Jobs and Careers
TH

Senior Security Architect

The New York Public Library
Crystal Building 40 W20th St, United Statesfull_timeVerifiedPosted 27 Apr 2025
💰 $145,000/yr($130,000/yr$145,000/yr)

About the role

Senior Security Architect

Department: Information Technology

Employment Type: Full Time

Location: Crystal Building 40 W20th St

Reporting To: Jay Haque

Compensation: $130,000 - $145,000 / year


Description

This role requires onsite work in NYC; this is not a remote role.

Overview
The Senior Security Architect will focus on enhancing the effectiveness of cybersecurity practices,  embedding secure development practices within CI/CD pipelines, increasing automation, and integrating security measures into the development pipeline. This role involves hands-on oversight of key security tools and processes to ensure the organization's security posture is continuously improving through tighter alignment with modern infrastructure-as-code (IaC) and application development workflows using AWS, GCP, and GitHub Enterprise.

This position will have a wide breadth of access across the cybersecurity tools ecosystem and will focus on adoption, automation, and continuous improvements. This includes tools across the security landscape - vulnerability management, configuration management, SIEM/Logging, access management, CI/CD security testing (e.g., SAST, DAST, secrets scanning), SOAR, etc.

The role will interface with key stakeholders across the business including other technology teams and business department leaders and have significant influence on the cybersecurity ecosystem and focus on the hands-on execution of security measures, including implementing, optimizing, automating, and troubleshooting technical defenses, especially in development workflows involving code repositories, build pipelines, and infrastructure-as-code templates.

We are looking for someone we can count on to: Manage:
  • Cybersecurity tools and processes
  • Technical systems and capabilities including automation and distribution
  • Relationships with technology partners 
  • Roadmap of improvements and enhancements
  • Relationships across engineering teams (networking, devops, systems, app dev, etc.)
Teach:
  • General cybersecurity awareness and business justifications 
  • Best practices employed to secure computing environments
  • Methods of using available toolsets to improve overall cyber posture
  • Work closely with other departments to ensure understanding of cybersecurity
  • Work with colleagues across the business to ensure clear expectations are set
Learn:
  • NYPL’s cybersecurity tools
  • Automation mechanisms - SOAR, scripting, APIs, etc.
  • Understand Library’s unique place in providing network access as a means to accomplish its mission.
  • NYPL’s business and services to better understand the organization's risk profile.
  • Emerging technologies that simplify security management
Improve:
  • Operational efficiency
  • General awareness of cybersecurity
  • Cohesion amongst toolset
  • Security and compliance coverage across CI/CD pipelines
  • Code review and IaC validation through GitHub Enterprise integrations
  • Security posture management across engineering teams
Some expectations for this role are that within: 1 month, this person will:
  • Understand the organization’s risk profile and cybersecurity tools
  • Assess current cybersecurity technical processes and identify potential areas for improvement
  • Begin engaging with key stakeholders across security, development, and infrastructure teams
3 months, this person will:
  • Start implementing approved improvements or automation for routine security tasks; being actively hands-on on these platforms and systems (Windows, Linux, Networking)
  • Enhance integration between security tools for improved visibility and incident response
  • Continue adoption of GitHub Enterprise Actions and integrations for code scanning, secret detection, and dependency vulnerability scanning
  • Support infrastructure-as-code validation using tools like Checkov, tfsec, or CloudFormation Guard
  • Begin incorporating security testing into the development pipeline
6 months and beyond, this person will:
  • Fully integrate security testing suggestions into the development workflow
  • Continue refining automation processes and security practices across infrastructure
  • Propose ongoing improvements based on performance metrics
Responsibilities: 
  • Oversee the management and optimization of key cybersecurity tools and processes, including vulne

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

The New York Public Library

View company profile →