Job Title: Enterprise Architect - Infrastructure and Cyber Security
Berwyn, PA, US, 19312
The Enterprise Architect – Infrastructure & Cyber Security is the senior-most architect responsible for setting and governing target-state architecture across infrastructure, network, cloud, and security domains for a global, multi-business manufacturing company. This role defines resilient, secure, and compliant technical architecture for both commercial and regulated environments.
This role partners with the Enterprise Architect - Applications, and other functional peers to deliver reliable, scalable, and cost-efficient infrastructure and security platforms aligned to business strategy. As the senior architect within the Infrastructure, Operations, Architecture & Cyber Defense organization, this role sets the target-state architecture that the infrastructure, network, identity, and security operations teams implement, and partners with Governance, Risk & Compliance on control and compliance architecture.
Responsibilities:
- Own the enterprise architecture (EA) strategy, reference architectures, and roadmaps across infrastructure, network, cloud, workplace, and security domains.
- Establish and run the Architecture Steering Committee/Review Board, patterns/standards, and technology lifecycle governance for infrastructure and security.
- Embed reference architectures and standards into technology transitions and into strategic service providers’ operations, so that security and resilience are designed in as delivery shifts toward the outsourced operating model.
- Define multi-cloud strategy (Azure/AWS), hybrid patterns, landing zones, network segmentation, SASE/SD-WAN, and edge architectures.
- Architect OT/IT convergence patterns for plant network segmentation, IIoT, and edge computing, partnering with application and operations architecture as needed.
- Evaluate emerging technologies — including AI and generative-AI adoption and their security-architecture implications — in coordination with the Data, Analytics & AI function and enterprise AI governance.
- Embed Zero Trust, identity, secrets management, PAM, and secure-by-design principles across the environment, in partnership with the Director, Cyber Engineering and Operations.
- Define enterprise logging, telemetry, and observability architecture, including SIEM and detection data sources, in partnership with the Director, Cyber Engineering and Operations.
- Ensure architectures meet SOX, NIST 800-171/CMMC, DFARS 252.204-7012, ITAR/EAR, ISO 27001, and customer contract requirements; segment and protect Controlled Unclassified Information (CUI) as required.
- Define enterprise identity and access architecture (SSO/MFA, PAM, IGA) in partnership with IAM engineering.
- Architect data center, compute, storage, and disaster recovery/business continuity strategy.
- Lead technology due diligence for M&A from an infrastructure and security perspective; define integration blueprints and post-close modernization plans.
- Rationalize infrastructure and security tooling; manage vendor strategy and total cost of ownership for infrastructure and security platforms.
- Translate strategy into executable roadmaps with milestones, budgets, and KPIs.
- Mentor a team of infrastructure- and security-focused domain architects; build an EA community of practice.
- Partner with Finance on infrastructure cost optimization (cloud FinOps, license optimization).
Qualifications:
- BS in Computer Science/Engineering or related; MS/MBA preferred.
- 10+ years in architecture/engineering with 5+ years leading infrastructure or security architecture in complex, global organizations; proven delivery at scale across cloud and network domains.
- Deep expertise in Azure/AWS architecture, landing zones, and infrastructure as code.
- Network segmentation, SASE/SD-WAN, and edge architecture experience.
- Zero Trust, IAM, SSO/MFA, PAM, EDR/XDR, data protection, and logging/observability.
- OT/IT convergence and plant network segmentation experience a plus.
- Demonstrated experience with SOX ITGCs and regulated customer requirements (NIST 800-171/CMMC, DFARS, ITAR/EAR); contract flow-down comprehension.
- Executive presence, clear storytelling, ability to influence across engineering, operations, security, and finance; vendor and SOW negotiation.
- TOGAF or equivalent EA certification; Azure/AWS architect certification; CISSP/SABSA preferred.
- Eligibility to work with export-controlled information; ability to obtain/maintain relevant clearances when required by customer programs.
- Willingness to visit manufacturing sites and suppliers globally.
- Experience in decentralized, acquisitive, multi-business manufacturing environments; able to standardize architecture while respecting business-unit autonomy.
- Familiarity with multi-provider / service-integration (SIAM) operating models in which Corporate IT owns architecture and strategic providers execute operations.
- Demonstrated ability and willingness to use AI tools to improve productivity, decision-making, work quality, and to reduce costs. The successful candidate must be able to identify appropriate AI use cases and critically evaluate AI-generated outputs.
#LI-BM1
Nearest Major Market: Philadelphia