We are looking for a Security Architect / Risk & Compliance Lead to support a large-scale enterprise HR and Payroll transformation program in Boston, MA. This is a full-time contract opportunity working across cloud security, application security, identity and access management, SSO/MFA, risk and compliance, security architecture, and SaaS technologies. You’ll work closely with technical leadership, security teams, vendors, systems integrators, and business stakeholders to implement security controls and ensure a secure transition to a modern cloud-based solution.
The biggest opportunity here is the scale and impact of the project. You’ll have a seat at the table helping shape the security strategy for a major enterprise-wide transformation, from user access and IAM to incident response, disaster recovery, compliance, and cloud security. This is a great fit for someone who enjoys taking complex security requirements and turning them into practical technical solutions, while working across both technical and business teams. The role also provides exposure to modern SaaS, AI security, cloud environments, and large-scale security governance.
Required Skills & Experience
· 9+ years of experience in IT design and implementation, with strong experience across at least two areas such as infrastructure/network design, application development, APIs, middleware, servers/storage, databases, data security, or systems administration
· 5+ years of security architecture, design, and implementation experience
· Experience architecting and implementing cloud-based security solutions
· Strong understanding of information security risk concepts, security controls, and risk assessment methodologies
· Experience developing and documenting security architecture, security plans, policies, processes, procedures, and standards
· Strong experience with IAM, SSO, MFA, identity management, and user provisioning/de-provisioning
· Experience integrating security tools and third-party vendor solutions
· Experience with security frameworks such as NIST, ISO 2700x, ITIL, SOX, or COBIT
· Experience with risk, business impact, control, and vulnerability assessments
· Knowledge of network security, firewalls, routers, switches, and network protocols
· Experience with security technologies including PAM, DLP, encryption, endpoint security, vulnerability scanning, patch management, and automated policy compliance tools
· Strong written and verbal communication skills with the ability to work across technical and business teams
· Experience with modern issue tracking systems such as JIRA
· Bachelor's degree in Computer Science, Systems Analysis, or a related field, or equivalent experience in audit, compliance, security, or risk management
Desired Skills & Experience
· Experience securing Human Resources and Payroll systems
· Experience with Workday or Workday Prism
· Experience with Workday user security, roles, groups, and access controls
· Experience implementing security solutions within a large public-sector or enterprise environment
· Experience with AI security or implementing AI tools within an enterprise/government environment
· Experience with SaaS implementations and migration from on-premises applications to cloud-based solutions
· Experience with security audit, compliance, and governance programs
· Experience with Microsoft security tools
· Experience with Snowflake security functions
· Security certifications such as Security+
· Experience supporting disaster recovery, business continuity, backup, and incident response programs
What You Will Be Doing
Tech Breakdown
· 25% Identity & Access Management - IAM, SSO, MFA, user provisioning/de-provisioning, access controls
· 20% Cloud & SaaS Security - cloud security architecture, SaaS vendor security, security controls, integrations
· 20% Risk, Compliance & Governance - NIST, ISO, audits, risk assessments, compliance, policies and standards
· 20% Application & Data Security - application security, data access controls, vulnerability management, security requirements
· 15% Security Operations - SIEM, incident response, security monitoring, disaster recovery and business continuity
Daily Responsibilities
· 35% Hands On Security Architecture & Implementation - Design and implement security controls, review configurations, support IAM/SSO/MFA integrations, and address security vulnerabilities
· 25% Risk & Compliance - Conduct assessments, review audits, monitor vendor SLAs, track risks, and develop mitigation strategies
· 20% Technical & Business Collaboration - Partner with technical leadership, vendors, systems integrators, security teams, and business stakeholders
· 10% Security Documentation - Develop security plans, procedures, diagrams, requirements, audit documentation, and operational processes
· 10% Incident Response & Security Operations - Support incident response, review security events and logs, assess threats, and coordinate remediation
| Location | Boston, MA |
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.
Free resume templatesImprove your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.
Free resume builder