Carpenter Technology Corporation
Posted 2mo ago

Lead Security Architect – Cloud Data & AI Platforms

Carpenter Technology Corporation
Philadelphia, Pennsylvania, United States
OnsiteFull Time
Responsibilities
  • securing platforms
  • defining roadmap
  • leading incidents
Requirements
  • 10+ years in information security/cloud architecture with 5+ years leadership
  • Experience securing cloud data/AI platforms (Microsoft Azure preferred)
  • Bachelor's in CS or related (or equiv)
  • Security certs (CISSP/CISM/CCSP) strongly preferred
Technical tools mentioned
Microsoft AzureMicrosoft Azure ADMicrosoft Azure SynapseMicrosoft FabricDatabricksTerraformMicrosoft Azure PolicyMicrosoft ExpressRouteVPCVNetKMSPKIDLPSIEMCI/CDNISTCIS Benchmarks

Job description

Carpenter Technology is seeking an experienced Security Architect to lead the security strategy and implementation for our next-generation cloud data & AI platforms. This full-time leadership role holds long-term responsibility for securing a unified analytics environment (built primarily on Microsoft Azure and related services) that will host highly sensitive and regulated data (including ITAR-controlled information). The role requires a visionary leader who can define multi-year security roadmaps and promote a security-first culture, as well as a hands-on expert capable of designing and deploying robust security controls. Operating with influence across both the enterprise cybersecurity team and the data/AI platform team, the Lead Architect will ensure security is embedded by design without stifling innovation, enabling Carpenter to deliver data-driven and AI solutions safely and in compliance with all requirements.

Key Responsibilities of Position:

  • Cloud Data & AI Platform Security Architecture: Own the security architecture and roadmap for Carpenter’s cloud-based data analytics and AI platform. Develop and maintain secure design patterns that cover data ingestion, storage, processing, and AI model deployment, ensuring controls are built-in across all components. Apply Zero Trust principles in every layer (identity, network, data access, applications) to minimize risk and attack surface. Work with leadership to align security investments with business strategy and risk appetite.
  • Identity & Access Management (IAM): Implement robust identity and access controls across the platform. Leverage enterprise identity services (e.g. Azure AD) to enforce single sign-on, multi-factor authentication, and conditional access policies. Define role-based access control (RBAC) models for data and analytics services, ensuring users and service accounts have least-privilege access. Establish governance for workspace permissions, data access roles, and secrets management (e.g., keys, credentials) using appropriate tools.
  • Data Protection & Privacy: Safeguard data in transit and at rest through encryption and strong key management. Ensure all sensitive data (including ITAR-regulated content) is encrypted end-to-end with appropriate customer-managed keys and meets required cryptographic standards. Implement data masking, anonymization, and tokenization techniques where needed. Coordinate with data governance teams to define data classification and handling rules, and enforce them through technical controls.
  • Network & Infrastructure Security: Design the network security architecture for the data platform in collaboration with infrastructure teams. Implement secure network segmentation and firewall policies that limit exposure and lateral movement (e.g., using private endpoints, VPC/VNet isolation). Ensure any hybrid connectivity or data pipelines connecting on-premises systems to the cloud are protected via encrypted channels and strict firewall rules. Continually evaluate and harden underlying cloud infrastructure components, aligning with best practices and reference frameworks (NIST, CIS benchmarks, etc.).
  • Governance, Risk & Compliance: Ensure the platform complies with internal policies and external regulations. Implement governance controls to meet standards such as ITAR, CMMC/NIST 800-171, and SOC/ISO 27001 as applicable. Define and monitor adherence to infrastructure and data security baselines across dev, test, and production environments. Work closely with risk management to assess and mitigate any platform-related risks that could impact operational continuity, data privacy, or regulatory compliance. Document security controls and provide evidence for audits and assessments as needed.
  • Data Governance & Monitoring: Integrate data governance tools (e.g., data catalog, lineage, DLP systems) with the platform to enable sensitivity labeling, data lineage tracking, and policy enforcement for data usage. Establish continuous monitoring and auditing of user activities, data access events, and configuration changes in the platform. Aggregate logs and telemetry into the corporate SIEM for advanced threat detection and maintain detailed audit trails for forensics and compliance verification.
  • AI Security & Trust: Develop security and trust frameworks for AI services and agents running on the platform. Ensure AI/ML solutions respect data access controls and do not expose sensitive information. Define Responsible AI policies and implement guardrails around AI model usage (e.g., ensuring proper training data governance, limitations on autonomous actions, and bias/ethics reviews). Collaborate with data science teams to integrate security in the AI model lifecycle, from development to deployment (e.g., secure model endpoints, API protections).
  • Incident Preparedness & Response: Institute robust incident detection and response processes for the data & AI platform. Work with the Cybersecurity Operations Center (SOC) to tailor alerting for this environment and ensure runbooks cover cloud/data-specific incident scenarios. Lead or support incident handling for any security events on the platform, including triage, containment, root-cause analysis, and recovery. Use insights from incidents and near-misses to strengthen the platform’s security posture (continuous improvement).
  • Strategic Leadership & Collaboration: Serve as the bridge between cybersecurity and data/AI teams, effectively reporting into both and aligning their objectives. Champion a culture of security-by-design and infrastructure-as-code, advising engineers and data professionals on integrating security into their workflows (automation of controls, DevSecOps practices). Provide thought leadership by tracking emerging threats and cloud capabilities, and proactively adjusting strategies to address them. Influence peers and executives through clear communication of security risks, wins, and needs, building consensus for key security initiatives.


 

KNOW-HOW

Know-How includes every kind of relevant knowledge, skill, and experience, however acquired, needed for acceptable performance in a job or role. Know-How has three dimensions: Practical/Technical Knowledge, Planning, Organizing and Managerial Knowledge; and Communicating & Influencing Skills. In the space below, please list the minimum requirements within each of the categories.

Education and/or Training:  

  • Education & Certifications: Bachelor’s degree in Computer Science, Information Security, or a related field (or equivalent experience). Master’s degree or MBA a plus. Professional certifications such as CISSP, CISM, CCSP, or relevant cloud security certifications (e.g., Azure Security Engineer, AWS Security) strongly preferred, demonstrating a commitment to ongoing professional development.

Relevant Work Experience:

  • Extensive Security & Architecture Experience: 10+ years of combined experience in information security and/or cloud architecture, including 5+ years of leadership in securing cloud data platforms or enterprise analytics solutions. Track record of successfully delivering security for large-scale data or AI platforms in a modern cloud environment.

Other Qualifications/Skills:

  • Cloud Platforms & Tools: Strong expertise in cloud security technologies and best practices. Hands-on experience with public cloud services (e.g., Azure, AWS, or GCP), with deep knowledge of securing cloud data services (data lakes, warehouses, streaming, etc.). Familiarity with modern analytics platforms (for instance, Azure Synapse, Microsoft Fabric, Databricks, or similar) and their security models is highly desirable.
  • Technical Proficiency: Demonstrated skills in key security domains:
    – Identity & Access Management: roles, SSO/MFA, identity governance.
    – Network Security: VPC/VNet design, firewalls, VPN/ExpressRoute, zero-trust network access.
    – Cryptography: data encryption strategies, key management systems (KMS), PKI.
    – Data Protection & DLP: implementing classification, DLP tools/policies, data masking.
    – Monitoring & DevSecOps: cloud logging/telemetry, SIEM integration, incident management, and automating security controls via code (e.g., Terraform, Azure Policy, CI/CD security checks).
  • Regulated Data & Compliance: Experience securing sensitive and regulated data in a cloud environment. Knowledge of regulatory frameworks (such as ITAR, HIPAA, GDPR, or similar) and experience implementing controls to comply with them. Capable of translating regulatory and risk requirements into actionable technical solutions (e.g., enforcing geo-restrictions, user screening, encryption, and auditing to meet compliance).

This Lead Security Architect role is a unique opportunity to shape the security of a flagship data & AI initiative from the ground up. The successful candidate will combine strategic foresight with hands-on expertise to ensure Carpenter’s data-driven future is built on a foundation of security, resilience, and trust.

Carpenter Technology Company offers a competitive salary and a comprehensive benefits package including life, medical, dental, vision, flexible spending accounts, disability coverage, 401k with company contributions as well as many other options to employees.

Carpenter Technology Corporation’s policy is to fully and effectively maintain a program of equal employment opportunity and nondiscrimination for all employees, to employ affirmative action for all protected classes, and to recruit and develop the best qualified persons available regardless of age, race, color, religion, sex, gender identity, sexual orientation, marital status, national origin, political affiliation or any other characteristic protected by law. The Company also will recruit, develop and provide opportunities for qualified persons with disabilities and protected veterans.

About Carpenter Technology Corporation

Public specialty-alloy manufacturer and distributor serving aerospace, defense, medical, energy, transportation, industrial, and consumer markets.

Similar jobs

Security Architect roles near Philadelphia, Pennsylvania
6d
Save
Mark Applied
Hide
Principal, Security Architect
New Brunswick or West Chester or Palm Beach Gardens or Warsaw or Raritan or Raynham
$102k-$204k/yr HybridFull Time
DePuy Synthes
DePuy Synthes: ’s private orthopaedic medical-technology business supplies surgeons and healthcare systems worldwide.
8+ YOEBachelor's degree and 8+ years in information security required, with security architecture, controls, vulnerability management, network segmentation, endpoint, cloud, and framework experience. English proficiency required.
AWS, Azure, GCP, EDR/XDR, SOAR, NIST, CIS, ISO 27001, DevSecOps, IoT
6d
Save
Mark Applied
Hide
Principal, Security Architect
New Brunswick or West Chester or Palm Beach Gardens or Warsaw or Raritan or Raynham
$102k-$204k/yr HybridFull Time
DePuy Synthes
DePuy Synthes: ’s private orthopaedic medical-technology business supplies surgeons and healthcare systems worldwide.
8+ YOEBachelor's degree and 8+ years in information security required, including security architecture, controls, vulnerability management, network security, endpoint protection, cloud security, and industry frameworks. English proficiency required.
AWS, Microsoft Azure, Google Cloud Platform (GCP), EDR, XDR, SOAR, NIST, NIST Zero Trust, CIS, ISO 27001, DevSecOps, IoT
1mo
Save
Mark Applied
Hide
Principal Security Architect
Wilmington, Delaware, United States
$127k-$236k/yr OnsiteFull Time
Berkley Technology Services
Berkley Technology Services: IT services providing software development, systems integration, networking, and help-desk support to W. R. Berkley companies.
10+ YOE5+ Mgmt10+ years cybersecurity/architecture experience, 5+ years leading transformation programs, demonstrated ZTNA/Zero Trust design, automation/SOAR and AI security controls experience, strong stakeholder and risk management skills.
ZTNA, SASE, Zscaler, Palo Alto Prisma Access, Cisco SSE, SIEM, SOAR, EDR, DLP, IAM, Microsoft Entra, Azure, AWS, GCP, Okta
3d
Save
Mark Applied
Hide
Senior Network Security Architect
Wilmington, Delaware, United States
HybridFull Time
Qnity Electronics
Qnity ElectronicsNYSE: Q: Materials and solutions for advanced electronics and high-tech industries.
Significant enterprise network security architecture or engineering experience; expertise with Palo Alto Networks, enterprise networking, Azure, cloud and on-premises security, and architecture documentation. Relevant certifications preferred.
Palo Alto Networks, NGFW, Panorama, Strata Cloud Manager, Prisma Access, GlobalProtect, Microsoft Entra ID, Defender, Microsoft Sentinel, Intune, Azure, PKI, ServiceNow, FireMon, Azure Virtual WAN, ExpressRoute, Windows 365, Azure Virtual Desktop, SIEM, VPN, DNS, TLS, NAT
1mo
Save
Mark Applied
Hide
Security Engineer / Architect
New Jersey, United States
$110k-$145k/yr RemoteFull Time
The Amynta Group
The Amynta Group: Private insurance services providing property, casualty, specialty, warranty, and protection solutions to carriers and businesses.
3+ YOE3+ years in security engineering, hands-on network, cloud and infrastructure security, experience with SIEM, Windows/Linux hardening, strong communication and threat remediation skills.
AWS, Azure, GCP, SIEM, Splunk, Microsoft Sentinel, Elastic, Python, PowerShell, Bash, OWASP Top 10
1mo
Save
Mark Applied
Hide
Senior Staff SaaS Security Architect
Boston or Berwyn or Princeton or Clifton
$120k-$203k/yr HybridFull Time
State Street
State StreetNYSE: STT: Global financial services and bank holding.
8+ YOE8+ years information security experience focused on SaaS/cloud/identity; hands-on SSPM/CASB/SSO and API security; strong OAuth/OIDC/SAML knowledge; scripting and automation skills; bachelor\u000apreferred.
Obsidian Security, OAuth, OpenID Connect (OIDC), SAML, API
4mo
Save
Mark Applied
Hide
Principal IT Security Architect - REMOTE from any EST or CST US-based location
Carmel or Chicago or Orlando or Charlotte or Minneapolis or Milwaukee or Philadelphia or Atlanta or Birmingham
$158k-$237k/yr RemoteFull Time
CNO Financial Group
CNO Financial GroupNYSE: CNO: Insurance and financial solutions for middle-income Americans.
12+ YOEBachelor’s in IT or related field; 12+ years IT experience with 5+ years as security architect; experience with DoD STIG, FedRAMP or similar; strong communication and leadership skills.
1y
Save
Mark Applied
Hide
Cloud Security Principal
Allentown or Louisville or Providence
HybridFull Time
PPL Corporation
PPL CorporationNYSE: PPL: Energy utility holding providing electricity and natural gas.
10+ YOEBachelor’s degree or equivalent experience; 10+ years of cybersecurity cloud experience; expertise in Azure, Microsoft 365, cloud architecture, security tools, IaC, scripting, frameworks, and Agile practices.
Microsoft Azure, Microsoft 365, Microsoft Endpoint Manager, Microsoft Intune, Microsoft Configuration Manager, Microsoft Defender for Cloud, Microsoft Identity and Access, Microsoft Active Directory, Microsoft Entra, ADFS, Kubernetes, Infrastructure as Code (IaC), DevOps, PowerShell, Azure CLI, VNETs, VPNs, ExpressRoute, Azure Security Center, Azure Virtual Machines, Group Policy, MFA, Azure Functions, Azure Networking, Azure IPsec Connections, Network Security Groups, Azure VDI, Azure Key Vault, CSPM, CWPP, CASB, NIST, CIS Benchmarks, SOX, NERC CIP, Agile, Python, .NET, Java, AWS, Google Cloud, CI/CD, SAFe