Senior Manager, Security Architecture
Simpson Thacher & Bartlett LLPAbout the role
The Senior Manager, Enterprise Security Architecture, is responsible for developing and leading a modern security architecture framework that ensures systems, applications, and data are secure by design. This role drives the evaluation, integration, and governance of security solutions, including AI-enabled capabilities—that align with business objectives and evolving threat landscapes. The position establishes enterprise technical standards, embeds risk mitigation strategies, and leverages cyber threat intelligence to proactively identify, assess, and address emerging risks.
The ideal candidate is a hands-on engineer with deep expertise in security frameworks, infrastructure, and cloud environments as well as a strong understanding of AI-driven security use cases and adversarial risks. They bring a strong security mindset—thinking like an attacker to identify and address vulnerabilities—and excel at influencing and collaborating across teams. This individual is adaptable, meticulous, and able to navigate complexity, solve problems quickly, and drive effective outcomes in a dynamic environment. This is an individual contributor role.
ESSENTIAL JOB DUTIES & RESPONSIBILITIES
Define, establish, and continuously evolve the enterprise security architecture framework aligned to business and technology strategy.
Develop and maintain target-state security architecture roadmaps, ensuring alignment with enterprise architecture and business objectives.
Participate in Firm’s IT architecture review board to ensure that new initiatives and related projects adhere to Firm security architecture strategy, including review and approval of key design documents.
Architect and guide secure implementations across hybrid environments, including on-premises, cloud, and containerized platforms.
Establish and enforce secure configuration management and system hardening standards.
Define standards and best practices for secure use of AI, including data protection, access controls, and safe consumption patterns.
Evaluate and secure enterprise adoption of AI-powered tools, platforms, and third-party services.
Partner with engineering teams to embed security controls into AI/ML lifecycles.
Create technical security standards and guidelines for all IT assets, including servers, endpoints, cloud platforms, hypervisors, mobile devices, network devices, and emerging technologies.
Conduct security architecture reviews to identify gaps, risks, and drive remediation strategies.
Document the impact of new systems and integrations on the Fim’s overall security posture.
Oversee the security tools portfolio, ensuring effective selection, deployment, and integration across the technology stack.
Lead proof of concepts, testing, and integration of new security tools, services, configurations, and risk mitigation strategies.
Design and implement cybersecurity solutions to prevent unauthorized access, detect threats, and mitigate cyber-attacks across IT systems.
Function as a trusted advisor to business, IT teams, and product organizations on security architecture and technology risk management.
Define, and report key performance indicators (KPIs) to measure security effectiveness and maturity.
Stay current on emerging threats, technologies, and industry trends to proactively reduce organizational risk.
Build strong cross-functional partnerships across global teams and external stakeholders.
EDUCATION
Required
Bachelor’s degree in information security, IT, related discipline, or equivalent experience
Preferred
Professional certifications such as CISSP, CCSP, CISM, or similar
SKILLS AND EXPERIENCE
10+ years of experience in an IT or Information Security role, with at least 5 years of experience in an enterprise or security architecture role
Strong technical knowledge of security frameworks, security tools, encryption standards, authentication and authorization standards and infrastructure security standards
Deep expertise across security domains – Infrastructure Security, Identity and Access Management, Data Protection and Application Security
Knowledge of AI/ML, cloud platforms, and hybrid architecture.
Experience planning and building enterprise cloud security at scale and mitigating security threats in the cloud.
Experience working in a global organization and broad knowledge of security domains, technology risk management concepts, and a working knowledge of security and risk frameworks.
Knowledge of com
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s