Director, Senior Cloud Security Architect
About the role
BNY is seeking a Senior Cloud and AI Security Architect to define and drive the enterprise cloud security architecture strategy while enabling the use of AI to enhance cloud security capabilities. This role combines deep expertise in cloud platforms, cybersecurity architecture, and security engineering with strong knowledge of AI-driven technologies and their practical application in security.
The role holder leads the design of secure, scalable, and resilient cloud architectures, establishes security standards and reference patterns, and acts as a strategic advisor on how AI can be leveraged to improve cloud security posture, automate controls, strengthen threat detection, and increase operational efficiency. This role also supports the development and execution of Cloud Security Strategy and Governance. The position is based in New York, NY or Pittsburgh, PA.
Responsibilities
- Define and lead the cloud security architecture strategy across enterprise cloud platforms and services.
- Develop and maintain cloud security reference architectures, design patterns, standards, and guardrails.
- Act as an AI enabler for cloud security by identifying, assessing, and promoting AI use cases that improve security outcomes.
- Drive the adoption of AI-driven capabilities for threat detection, risk analysis, automation, incident response, and security operations.
- Partner with cloud engineering, platform, data, AI, and cybersecurity teams to integrate AI securely and effectively into cloud security processes and tooling.
- Evaluate emerging cloud security and AI technologies and recommend innovations that enhance resilience, efficiency, and risk management.
- Advise senior leadership and key stakeholders on cloud security risks, architecture decisions, and strategic technology direction.
- Support security transformation initiatives by embedding security-by-design and automation-by-design principles into cloud adoption programs.
- Define secure cloud design principles and reference patterns, mapping architecture decisions to NIST SP 800-53 controls and related enterprise requirements.
- Work with platform operational teams, DevOps, and application teams to operationalize security architecture decisions through reusable patterns, automation, and policy enforcement.
- Review high-risk cloud initiatives, balance and document residual risks, and support audits and regulatory reviews with defensible architecture rationale.
- Support the development and execution of the enterprise Cloud Security Strategy, defining cloud security standards, governance processes, and architecture review criteria.
- Partner with risk, compliance, and audit stakeholders to ensure cloud security architecture remains aligned with enterprise obligations and regulatory expectations.
- Define the target-state posture management architecture across third-party and cloud-native capabilities, establishing standards for preventing and detecting cloud misconfigurations.
- Drive adoption of AI capabilities to improve threat detection, posture analysis, risk prioritization, and security operations efficiency.
- Help streamline cloud security tooling, processes, and workflows through intelligent automation and AI-driven insights.
Requirements
- 10+ years of cloud security architecture, enterprise security architecture, or cybersecurity engineering experience.
- 7+ years of direct experience designing and securing cloud environments in one or more major cloud service providers such as Azure, AWS, GCP, or OCI.
- Deep understanding of cloud security principles including IAM, zero trust, network segmentation, encryption, key management, logging, monitoring, and workload protection.
- Strong understanding of AI and machine learning concepts, with practical experience applying AI to cybersecurity or security operations use cases.
- Experience with security automation, orchestration, analytics, and AI-driven security tooling.
- Ability to translate complex technical concepts into clear architectural direction for technical and non-technical stakeholders.
- Excellent stakeholder management, communication, and influencing skills.
- Proven ability to lead cross-functional initiatives in complex enterprise environments.
- Experience with CSPM/CNAPP tools such as Wiz.
- Experience with cloud-native posture and policy services, container and Kubernetes security, API security, and CI/CD security architecture.
Preferred Qualifications
- Familiarity with NIST 800-53, CSF, CIS Benchmarks, CSA CCM, and OWASP guidance.
- Experience with cloud security tooling such as CSPM, CNAPP, DSPM, CWPP, or SIEM integrations.
- Relevant certifications such as CISSP, CCSP, AWS Security Specialty, Azure Security Engineer Associate, or Google Professional Cloud Security Engineer.
- Master’s degree in computer science, engineering, cybersecurity, or a related discipline.
Benefits
BNY offers highly competitive compensation, benefits, and wellbeing programs rooted in a strong culture of excellence and a pay-for-performance philosophy. Benefits include:
- Access to flexible global resources and tools for personal and financial wellbeing.
- Generous paid leaves, including paid volunteer time.
Pay
The base salary for this position is expected to be between $83,000 and $310,000 per year at the commencement of employment, determined based on experience and market location. This is part of a total compensation package that may also include commission earnings, discretionary bonuses, short and long-term incentive packages, and company-sponsored benefit programs.