Jobs · Information Technology · Maryland

Director of Enterprise Security Design

Dexian · Columbia, MD · 4 days ago
Information TechnologyFull-time

Must be local to Washington, D.C. area.

About the Role

The Director, Enterprise Security Architecture & Design is responsible for defining and executing the organization's enterprise security architecture strategy, ensuring security principles are embedded across business and technology initiatives. This leader acts as a trusted advisor to executive stakeholders, driving security-by-design practices, establishing architecture standards, and leading cross-functional efforts to identify, assess, and mitigate cybersecurity risk. This role maintains a forward-looking perspective on emerging threats, evolving technologies, regulatory requirements, and business objectives to strengthen organizational security posture, resilience, and operational effectiveness.

Responsibilities

  • Security Strategy & Architecture
    • Develop and maintain the enterprise security architecture roadmap aligned to business and technology objectives.
    • Establish and promote security-by-design principles across infrastructure, applications, cloud platforms, and data environments.
    • Define enterprise security standards, reference architectures, and engineering guardrails.
    • Translate business requirements into scalable security capabilities and controls.
    • Influence enterprise technology decisions to ensure security considerations are integrated into architectural planning and implementation.
    • Lead long-term cybersecurity maturity and transformation initiatives.
  • Executive Leadership & Governance
    • Serve as a strategic advisor to executive leadership on cybersecurity risk, security investments, and technology initiatives.
    • Present security strategies, key risks, mitigation plans, and investment recommendations to senior stakeholders.
    • Participate in governance committees, architecture review boards, and risk management forums.
    • Provide leadership for enterprise-wide security transformation efforts.
    • Drive prioritization of remediation activities based on organizational risk and business impact.
  • Risk Management & Security Operations
    • Lead security risk assessments for technology initiatives, change requests, and strategic programs.
    • Evaluate cybersecurity risks associated with major technology implementations, digital transformation initiatives, and business changes.
    • Establish and oversee risk-based vulnerability management practices.
    • Partner with engineering and operational teams to remediate identified vulnerabilities and security weaknesses.
    • Conduct threat and risk assessments to identify emerging concerns and control gaps.
  • Security Monitoring & Incident Response
    • Support and optimize enterprise security technologies, including SIEM, endpoint protection, identity security, network security, vulnerability management, and detection platforms.
    • Analyze outputs from security monitoring and assessment tools and coordinate remediation activities.
    • Lead or support incident investigations, root cause analyses, and corrective action planning.
    • Develop and maintain incident response strategies and playbooks.
    • Monitor emerging threats and recommend appropriate security enhancements.
  • Metrics & Reporting
    • Develop security KPIs, operational metrics, and executive dashboards.
    • Establish meaningful reporting mechanisms to measure program effectiveness, risk reduction, and cybersecurity maturity.
    • Communicate security performance and risk posture to business and technology leadership.

Requirements

  • Experience
    • 10+ years of progressive cybersecurity experience.
    • 5+ years leading security architecture, security engineering, or enterprise cybersecurity programs.
    • Experience securing complex environments spanning on-premises, cloud, and SaaS platforms.
    • Experience developing enterprise security strategies, roadmaps, and governance frameworks.
    • Proven ability to influence executive stakeholders and communicate risk-based recommendations.
    • Experience leading cross-functional initiatives within matrixed organizations.
    • Experience managing penetration testing and vulnerability remediation programs.
    • Experience supporting regulatory, compliance, or security frameworks such as NIST, ISO 27001, SOC 2, PCI-DSS, HIPAA, or comparable standards.
  • Preferred Experience
    • Zero Trust architecture design and implementation.
    • Microsoft security ecosystem, including Defender, Sentinel, Entra ID, and Purview.
    • Cloud security experience in Azure and/or AWS.
    • Enterprise threat modeling and risk assessment methodologies.
    • Leadership during significant cybersecurity incidents.
    • Large-scale technology transformation initiatives.
    • Security architecture within highly regulated industries.
    • Familiarity with AI governance, security, and risk considerations.
  • Certifications
    • Required
      • CISSP
      • Azure Security Engineer (AZ-500)
      • GIAC Certified Incident Handler (GCIH)
    • Preferred
      • CCSP
      • SABSA
      • TOGAF
      • AWS Security Specialty
      • Additional GIAC certifications
  • Education
    • Bachelor's Degree required.
    • Master's Degree preferred.

Similar jobs