Enterprise Architect - Information Security and Compliance
Costco IT · Seattle, WA · 3 wk ago
Information TechnologyFull-time
About the Role
Costco IT is responsible for the technical future of Costco Wholesale, the third largest retailer in the world with operations in fourteen countries. We foster a family-oriented, employee-centric culture where our team thrives and succeeds. This role is part of a dynamic, fast-paced environment driving exciting transformation efforts, including building the next generation retail environment.
Responsibilities
- Partners with Enterprise Architecture to develop strategies, standards, and secure reference architectures for enterprise solutions.
- Reviews and designs new systems, embedding security and compliance requirements.
- Creates reusable security design patterns and reference architectures; drives zero trust and secure-by-design adoption across the enterprise.
- Identifies dependencies with Costco value streams and shared services based on enterprise security architectures.
- Integrates essential safeguards and practices into solution designs, documenting residual risks.
- Maintains Security-related Business Capability Hierarchies and collaborates with Security delivery teams to assess capability maturity.
- Analyzes technical risks, conducts threat modeling, and advises on risk mitigation strategies.
- Defines security patterns for machine and non-human identities, including credential lifecycle and least-privilege scoping.
- Establishes software supply chain security requirements, including SBOM visibility and secure SDLC practices aligned to NIST SSDF.
- Addresses compliance requirements such as PCI, HIPAA, PII, and SOX.
- Designs and deploys secure cloud solutions, applying best practices for cloud, hybrid, and on-prem applications.
- Defines secure patterns, standards, and governance for AI/ML, generative AI, and agentic AI systems.
- Provides security-focused architecture consulting to project teams and IT leaders.
- Develops secure API and integration patterns for internal and partner-facing services.
- Translates incident findings and threat intelligence into architectural improvements.
- Co-designs security-related integration and deployment architectures for on-premise and cloud networks.
- Supports product roadmap development based on prioritized features.
- Evaluates and recommends security technologies and services, driving consolidation of the security tooling portfolio.
- Coaches and mentors peers in Costco’s architecture framework.
- Measures and matures Costco’s Enterprise Architects practice.
- Establishes and maintains Costco's Architectural Framework and Governance Model.
- Participates in team planning and skill-building activities.
Qualifications
- 10+ years’ professional IT experience in solutioning, designing, and delivering architecture solutions for large enterprises.
- 5+ years’ experience in a senior architecture role, with expertise in IAM, networking, application security, infrastructure, and security operations.
- 5+ years’ enterprise-level experience designing and deploying secure cloud solutions (Azure, GCP, or AWS).
- 5+ years’ technical team leadership experience.
- Experience designing security standards to ensure compliance with PCI, SOX, HIPAA, GDPR, ISO 27001, and NIST.
- Experience with zero trust architecture, threat modeling, and security architecture reviews.
- Experience applying frameworks like SABSA, NIST CSF, CIS Controls, and MITRE ATT&CK.
- Strong understanding of emerging technologies, including AI/ML, and their security implications.
- Excellent verbal and written communication skills; ability to translate technical designs to diverse audiences.
- Proven leadership, collaboration, and governance skills in a large, matrixed organization.
Skills
- Interpersonal skills, including collaboration, facilitation, and negotiation.
- Experience with architecture frameworks, methods, and tools.
- Graphical modeling skills.
- Analytical and organizational skills.
- Broad knowledge of technical domains (application, information, integration, infrastructure) and business functional domains.
- Ability to assess risks and apply risk profiles to architecture alternatives.
- Understanding of enterprise politics and navigation strategies.
Recommended
- Bachelor’s degree in computer science, information systems, cybersecurity, or related field.
- Industry certifications: CISSP, CCSP, CISM, TOGAF, cloud security certifications (AWS, GCP, Azure), SABSA, CCSK.
- Experience with AI security frameworks (NIST AI RMF, ISO/IEC 42001).
- Experience securing generative AI systems and non-human identities.
- Experience with containers (Kubernetes, Docker), IaC, and DevSecOps practices.
- Understanding of Costco’s business model and legacy systems.
- Proficiency in Google Workspace applications.
Pay
Level 3: $171,000 - $205,000 (Bonus and RSU eligible)
Level 4: $201,000 - $240,000 (Bonus and RSU eligible)
Benefits
- Paid time off
- Health benefits: medical, dental, vision, hearing aid, pharmacy, behavioral health, employee assistance
- Health care reimbursement account
- Dependent care assistance plan
- Short-term and long-term disability insurance
- AD&D insurance
- Life insurance
- 401(k)
- Stock purchase plan
Costco is committed to a diverse and inclusive workplace. We are an equal opportunity employer.