent experience
  • Professional certifications such as CISSP, CCSP, CISM, or similar

Salary/Compensations

  • $190,000 to $220,000

About the Company

  • Simpson Thacher & Bartlett is committed to a collegial work environment in which all individuals are treated with respect and dignity.

Equal Opportunity

  • The Firm prohibits discrimination or harassment based upon race, color, religion, gender, gender identity or expression, age, national origin, citizenship status, disability, marital or partnership status, sexual orientation, veteran’s status or any other legally protected status. This Policy pertains to every aspect of an individual’s relationship with the Firm, including but not limited to recruitment, hiring, compensation, benefits, training and development, promotion, transfer, discipline, termination, and all other privileges, terms and conditions of employment.