You won't be handed a finished program. You will design it. Working at the intersection of security engineering, enterprise architecture, and business strategy, you will establish the frameworks, reference architectures, and technical standards that govern how AlphaSense builds and operates its technology environment securely at scale
This role requires deep technical expertise paired with the ability to influence executive stakeholders, shape cross-functional programs, and operate as a force multiplier across Security Operations, Integrated IT, Information Engineering, and the business
Own the architecture: Define and maintain the enterprise security architecture across Zero Trust, identity, network, endpoint, SaaS, infrastructure, mobile, and OT domains
Set the standard: Author and govern security architecture principles, reference designs, and technical standards adopted across the organization
Lead without authority: Drive alignment across Security Operations, Corporate Technology, Information Engineering, and Integrated IT teams through technical credibility and structured decision-making
Anticipate risk: Identify architectural gaps and emerging threat vectors before they become incidents, and prescribe remediation roadmaps
Accelerate programs: Provide architecture leadership for strategic security initiatives including Zero Trust maturity, identity consolidation, SaaS governance, and device trust
Define and own the Zero Trust and Device Trust architecture strategy, including network segmentation, ZTNA policy design, and enforcement model across corporate and remote environments
Architect Cloudflare WARP/Access and equivalent controls for secure remote access, replacing legacy VPN patterns with identity-aware, context-driven enforcement
Design network security architecture for all office and data center environments including Meraki SD-WAN, firewall policy, 802.1X, and DNS security
Establish architecture standards for microsegmentation, East-West traffic inspection, and lateral movement prevention
Own the enterprise identity architecture spanning Okta, SAML/OIDC federation, SCIM provisioning, MFA, Privileged Access Management (PAM), and lifecycle governance across AlphaSense and Tegus tenants
Design device trust and certificate-based authentication frameworks integrating MDM (Kandji, Intune), Okta FastPass, TPM/Secure Enclave, and hardware-bound credentials
Define role-based access control (RBAC) architecture and Joiner-Mover-Leaver (JML) automation patterns for consistent enforcement across 200+ enterprise applications
Architect identity federation patterns for M&A integrations, third-party partners, and customer-facing systems
Define the enterprise endpoint security architecture across macOS, Windows, and mobile platforms, including EDR (CrowdStrike Falcon), MDM policy standards, and patch management architecture
Design mobile device management architecture for corporate and BYOD scenarios, establishing enrollment profiles, compliance policies, and conditional access integration
Establish architecture standards for endpoint hardening, application allow-listing, DLP controls, and removable media policy
Provide architectural oversight for RMM tooling and remote management capabilities, ensuring security boundaries and abuse-resistance controls are embedded by design
Define the SaaS security architecture program: vendor risk tiering, security review criteria, integration security standards, and ongoing posture monitoring frameworks
Architect CASB, SSPM, and SaaS access governance controls to ensure visibility and enforcement across the business application portfolio
Establish data classification and DLP architecture for SaaS environments including Google Workspace, Microsoft 365, Salesforce, and Workday
Design AI/shadow SaaS governance architecture, including browser isolation, OAuth scope enforcement, and sanctioned AI tooling controls
Define security architecture standards for on-premise and cloud-hosted internal infrastructure including IDF/MDF environments, server rooms, physical access control systems (Brivo), and AV infrastructure
Architect logging, SIEM integration, and telemetry collection frameworks ensuring consistent visibility across infrastructure, identity, network, and endpoint layers
Design disaster recovery and resilience architecture for critical corporate infrastructure, including offline backup strategies and clean-room recovery playbooks
Develop OT security architecture standards for physical and building systems including access control hardware, environmental sensors, and network-connected facility equipment
Define segmentation and monitoring architecture to isolate OT environments from corporate IT networks, reducing blast radius and unauthorized access risk
Establish a vulnerability management framework for OT assets, accounting for patching constraints and availability requirements unique to operational environments
Maintain a living enterprise security architecture document and domain-level reference architectures, keeping them current with technology changes and threat landscape evolution
Conduct security architecture reviews for new technology programs, vendor onboarding, and significant infrastructure changes — providing actionable guidance rather than just approval/denial
Define security requirements and acceptance criteria for strategic projects in partnership with Product Security, Engineering, and Corporate Technology
Produce architecture decision records (ADRs) and security design patterns that teams can reuse, reducing review cycle time and engineering rework