Enterprise Security Architect
Corebridge FinancialAbout the role
Who We Are
At Corebridge Financial, we believe action is everything. That’s why every day we partner with financial professionals and institutions to make it possible for more people to take action in their financial lives, for today and tomorrow.
We align to a set of Values that are the core pillars that define our culture and help bring our brand purpose to life:
• We are stronger as one: We collaborate across the enterprise, scale what works and act decisively for our customers and partners
• We deliver on commitments: We are accountable, empower each other and go above and beyond for our stakeholders
• We learn, improve and innovate: We get better each day by challenging the status quo and equipping ourselves for the future
• We are inclusive: We embrace different perspectives, enabling our colleagues to make an impact and bring their whole selves to work
About the role
The Enterprise Security Architect will help to lead the design, implementation, and oversight of secure systems and architectures across our organization. This role is critical to embedding security into enterprise processes, aligning with industry standards, and building a scalable security foundation. The ideal candidate will bring deep technical expertise, strong communication skills, and the ability to work independently or collaboratively to drive security initiatives and foster a security-first culture.
- Design, document, and maintain secure architecture patterns, diagrams, and reference architectures to guide security implementations across the organization.
- Conduct comprehensive security reviews of applications, systems, and networks, identifying vulnerabilities and recommending secure design strategies.
- Perform threat modeling and risk assessments to identify potential vulnerabilities and recommend appropriate mitigating controls.
- Partner with enterprise and line-of-business architects to integrate security seamlessly into designs and processes.
- Translate complex technical security concepts into clear, actionable insights for C-level executives, business leaders, non-technical stakeholders, and technical engineering teams.
- Recommend mitigating controls, security tools, and remediation strategies to address security gaps and minimize risk.
- Stay current on security threats, vulnerabilities, and technologies to enhance the organization’s security posture.
- Promote a security-first culture by mentoring technical teams, educating stakeholders, and embedding security best practices into organizational workflows.
Please note: The job can only be performed in the State location listed: Jersey City, NJ, Durham, NC, and Houston, TX.
What we are looking for
Required Qualifications:
- 7+ years of hands-on experience in infrastructure, systems, networks, applications, or cloud security.
- Ability to create and review diagrams using tools such as Visio or Lucidchart.
- Familiarity with secure architecture patterns, reference architectures, and frameworks.
- Expertise in SaaS, PaaS, and IaaS environments, including platforms like AWS, Azure, M365, and Salesforce.
- Experience working with various identity and access management (IAM) solutions such as CyberArk, Okta, Ping Identity, Entra ID/Azure AD, and other tools supporting SSO, MFA, and PAM.
- Familiarity with tools like Jira, Confluence, and ServiceNow for workflow management and documentation.
- Expertise in threat modeling, vulnerability management, and risk assessments.
- Working knowledge of regulatory requirements and compliance standards such as NYDFS, CCPA, GLBA, PCI-DSS, HIPAA, SOX, and GDPR.
- Relevant certifications such as CISSP, CCSP, or equivalent.
- Ability to work independently or collaboratively in a team-oriented environment.
- Bachelor’s degree in a relevant field or proven record of experience in Information Technology and Cyber Security roles.
Technical Skills:
- Familiarity with protocols such as SAML, OAuth, OIDC, FIDO, PKI, JWT, LDAP, and Kerberos.
- Strong knowledge of common network protocols, including TCP/IP, HTTP/HTTPS, DNS, SMTP, SNMP, SSH, and VPN technologies.
- Expertise in encryption technologies (e.g., TLS, AES, RSA) and key management practices (e.g., KMS, HSM, PKI).
- Familiarity with firewalls, IDS/IPS, WAF, VPN, Routers, Switches, Load Balancers, Zero-Trust, microsegmentation, and SD-WAN security solutions, CASB, Proxy, SSE.
- Experience with SIEM tools such as Splunk, QRadar, or ArcSight and logging/monitoring best practices.
- Knowledge of Docker, Kubernetes, EKS, ECS, and OCP, including
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s