Staff Cybersecurity Architect - Security Controls
Reinsurance Group of AmericaAbout the role
You desire impactful work.
You’re RGA ready
RGA is a purpose-driven organization working to solve today’s challenges through innovation and collaboration. A Fortune 200 Company and listed among its World’s Most Admired Companies, we’re the only global reinsurance company to focus primarily on life- and health-related solutions. Join our multinational team of intelligent, motivated, and collaborative people, and help us make financial protection accessible to all.
The Staff Cybersecurity Architect - Security Controls is a strategic and technical authority responsible for designing, implementing, validating, and continuously improving enterprise security controls and guardrails. This role operationalizes policy, risk, and regulatory requirements into controls as code and evidence as data, ensuring controls are default secure, measurable, resilient, and audit ready across endpoint, data, identity, and detection/telemetry domains. The Security Controls Architect partners deeply with engineering and platform teams to embed secure by default patterns across hybrid environments and target operating systems (Windows, macOS, RHEL, Windows Server), driving automated control health reporting, immutable audit evidence, and friction reducing guardrails that enable the business.
Principle Duties
Design, develop, and implement the technical direction for enterprise security control architectures, translating policy, risk, and regulatory obligations (e.g., NIST CSF/800-53, CIS Controls, ISO 27001, PCI-DSS) into measurable technical patterns and reference implementations.
Champion secure by default guardrails over gates—standard baselines, configurations, and self-service patterns that enable teams while reducing risk across endpoints, data, identity, and detection.
Define processes to enable control threat modeling and risk analyses; anticipate adversary tactics and engineer preventative and detective control coverage with traceable success criteria.
Ensure controls are operationalized and continuously validated with automated SLIs/SLOs, drift detection, regression testing, and machine-verifiable audit evidence routed to dashboards and scorecards.
Author and maintain enterprise control standards, reference architectures, RACI models, exception handling patterns, and technical guardrails to drive consistency and scalability.
Partner with endpoint, data, identity, network, cloud, and enterprise architecture teams to embed controls into SDLC and change management, aligning decisions with business priorities and service reliability.
Convert business risks and authoritative requirements into testable technical controls; maintain end-to-end traceability from objective → configuration items → validation tests → evidence artifacts.
Evaluate and standardize strategic platforms for control efficacy and architectural impact, including Splunk Cloud, Cribl Cloud, CrowdStrike Falcon, Microsoft Defender, Microsoft Purview, Varonis Data Security, and Tines.
Define and enforce scalable identity, access, and privileged access guardrails; implement automated backstops (e.g., sensor re-enrollment, quarantine workflows, tamper protection).
Contribute to incident response planning and post incident reviews by delivering resilient control patterns, hardening packs, and validation procedures to prevent recurrence.
Provide technical leadership and coaching on controls as code, test harnesses, adversary/atomic testing, and automation first practices across PowerShell, Python, Bash, REST APIs, and Git-based workflows.
Continuously assess and improve control posture through Splunk based control health scorecards (coverage %, pass/fail, drift, MTTR, false positive/negative rates, exception aging) and executive ready reporting.
Design, implement, and continuously improve telemetry architectures and quality gates, ensuring normalized schemas, required data sources, and cost/fidelity/coverage balancing via Cribl → Splunk pipelines.
Serve as security controls technical architecture representative in enterprise forums and governance bodies; advocate for security priorities, influence technology roadmaps, and align control strategies with broader enterprise objectives.
Perform other duties as assigned.
Education
Bachelor's degree in arts/sciences (BA/BS) or equivalent experience – Required
Active CISSP certification – Preferred
Additional certifications (e.g., Microsoft SC-200/SC-400/AZ-500, Splunk Core Power User/Architect, CrowdStrike CCFA/CCFR, Varonis DSE, Jamf, RHCSA/RHCE, CISM, CSSLP, GIAC) – Preferred
Work Experience
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s