Technology Cloud Security Architect

Cooley LLP
  • Boston, MA
  • $120,000–$175,000 Per Year
4 days ago

Job Description

Technology Cloud Security Architect

Cooley is seeking a Technology Cloud Security Architect to join the Security team.

About Cooley: Cooley is a global law firm with an expansive practice and more than 3,000 employees and partners worldwide. We value and celebrate diverse perspectives and strive to create a workplace where every individual can thrive. At the core of Cooley's success is the exceptional talent and unwavering spirit of our people. We embrace individuality while fostering a 'one-firm' culture where collaboration and creativity thrive. Our people are the foundation of our success and the driving force behind everything we do.

Hybrid Schedule Philosophy: As part of the Cooley culture, we recognize and appreciate the value of being together, in person, to build comradery with others in the office and to be a contributing member of the Cooley office. However, we also appreciate the benefits and flexibility that come from remote working. As such, the default assumption for employees and partners is a hybrid schedule: some in-office presence and some work from home days absent certain essential in-office roles that require five (5) days/week in-office.

Position Summary: Cooley Technology embraces a culture of customer service excellence, and all members of the department are expected to move this agenda forward. To that end, the Technology Cloud Security Architect is expected to recognize that the Cooley Technology department is a service organization first and foremost and will be evaluated on this requirement equal in importance to the technical or operational responsibilities outlined later in this document.

The Technology Cloud Security Architect will work to maintain and monitor the security practices and systems implemented by the Firm within our cloud environments. The Technology Cloud Security Architect will proactively identify and mitigate cyber threats to minimize architectural and operational risk. This role requires a deep understanding of advanced cloud architectures, threat detection techniques, strong analytical skills, and the ability to work collaboratively with other security professionals and other Cloud Architects on the Technology Infrastructure and Development Operations team.

Specific duties include, but are not limited to, the following:

Position responsibilities

  • Develop and maintain a comprehensive security architecture framework that aligns to the enterprise architecture strategy and the organizations strategic objectives
  • Architect, design, prioritize, coordinate, and communicate the security technologies necessary to ensure a highly secure yet usable computing environment in the Cloud
  • Develop and implement architectural reference patterns to direct the selection, development, deployment, and utilization of Technology systems across the organization
  • Perform and participate in risk and security assessments, follow and enhance the security solutions lifecycle (evaluation, purchase, build, technical policy configuration, integration into Cloud environments, and run)
  • Develop strategies to handle security incidents and coordinating responses to security breaches
  • Recommend and coordinate implementation of identity and access management controls for cloud services
  • Provide security guidance across the system development life cycle, including security architectural reviews
  • Contribute to the development and implementation of security technology solutions for complicated and more complex environments and architecture
  • Analyze business impact and exposure based on emerging security threats, vulnerabilities and risks, and recommend technologies and solutions to mitigate them
  • Ensure that cloud-based systems meet industry security standards and regulatory requirements
  • Contribute to Cloud security solutions R&D to evaluate the latest cutting-edge tools against unfilled strategic security capabilities to drive business priorities
  • Act as a subject matter expert on the implementation and capabilities of existing security controls
  • Provide direction and thought leadership to enterprise-wide initiatives applying security principles such as access control, encryption, and host security as well as state of the art and emerging technologies such as cloud computing, mobile computing, and next generation architecture
  • Identify the need for new security technology solutions; design, review and collaborate on the deployment of new solutions
  • Stay up to date with the latest developments in security technologies, including mitigation strategies, threats, tools, attack vectors, and preventative measures, to enhance the organization security posture
  • Work closely with other technology architects and engineers to ensure security is properly represented in their technology domains and integrated into their project planning to ensure consistency and compatibility
  • Actively communicate with stakeholders to drive awareness and understanding of security architecture roadmaps and directions
  • Providing training and guidance on cloud security best practices to Technology staff and other employees
  • Required to participate in a 7x24 on-call rotation
  • All other duties as assigned or required

Skills and experience:

Required:

  • After orientation at Cooley LLP, exhibit proficiency in the Microsoft Office suite, iManage and other firm applications
  • Ability to work extended and/or weekend hours, as required
  • Ability to travel, as required
  • 3+ years direct applicable experience (e.g., cloud architecture security)
  • Extensive knowledge and experience with the configuration of security controls and secure migration of enterprise applications to one of the major cloud providers such as Azure (preferred) and AWS
  • Extensive knowledge and experience with developing Cloud Security Frameworks using industry best practices such as those from the Cloud Security Alliance (CSA) and NIST CSF
  • Experience with implementing security tools and architecture in Cloud environments such as:
  • Access Controls
  • Data Loss Prevention (DLP)
  • Web Application Firewalls (WAF)
  • Secure SDLC and Software Security
  • Firewalls
  • Anti-malware and anomaly detection controls
  • Data encryption in transit and at rest
  • Network security
  • Monitoring
  • Experience with a formal requirements definition

Preferred:

  • Bachelor's degree in information technology or computer information systems
  • Knowledge of the MITRE ATT&CK framework and NIST Cyber Security Framework
  • Familiarity with common security controls in the enterprise (Firewall, Proxy, AV, SIEM, etc.)
  • Experience with incident response procedures
  • Extensive knowledge and understanding of security issues, techniques, and implications across multiple computer platforms
  • Demonstrated experience leading and developing others by providing technical guidance and leadership to project teams
  • Solid knowledge and understanding of security regulations and best practices such as the ISO 27000 family of standards.
  • Solid knowledge and understanding of systems development life cycle (SDLC).
  • Demonstrated experience translating business requirements into architectural deliverables and technical specifications
  • Demonstrated experience communicating technical information to business clients and less experienced technologists
  • CISSP, CISM or equivalent
  • Experience with CI/CD pipelines
  • Cloud Architecture and/or Cloud Security Certifications (AWS, Azure, GCP)
  • Cloud Security Alliance (CCSP, CCSK) (ISC)2
  • Additional security certifications

Competencies:

  • Exceptional customer service skills
  • Excellent analytical, problem-solving, customer service, project management and communication skills
  • Goal-oriented
  • Proven track record of excellent decision making, integrity and working with Technology management, business professionals
  • Excellent oral and written communication skills, including technical and user documentation
  • Strong organizational skills
  • Ability to work independently and under high pressure with tight schedules and deadlines
  • Ability to interact well with all levels of business professionals
  • Excellent active listening skills
  • Flexible and patient with process development/execution and adherence to instruct project management practices
  • Capable of grasping new concepts quickly and without prior experience
  • Detail-oriented
  • Ability to multi-task and work in fast-paced environment
  • Ability to interact and coordinate with several teams to achieve objectives
  • Ability to solve problems independently and simultaneously, effectively managing multiple tasks
  • Professional demeanor at all times

Cooley offers a competitive compensation and excellent benefits package and is committed to fair and equitable employment practices. EOE.

The expected annual pay range for this position with a full-time schedule is $120,000 - $175,000. Please note that final offer amount will be dependent on geographic location applicable experience and skillset of the candidate. Senior level candidates may be considered for this position and would be eligible for a higher salary range based on experience.

We offer a full range of elective benefits including medical, health savings account (with applicable medical plan), dental, vision, health and/or dependent care flexible spending accounts, pre-tax commuter benefits, life insurance, AD&D, long-term care coverage, backup care for children and/or adults and other parental support benefits. In addition to elective benefit options, benefited employees receive firm-paid life insurance, AD&D, LTD, short term medical benefits as well as 21 days of Paid Time Off ("PTO") and 10 paid holidays each year. We provide generous parental leave and fertility benefits. New employees will attend a detailed benefit orientation to learn more about our many benefits and resources.

Numbers & Facts

LocationBoston, MA
Salary$120,000–$175,000 Per Year

Skills

  • Access Controlunmatched
  • Amazon Web Services (AWS)unmatched
  • Analysis Skillsunmatched
  • Architectural Designunmatched
  • Architectural Servicesunmatched
  • Audiovisualunmatched
  • Best Practicesunmatched
  • Business Architectureunmatched
  • Business Strategyunmatched
  • Business impact analysis (BIA)unmatched
  • CCSP - Cisco Certified Security Professionalunmatched
  • CISM - Certified Information Security Managerunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Change Controlunmatched
  • Cloud Architectureunmatched
  • Cloud Computingunmatched
  • Communication Skillsunmatched
  • Computer Securityunmatched
  • Computer Systemsunmatched
  • Continuous Deployment/Deliveryunmatched
  • Continuous Integrationunmatched
  • Cryptographyunmatched
  • Customer Service Managementunmatched
  • Customer Support/Serviceunmatched
  • Detail Orientedunmatched
  • Emerging Technologyunmatched
  • Enterprise Applicationsunmatched
  • Enterprise Architectureunmatched
  • Establish Prioritiesunmatched
  • Firewallsunmatched
  • GCP (Good Clinical Practices)unmatched
  • ISO (International Organization for Standardization)unmatched
  • Identity Data Managementunmatched
  • Incident Responseunmatched
  • Industry Standardsunmatched
  • Information Technology & Information Systemsunmatched
  • Internet Securityunmatched
  • Leadershipunmatched
  • Leading Edge Technologyunmatched
  • Legalunmatched
  • Loss Preventionunmatched
  • Malwareunmatched
  • Microsoft Officeunmatched
  • Microsoft Windows Azureunmatched
  • Mobile Technologyunmatched
  • Multiplatform/Cross-Platformunmatched
  • Multitaskingunmatched
  • Network Securityunmatched
  • On Callunmatched
  • Organizational Skillsunmatched
  • Philosophyunmatched
  • Policy Developmentunmatched
  • Presentation/Verbal Skillsunmatched
  • Problem Solving Skillsunmatched
  • Process Developmentunmatched
  • Project Planningunmatched
  • Project/Program Managementunmatched
  • Regulationsunmatched
  • Regulatory Requirementsunmatched
  • Requirements Managementunmatched
  • Research & Development (R&D)unmatched
  • Resolve Customer Issuesunmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Security Analysisunmatched
  • Security Architectureunmatched
  • Security Attacksunmatched
  • Security Information and Event Management (SIEM)unmatched
  • Security Monitoringunmatched
  • Software Development Lifecycle (SDLC)unmatched
  • Strategic Planningunmatched
  • Team Playerunmatched
  • Technical Deliveryunmatched
  • Technical Leadershipunmatched
  • Technical Writingunmatched
  • Thought Leadershipunmatched
  • Time Managementunmatched
  • Training/Teachingunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • Web Application Frameworkunmatched
  • Willing to Travelunmatched
  • Writing Skillsunmatched
  • iManageunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder