Enterprise Information Security Engineer/ Architect
Senior
Analytics
Cloud Platforms
Cybersecurity Tools
Data Security
Enterprise Architecture
Enterprise Risk
Identity and Access Management
Incident Response
Information Security
Information Technology (IT)
InfoSec
Log Management
Risk Governance
Risk Management
Security
Security Compliance
Security Operations
Solution Architecture
Splunk Enterprise Security
Job Description
The Enterprise Information Security Engineer/Architect will design secure enterprise solutions and implement robust measures to safeguard Church Pension Group’s information assets and staff. The role ensures security is embedded across on-premises, cloud-hosted, SaaS, and other vendor services, while overseeing monitoring, incident response, compliance, and vendor management, with a focus on clear cross-team collaboration.
Responsibilities
- Architect Systems and Solutions: Develop security architectures that enable identification, protection, detection, response, and recovery from cyber threats; translate threat assessments, risk modeling, system analysis, and regulatory requirements into concrete security requirements; craft integration plans for existing infrastructure and future solutions.
- Security Operations: Deploy and manage security technologies such as firewalls, encryption, SIEM, DLP, and IDS/IPS, either directly or in collaboration with other teams and MSSPs; monitor networks and systems for breaches and anomalies, ensuring accurate metrics; conduct vulnerability assessments and penetration testing, and manage related services; maintain relationships with multiple security tool vendors.
- Governance and Compliance: Create and maintain security policies, standards, and procedures to sustain a secure environment and regulatory compliance; address remediation and engage in organizational discussions; develop action plans to harden systems and respond to security and disaster recovery events.
- Risk Management: Identify, evaluate, and report information security risks; perform regular risk assessments and propose mitigation strategies.
- Education and Awareness: Educate staff on cybersecurity best practices and the security program; design or source training to address gaps and remediation; oversee IT compliance and collaborate on corporate compliance measures; advise business units on secure configurations, vendors, and architectures.
- Support Leadership: Assist the EISO in security event management, cross-team collaboration, and planning and budgeting; continue developing both technical and management capabilities.
- Collaboration and Presence: Regular on-site collaboration is required to foster relationships and effective teamwork.
- Other duties may be assigned.
Requirements
- Strong grounding in cybersecurity principles, frameworks, and tools.
- Experience with a broad set of tools including IDS, IPS, firewalls, and SIEM systems.
- Deep understanding of Cloud Security and SaaS Vendor Security.
- Proficiency in risk assessment, incident response, and threat modeling.
- Excellent communication skills to enable cross-functional collaboration.
Technologies
- IDS, IPS, firewalls
- Encryption
- SIEM, DLP
- AWS, Azure
- Microsoft 365, Entra ID
- Splunk, CrowdStrike, Darktrace, Tripwire
Benefits
- Medical (including Vision) and Dental
- Employer funded defined benefit pension plan with five year vesting
- Life Insurance for employee, spouse, and dependents
- AD&D Insurance
- Short-Term and Long-Term Disability coverage
- Business Travel Accident Insurance
- Worker’s Compensation and Employee Assistance Program
- Retiree health insurance (eligible after 10 years) and retiree life insurance
- 401(k) with immediate vesting and employer matching
- Flexible Spending Accounts and Commuter Benefits
- New York 529 College Savings Program (NY State residents)
- Educational Assistance Program for eligible employees
- Parental Leave and various Time Off options (Vacation, Sick, Personal, Holidays)
- Discretionary annual incentive program
Physical Demands
- Extensive use of a computer keyboard to perform essential duties.
Work Environment
- Hybrid work arrangement with in-office presence required Tuesday through Thursday, and flexibility to work remotely on Mondays and Fridays.
- Employees are expected to maintain a professional, compassionate, and trustworthy work environment.
- Reasonable accommodations may be provided to enable performance of essential functions for individuals with disabilities.