Cybersecurity Architect
Cary, NC, US Overland Park, KS, US
Together, we own our company, our future, and our shared success.
As an employee-owned company, our people are Black & Veatch. We put them at the center of everything we do and empower them to grow, explore new possibilities and use their diverse talents and perspectives to solve humanity's biggest challenges in an ever-evolving world. With over 100 years of innovation in sustainable infrastructure and our expertise in engineering, procurement, consulting and construction, together we are building a world of difference.
Company : Black & Veatch Corporation
Req Id : 113654
Opportunity Type : Staff
Relocation eligible : No
Full time/Part time : Full-Time
Project Only Hire : No
Visa Sponsorship Available: No
Why Black and Veatch
Black & Veatch allows you to lend your talent and perspective to humanity’s biggest challenges in a flexible environment where you are empowered to grow and explore new possibilities. We offer competitive compensation; 401K match and benefits that start day one.
At Black & Veatch, you own your career with purpose and meaning. You are empowered to grow and explore new possibilities at every step of your career journey. Bring your big ideas knowing you are safe to be who you are and speak up with concerns or questions and put your diverse talents and perspectives to use.
The Opportunity
The Cybersecurity Architect is a key senior role focused on defining, designing, and maintaining the organization's enterprise-wide security architecture to align with business goals, risk strategies, and evolving threats.
Core Responsibilities:
- Develops and maintains a comprehensive security architecture strategy, including plans, roadmaps, processes, and artifacts (e.g., models, standards, templates) that translate business objectives, technology needs, and threat landscapes into actionable, aligned security solutions for cloud, on-premise, and hybrid environments.
- Monitors emerging digital business changes and threat developments; updates security strategies, architectures, and reference designs accordingly; validates IT infrastructure, configurations, and tools (e.g., firewalls, IPS, WAF, endpoint protection) against best practices; recommends enhancements to mitigate risks.
- Collaborates with stakeholders—including enterprise architects, system owners, security engineers, vendors, operational teams, and the CISO—to assess and integrate security controls (system-specific, hybrid, common); evaluates third-party SOWs, audit reports, and provider controls; coordinates security for OT/IoT systems; serves as primary liaison for control allocation and assurance.
The Team
Black & Veatch’s Business Enablement consists of critical groups that help enable the organizations people, projects, and businesses to be as successful as possible. Functions in this group include Digital & Information Technology, Global Finance, Global Human Resources, Legal, Risk Management, and Government Affairs and Real Estate and Building Services.
Key Responsibilities
- Establishes baseline security configuration standards for operating systems, network segmentation, least-privilege access, and identity and access management (IAM); reviews and validates network segmentation designs.
- Defines and maintains standards and procedures for data encryption, tokenization, and protection of sensitive data, aligned with organizational data classification; collaborates with privacy teams to map data flows and recommend appropriate controls.
- Drafts, documents, and maintains security policies, standards, procedures, and architecture artifacts; submits for executive/CISO review and approval; ensures integration throughout the acquisition lifecycle and system development.
- Conducts threat modeling for applications, services, and systems based on associated risks and data sensitivity; identifies architecture gaps, performs security reviews, and develops risk management plans to address vulnerabilities.
- Stays current on emerging security technologies, threats, trends, and best practices; evaluates new tools, services, and vendors; provides recommendations to the security team based on security, cost, and operational considerations.
- Collaborates with DevOps, development, and project teams to promote secure coding practices, participate in application/infrastructure projects, advise on security planning, and escalate issues to the CISO.
- Supports security testing, validation, and internal audits of controls; liaises with internal audit, vendor management, and other security practitioners to assess vendor risks, review SOWs/audits, and share best practices.
- Analyzes the security impact of new systems, interfaces, or changes on the existing environment; recommends enhancements to maintain or improve overall security posture.
Management Responsibilities
Preferred Qualifications
- Hands-on expertise managing security infrastructure: firewalls, IPS, WAFs, endpoint protection, SIEM, and log management.
- Proven track record building enterprise AI security frameworks and controls for generative AI, LLMs, federated learning, and AI supply chain risks
- Direct experience securing applications and infrastructure in public clouds (AWS, Azure).
- Practical design and implementation of IAM technologies and services
- Excellent communication skills: able to translate complex security topics into clear business language; strong verbal/written presentation to stakeholders.
Minimum Qualifications
- Bachelor's degree: Computer Science, Cybersecurity, Information technology, Network Engineering, or a closely related field.
- 8-10+ years in InfoSec or Information Technology with a significant portion in cybersecurity.
- All applicants must be able to complete pre-employment onboarding requirements (if selected) which may include any/all of the following: criminal/civil background check, drug screen, and motor vehicle records search, in compliance with any applicable laws and regulations.
Certifications
CISSP, CISM, CCSP, CEH, or similar with a Cybersecurity emphasis
Work Environment/Physical Demands
Hybrid or flexible work options may be offered after the first 90 days of employment based upon manager discretion, job performance and work assignments.
Salary Plan
Job Grade
Black & Veatch endeavors to make www.bv.com/careers accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process because of a disability, please contact the Employee Relations Department at +1-913-359-1622 or via our accommodations request form. This contact information is for disability accommodation requests only; you may not use this contact information to inquire about the status of applications. General inquiries about the status of applications will not be returned.
Black & Veatch is committed to being an employer of choice by creating a valuable work experience that keeps our people engaged, productive, safe and healthy.
Our comprehensive benefits portfolio is a key component of this commitment and offers an array of health care benefits including but not limited to medical, dental and vision insurances along with disability and a robust wellness program.
To support a healthy work-life balance, we offer flexible work schedules, paid vacation and holiday time, sick time, and dependent sick time.
A variety of additional benefits are available to our professionals, including a company-matched 401k plan, adoption reimbursement, tuition reimbursement, vendor discounts, an employment referral program, AD&D insurance, pre-taxed accounts, voluntary legal plan and the B&V Credit Union. Professionals may also be eligible for a performance-based bonus program.
We are proud to be a 100 percent ESOP-owned company. As employee-owners, our professionals are empowered to drive not only their personal growth, but the company's long-term achievements - and they share in the financial rewards of the success through stock ownership.
By valuing diverse voices and perspectives, we cultivate an authentically inclusive environment for professionals and are able to provide innovative and effective solutions for clients.
BVH, Inc., its subsidiaries and its affiliated companies, complies with all Equal Employment Opportunity (EEO) laws and regulations. Black & Veatch does not discriminate on the basis of age, race, religion, color, sex, national origin, marital status, genetic information, sexual orientation, gender Identity and expression, disability, veteran status, pregnancy status or other status protected by law.
For our EEO Policy Statement, please click here.
Notice to External Search Firms: Black & Veatch does not accept unsolicited resumes and will not be obligated to pay a placement fee for unsolicited resumes. Black & Veatch Talent Acquisition engages with search firms directly for hiring needs.
Job Segment:
Architecture, Network Engineer, Engineer, Engineering