Role OverviewThe Security Architect is a senior technical practitioner responsible for designing the security architecture of Hexion's enterprise environment: on-premises infrastructure, Azure and AWS cloud platforms, AI and machine learning systems, and the interfaces between enterprise IT, Operational Technology, and physical security systems.
What You Will Do
The Security Architect will own reference architectures, security design patterns, and architectural standards, and will work alongside engineering teams to make those controls real in configuration, code, and network design.
Why It Might Be a Fit
The successful candidate will have experience architecting security for both on-premises infrastructure and public cloud at enterprise scale, and will have hands-on architectural depth in both Microsoft Azure and Amazon Web Services.
Requirements
- Bachelor's degree in Computer Science, Information Security, Engineering, or related field (or equivalent practical experience)
- 8+ years in information security with at least 4 years in a dedicated security architecture or senior security engineering role
- Demonstrated experience architecting security for both on-premises infrastructure and public cloud at enterprise scale
- Hands-on architectural depth in both Microsoft Azure and Amazon Web Services — identity, networking, encryption, and native security services in each
- Working fluency with ISO/IEC 27001 and Annex A controls as an architectural framework, including practical application of ISO/IEC 27017 and 27018 to cloud designs
- Familiarity with ISO/IEC 42001 and the AI security threat landscape, with experience designing controls for AI or machine learning systems
- Understanding of OT and industrial control system architecture, including ISO/IEC 27019, IEC 62443, or NIST SP 800-82 concepts
- Experience with physical security systems and the integration of physical and logical access control
- Strong identity architecture skills — Active Directory, Entra ID, SAML and OIDC federation, privileged access management, and non-human identity models
- Network security design depth — segmentation, zero trust architecture, firewalls, proxies, and secure connectivity across hybrid environments
- Proficiency with threat modeling methodologies (STRIDE, PASTA, attack trees) and the ability to produce clear architectural documentation and diagrams
- Strong written and verbal communication — able to defend a design to engineers and explain the same decision to executives
Benefits
- Remote-first position with periodic travel to Hexion manufacturing facilities, data center and colocation sites, and partner or vendor engagements as required
- Site visits are an expected part of the role — OT and physical security architecture cannot be designed entirely from a network diagram
]]>