We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Security Architect

Sorenson Communications
medical insurance, paid holidays, sick time, 401(k)
United States, Utah, Salt Lake City
Oct 01, 2026
Description

Job Summary

The Security Architect serves as Sorenson's senior security architecture authority and is responsible for defining, advancing, and overseeing the enterprise cybersecurity architecture strategy. Positioned within the Security organization, this role has enterprise-wide influence over security architecture practices across identity, application, cloud, infrastructure, network, data, security operations, resilience, Zero Trust, and emerging technologies.

The Security Architect establishes security principles, standards, reference architectures, technical guardrails, and reusable design patterns that guide the secure development, deployment, operation, and integration of enterprise technologies. The role establishes and leads the Security Architecture Review process for materially significant initiatives, helping ensure security is incorporated early in solution design and technology decision-making.

The role works in close partnership with Enterprise Architecture, Engineering, Product, Data, AI Governance, Legal, Privacy, Compliance, and Risk Management. The Security Architect represents and governs the security architecture domain while aligning with broader enterprise architecture and governance processes.

Artificial intelligence is an important component of the role's emerging-technology responsibilities. The Security Architect defines security architecture and control patterns for AI systems, models, agents, platforms, data pipelines, vector databases, and retrieval-augmented generation solutions while ensuring alignment with enterprise security, data governance, privacy, compliance, risk, and responsible AI objectives.

Success is measured through increased adoption of approved security architecture standards, timely completion of architecture reviews for materially significant initiatives, improved threat-modeling and SSDLC coverage, reduction of systemic architectural risk and technical debt, advancement of Zero Trust and cyber-resilience maturity, and secure deployment of new and emerging technologies.

Essential Duties and Responsibilities

Enterprise Security Architecture Strategy and Standards



  • Define, advance, and govern Sorenson's enterprise cybersecurity architecture strategy, principles, standards, reference architectures, and design patterns.
  • Develop reusable security architecture patterns and technical guardrails that accelerate secure delivery while maintaining consistency across enterprise systems, products, and platforms.
  • Define architectural security requirements and implementation guidance that support business objectives, operational resilience, and risk management goals.
  • Maintain alignment between security architecture strategy and Sorenson's enterprise technology strategy through partnership with Enterprise Architecture and technology leadership teams.


Security Architecture Review & Decision Leadership



  • Establish and lead the Security Architecture Review process for materially significant technology initiatives, including cloud platforms, enterprise applications, customer-facing products, AI systems, data platforms, third-party services, and major architectural changes.
  • Define risk-based review criteria, engagement points, required architecture artifacts, security requirements, and exception-management processes.
  • Ensure security is incorporated early in solution design, technology selection, procurement, and implementation planning.
  • Document security architecture determinations, required security controls, approved patterns, design alternatives, exceptions, and material risk considerations.
  • Provide architectural guidance and recommendations that balance security, operational effectiveness, business objectives, cost, and delivery timelines.


Application Security & Secure Software Architecture



  • Define and maintain secure application architecture standards and reference patterns for:
  • Authentication and authorization
  • API security
  • Microservices security
  • Service-to-service trust
  • Secure design principles
  • Secrets management
  • Secure session management
  • Application threat modeling
  • Partner with Application Security, Product, Engineering, and DevSecOps teams to integrate approved security architecture patterns throughout the software development lifecycle.
  • Define architecture expectations and verification criteria that support consistent implementation of secure software development practices.
  • Support engineering teams in resolving complex design challenges requiring security architecture expertise.


Zero Trust, Identity & Data Protection Architecture



  • Establish and maintain the Zero Trust architecture strategy and roadmap across identity, device, network, application, workload, and data pillars.
  • Architect identity and access management patterns including:
  • Single Sign-On (SSO)
  • Multi-Factor Authentication (MFA)
  • Privileged Access Management (PAM)
  • Role-Based Access Control (RBAC)
  • Attribute-Based Access Control (ABAC)
  • Federation
  • Non-human and workload identities
  • Define data protection architectures including:
  • Data classification controls
  • Encryption standards
  • Key management
  • Data loss prevention patterns
  • Access control architectures
  • Ensure security architectures support enterprise identity, API management, and governance frameworks.


Cloud, Infrastructure, Network & Cyber Resilience Architecture



  • Design security reference architectures across public cloud, private cloud, hybrid, and on-premises environments.
  • Define architecture standards for:
  • Cloud landing zones
  • Network segmentation
  • Infrastructure-as-Code security
  • Container security
  • Workload protection
  • Secrets and credential management
  • Cloud security posture management
  • Define architecture patterns that support operational resilience, recoverability, survivability, and security monitoring.
  • Develop security modernization roadmaps that address legacy technology risks, architectural technical debt, cyber resilience capabilities, disaster recovery readiness, and strategic security transformation initiatives.
  • Partner with Infrastructure, Operations, and Enterprise Architecture teams to prioritize long-term security modernization objectives.


Enterprise Data, Analytics & AI Security Architecture



  • Define security architecture patterns and controls for:
  • Enterprise data platforms
  • Analytics environments
  • Data-sharing ecosystems
  • AI data pipelines
  • Vector databases
  • Embedding pipelines
  • Retrieval-Augmented Generation (RAG) architectures
  • Develop security architecture standards and technical controls to protect AI systems, models, agents, platforms, and associated data.
  • Define safeguards addressing:
  • Prompt injection
  • Tool misuse
  • Data exposure
  • Model abuse
  • Excessive agent privilege
  • Memory and context isolation
  • AI observability and guardrails
  • Ensure AI and data architectures align with enterprise security requirements, privacy requirements, data governance standards, and responsible AI principles.
  • Partner with AI Governance, Data Governance, Legal, Privacy, Compliance, and Risk Management stakeholders to ensure secure and compliant adoption of AI capabilities.


Third-Party & Technology Partner Security Architecture



  • Partner with the SOC to define detection, logging, and response architecture (telemetry standards, SIEM/SOAR, detection engineering).
  • Align defensive architecture to threat-informed defense using MITRE ATT&CK and emerging AI threat frameworks.
  • Lead enterprise threat modeling for new and materially changed systems-including AI/agentic systems-ensuring mitigations are documented, tracked, and testable.
  • Identify systemic architecture risk across the portfolio and drive roadmap items to reduce exposure.


Threat Modeling, Security Operations & Security-by-Design



  • Oversee threat modeling activities for new and materially changed systems, applications, services, and AI-enabled solutions.
  • Apply frameworks such as:
  • STRIDE
  • MITRE ATT&CK
  • MITRE ATLAS
  • MAESTRO
  • OWASP methodologies
  • Ensure identified threats, mitigations, and security requirements are documented, assigned, tracked, and validated.
  • Partner with Security Operations to define security monitoring, logging, telemetry, detection engineering, and response architecture patterns.
  • Support Security-by-Design activities by ensuring architecture artifacts, system descriptions, diagrams, and technical documentation align with implemented solutions.


Cross-Functional Leadership, Metrics & Continuous Improvement



  • Serve as Security's senior architecture advisor for major technology initiatives and strategic programs.
  • Partner closely with Enterprise Architecture to ensure alignment between enterprise technology direction and security architecture requirements.
  • Chair or participate in security architecture governance activities including architecture reviews, standards development, exception management, and architectural decision-making forums.
  • Define, track, and report security architecture effectiveness metrics including:
  • Architecture review coverage
  • Threat modeling coverage
  • Security pattern adoption
  • Exception trends
  • Architectural technical debt reduction
  • Security control adoption
  • Security architecture maturity
  • Mentor engineers, architects, and security professionals on architecture principles, emerging technologies, and secure design practices.
  • Drive continuous improvement of security architecture capabilities, standards, and governance processes.


Other duties as assigned.

Supervisory Responsibility

This position has no direct supervisory responsibilities but does serve as a coach and mentor for other positions in the department.

Travel Requirements

Travel Requirements: Less than 25%

Education

Minimum 4 Year / Bachelors Degree In Computer Science, Cybersecurity, Information Systems, Software Engineering, or related field.

Preferred: Graduate Degree In Cybersecurity, Computer Science, Information systems or related discipline.

Experience

Minimum of 8 Years of Experience



  • Demonstrated experience designing and governing security architectures across multiple domains including application, cloud, infrastructure, identity, data protection, and security operations.
  • Experience conducting architecture reviews, threat modeling, and risk-based design assessments for complex enterprise environments.
  • Experience evaluating emerging technologies and providing architecture recommendations that balance security, business objectives, and operational requirements.



Knowledge, Skills, and Abilities



  • Deep expertise in security architecture spanning application, cloud, infrastructure, network, identity, Zero Trust, security operations, and data protection domains.
  • Strong understanding of secure application architecture, APIs, microservices, distributed systems, and secure software development practices.
  • Experience establishing reusable security architecture standards, reference architectures, technical controls, and implementation patterns.
  • Experience securing modern AI systems, machine learning solutions, agentic systems, AI orchestration platforms, and RAG implementations.
  • Experience securing enterprise data platforms, analytics environments, and large-scale cloud-native systems.
  • Knowledge of security architecture frameworks, governance processes, and risk-management practices.
  • Ability to assess complex architectural risks and provide pragmatic, business-aligned recommendations.
  • Ability to influence enterprise technology decisions through partnership, expertise, and architectural leadership.
  • Strong written and verbal communication skills with technical and executive stakeholders.
  • Strong analytical, strategic-thinking, and problem-solving capabilities.
  • Professional attitude, team player, good interpersonal communication skills and able to work across company departments.
  • Preferred
  • Experience establishing and leading enterprise security architecture review functions.
  • Experience implementing Zero Trust architectures at scale.
  • Experience securing enterprise data platforms, analytics environments, AI systems, RAG architectures, and AI-enabled applications.
  • Experience assessing SaaS platforms, cloud services, AI providers, and strategic technology vendors.
  • Experience developing security modernization and cyber resilience strategies.
  • Experience working within governance-heavy or compliance-driven regulated environments (e.g., HIPAA, PCI DSS, SOC 2).
  • Relevant certifications such as CISSP, CISSP-ISSAP, SABSA, CCSP, AWS Security Specialty, Azure Security Engineer Associate, Google Professional Cloud Security Engineer, or other relevant security specialties.



Come be a part of our mission and make a meaningful and positive impact with the industry leading provider of language services for the Deaf and hard-of-hearing!

Full time Benefits



  • Paid Vacation Time and Paid Sick Time and Paid Holidays
  • 401k 6% match with immediate vesting
  • Nationwide Medical Insurance plans and coverage (Medical, Dental/Orthodontia, Vision)


    • TeleDoc
    • HSA company match
    • 3 Medical plan options including a Low Deductible PPO Medical Plan Offering


  • Employee Assistance Program
  • Engaged Employee Resource Groups
  • Outstanding Learning and Career Development Opportunities


Pay Range: Actual pay may vary up or down depending on job-related factors which may include knowledge, skills, experience, and location. In addition, this position may be eligible for incentive compensation.

* Applicants must be legally eligible to work in the United States to be considered. Visa sponsorship is not available for this role *

Company Summary

Our Mission...Leveraging the Power of Language, we connect lives and enrich the human experience.

Our Vision...To provide global language services that expand opportunities, nurture belonging, and empower the world to connect beyond words.

As one of the world's leading language services providers, Sorenson combines patented technology with human-centric solutions. We strive to increase accessibility and inclusion through communication solutions for all: call captioning and video relay services, over-video and in-person sign language and spoken language interpreting, translation, real-time captioning, and post-production language services. Sorenson's impact vision and plan extends to enhancing generational wealth and inclusive workplaces for our employees and the communities we serve.

We achieve great things together working "The Sorenson Way" with our employee values: Customer First, Can-Do Attitude, Collective Action, Growth Mindset, Ownership, and Connect Direct.

Equal Employment Opportunity:
Sorenson Communications is an Equal Opportunity, Affirmative Action Employer.

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities

This employer is required to notify all applicants of their rights pursuant to federal employment laws.
For further information, please review the Know Your Rights notice from the Department of Labor.
Applied = 0

(web-9db6c7984-cdtlt)