AlphaSense Oy logo
Posted August 7, 2026 · 21 days agoLast seen August 27, 2026Est. expiry September 11, 2026

Enterprise Security Architect

Senior Enterprise Security Architect
About the role

We are looking for an Enterprise Security Architect to join AlphaSense's Corporate Technology organization. Reporting directly to the VP of Secure IT, this is a senior individual contributor role responsible for defining and driving the security architecture strategy across our entire enterprise technology landscape — spanning Zero Trust, identity, network, SaaS, endpoint, internal infrastructure, mobile, and operational technology. You won't be handed a finished program. You will design it. Working at the intersection of security engineering, enterprise architecture, and business strategy, you will establish the frameworks, reference architectures, and technical standards that govern how AlphaSense builds and operates its technology environment securely at scale. At the Staff level, you will: - Own the architecture: Define and maintain the enterprise security architecture across Zero Trust, identity, network, endpoint, SaaS, infrastructure, mobile, and OT domains. - Set the standard: Author and govern security architecture principles, reference designs, and technical standards adopted across the organization. - Lead without authority: Drive alignment across Security Operations, Corporate Technology, Information Engineering, and Integrated IT teams through technical credibility and structured decision-making. - Anticipate risk: Identify architectural gaps and emerging threat vectors before they become incidents, and prescribe remediation roadmaps. - Accelerate programs: Provide architecture leadership for strategic security initiatives including Zero Trust maturity, identity consolidation, SaaS governance, and device trust. Responsibilities Zero Trust & Network Security Architecture - Define and own the Zero Trust and Device Trust architecture strategy, including network segmentation, ZTNA policy design, and enforcement model across corporate and remote environments. - Architect Cloudflare WARP/Access and equivalent controls for secure remote access, replacing legacy VPN patterns with identity-aware, context-driven enforcement. - Design network security architecture for all office and data center environments including Meraki SD-WAN, firewall policy, 802.1X, and DNS security. - Establish architecture standards for microsegmentation, East-West traffic inspection, and lateral movement prevention. Identity & Access Architecture - Own the enterprise identity architecture spanning Okta, SAML/OIDC federation, SCIM provisioning, MFA, Privileged Access Management (PAM), and lifecycle governance across AlphaSense and Tegus tenants. - Design device trust and certificate-based authentication frameworks integrating MDM (Kandji, Intune), Okta FastPass, TPM/Secure Enclave, and hardware-bound credentials. - Define role-based access control (RBAC) architecture and Joiner-Mover-Leaver (JML) automation patterns for consistent enforcement across 200+ enterprise applications. - Architect identity federation patterns for M&A integrations, third-party partners, and customer-facing systems. Endpoint & Mobile Security Architecture - Define the enterprise endpoint security architecture across macOS, Windows, and mobile platforms, including EDR (CrowdStrike Falcon), MDM policy standards, and patch management architecture. - Design mobile device management architecture for corporate and BYOD scenarios, establishing enrollment profiles, compliance policies, and conditional access integration. - Establish architecture standards for endpoint hardening, application allow-listing, DLP controls, and removable media policy. - Provide architectural oversight for RMM tooling and remote management capabilities, ensuring security boundaries and abuse-resistance controls are embedded by design. SaaS & Cloud Security Architecture - Define the SaaS security architecture program: vendor risk tiering, security review criteria, integration security standards, and ongoing posture monitoring frameworks. - Architect CASB, SSPM, and SaaS access governance controls to ensure visibility and enforcement across the business application portfolio. - Establish data classification and DLP architecture for SaaS environments including Google Workspace, Microsoft 365, Salesforce, and Workday. - Design AI/shadow SaaS governance architecture, including browser isolation, OAuth scope enforcement, and sanctioned AI tooling controls. Internal Infrastructure Security Architecture - Define security architecture standards for on-premise and cloud-hosted internal infrastructure including IDF/MDF environments, server rooms, physical access control systems (Brivo), and AV infrastructure. - Architect logging, SIEM integration, and telemetry collection frameworks ensuring consistent visibility across infrastructure, identity, network, and endpoint layers. - Design disaster recovery and resilience architecture for critical corporate infrastructure, including offline backup strategies and clean-room recovery playbooks. Operational Technology (OT) Security - Develop OT security architecture standards for physical and building systems including access control hardware, environmental sensors, and network-connected facility equipment. - Define segmentation and monitoring architecture to isolate OT environments from corporate IT networks, reducing blast radius and unauthorized access risk. - Establish a vulnerability management framework for OT assets, accounting for patching constraints and availability requirements unique to operational environments. Architecture Governance & Engineering Enablement - Maintain a living enterprise security architecture document and domain-level reference architectures, keeping them current with technology changes and threat landscape evolution. - Conduct security architecture reviews for new technology programs, vendor onboarding, and significant infrastructure changes — providing actionable guidance rather than just approval/denial. - Define security requirements and acceptance criteria for strategic projects in partnership with Product Security, Engineering, and Corporate Technology. - Produce architecture decision records (ADRs) and security design patterns that teams can reuse, reducing review cycle time and engineering rework. Qualifications Required - 8+ years of experience in information security with at least 4 years in a security architecture, security engineering lead, or equivalent senior technical role. - Demonstrated expertise designing and implementing Zero Trust architectures in enterprise environments, including ZTNA, identity-aware access, and microsegmentation. - Deep knowledge of identity and access management — Okta (or equivalent), SAML, OIDC, SCIM, MFA, PAM, and certificate-based authentication. - Strong endpoint security architecture experience across macOS and Windows, including EDR (CrowdStrike preferred), MDM (Kandji/Intune), and patch management. - Experience architecting SaaS security programs including vendor risk frameworks, CASB/SSPM tooling, and OAuth/API integration controls. - Solid understanding of network security architecture: firewalls, SD-WAN, 802.1X, DNS security, and network segmentation principles. - Familiarity with OT/IoT security architecture concepts and the challenges of securing non-traditional network-connected assets. - Proven ability to produce high-quality security architecture documentation including reference architectures, design patterns, and ADRs. - Strong communicator capable of presenting complex security topics to both technical peers and senior non-technical stakeholders. Nice to Have - Professional certifications: CISSP, SABSA, CCSP, or equivalent architecture/security credentials. - Experience operating in a post-M&A environment with multi-tenant identity and infrastructure consolidation challenges. - Familiarity with Cloudflare Access/WARP, Meraki, CrowdStrike Falcon, Kandji, Qualys VMDR, or Drata/GRC tooling. - Experience designing AI governance and shadow SaaS controls for enterprise environments. - Background working in a regulated industry or supporting compliance frameworks (SOC 2, ISO 27001, FedRAMP).

Job Details

Responsibilities

  • Define and maintain enterprise security architecture across Zero Trust, identity, network, endpoint, SaaS, infrastructure, mobile, and OT domains
  • Author and govern security architecture principles, reference designs, and technical standards
  • Drive alignment across Security Operations, Corporate Technology, and Information Engineering teams
  • Identify architectural gaps and emerging threat vectors and prescribe remediation roadmaps
  • Lead strategic security initiatives including Zero Trust maturity, identity consolidation, and SaaS governance
  • Design ZTNA policy and replace legacy VPNs with identity-aware, context-driven enforcement
  • Architect identity frameworks spanning Okta, SAML/OIDC, SCIM, MFA, and PAM
  • Define endpoint security architecture for macOS and Windows using EDR and MDM
  • Architect SaaS security programs, including vendor risk tiering and CASB/SSPM controls
  • Design AI and shadow SaaS governance architecture
  • Develop OT security architecture standards for physical and building systems
  • Conduct security architecture reviews for new technology programs and vendor onboarding
  • Produce Architecture Decision Records (ADRs) and reusable security design patterns

Requirements

  • 8+ years of experience in information security
  • At least 4 years in a security architecture, security engineering lead, or equivalent senior technical role
  • Expertise in designing and implementing Zero Trust architectures (ZTNA, identity-aware access, microsegmentation)
  • Deep knowledge of IAM: Okta, SAML, OIDC, SCIM, MFA, PAM, and certificate-based authentication
  • Strong endpoint security architecture experience across macOS and Windows (EDR, MDM, patch management)
  • Experience architecting SaaS security programs (vendor risk frameworks, CASB/SSPM, OAuth/API controls)
  • Solid understanding of network security architecture (firewalls, SD-WAN, 802.1X, DNS security, segmentation)
  • Familiarity with OT/IoT security architecture concepts
  • Ability to produce high-quality security architecture documentation (reference architectures, design patterns, ADRs)
  • Strong communication skills for technical and non-technical stakeholders

Skills & Technologies

Zero TrustZTNAOktaSAMLOIDCSCIMMFAPAMCrowdStrike FalconKandjiIntuneCloudflare WARP/AccessMeraki SD-WANCASBSSPMSaaS GovernanceEDRMDMOT/IoT SecurityADR
Seen 1 day agoPartial Schema
Financial overview
€28.2M
Revenue
€14.9M
Profit
53.0%
Profit margin
AlphaSense Oy logo
AlphaSenseOy · 216 open roles
Top locations: Remote - Global · 176 · Helsinki, Finland · 27 · London, UK · 2+9 other locations
View company
Current open roles at AlphaSense Oy on JobCrawls
LocationActive listings
Remote - Global176
Helsinki, Finland27
London, UK2
New York, USA2
Singapore2
Remote - Europe1
Remote - Finland1
Remote1
New York, United States1
New York City, United States1
Bangalore, India1
London, United Kingdom1
Current role mix at AlphaSense Oy on JobCrawls
Role typeActive listings
Software Engineer28
Account Manager9
Customer Success Manager6
Product Manager6
Compliance Analyst5
Channel and Customer Research Associate5
Sales Development Representative4
Content Analyst4
Product Designer4
Account Executive4
Human Resources Specialist3
AI Platform Engineer3
Analyst Development Representative3
Principal Software Engineer3
Analyst3
Android Engineer3
Network Engineer3
Cloud Platform Engineer2
Principal Design Engineer2
Senior Manager2
People Business Partner2
Technical Program Manager2
Design Engineer2
Program Manager2
Customer & Product Support Analyst2
iOS Engineer2
IT Support Analyst2
Data Scientist2
Sector Lead2
Site Reliability Engineer2
Manager2
Associate Account Executive2
Enterprise Account Executive2
Head of Developer Experience2
Operations Manager2
Sales Development Manager2
Pre-Sales Manager2
Customer Support Specialist2
Channel and Customer Research Sector Lead1
Business Applications Security Engineer1
Product Analyst1
Senior Technical Program Manager1
Talent Acquisition Partner1
Senior Commercial Counsel1
Security Operations Analyst1
Revenue Accounting1
Compliance Surveillance Analyst1
Strategic Sales Manager1
Director of AI Governance and Security1
Analytics Engineer1
Marketing Analyst1
Customer Education Manager1
Cloud Reliability and Recovery Engineer1
Tax Associate1
Strategic Account Leader1
Account Management1
Solutions Marketing Manager1
Sales Enablement1
Solutions Consultant1
Senior Engineer1
Equity Research Associate1
Content Support Analyst1
Strategic Account Executive1
Customer Support Analyst1
Payroll Director1
Executive Assistant1
Deal Desk Analyst1
Head of Strategic Alliances1
Marketing AI & Transformation Strategy Lead1
Key Account Director1
Equity Research1
Account Director1
Staff Engineer1
Researcher1
Legal Content and Data Director1
Audio Visual Engineer1
Program Management1
Strategic Finance Manager1
Team Leader1
Pre-Sales Consultant1
Growth Marketing Manager1
Human Resources1
Director of Global Real Estate and Workplace Experience1
Director of Executive Recruiting1
Marketing Manager1
Senior Staff Software Engineer1
Motion Designer1
Financial Data Application Specialist1
Product Platforms Engineer1
Head of Broker Relations1
Revenue Tools Specialist1
Analyst Development1
Senior Software Engineer1
Deal Desk Contracting Manager1
Client Research Manager1
Sales Operations Analyst1
Implementation Consultant1
Data Analyst1
Talent Community Member1
People Operations Coordinator1
Current role-level mix at AlphaSense Oy on JobCrawls
Role levelActive listings
Mid-Level162
Senior12
Manager3
Executive1

Help us improve JobCrawls — sign in to sync saved jobs across devices, or send feedback anytime.