Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Senior Security Architect image - Rise Careers
Job details

Senior Security Architect

General Information Locations: Kirkland, Washington, United States of America • Location: Kirkland • Country: United States of America Role ID 204317 Worker Type Regular Employee Studio/Department CTO - Security Flexible Work Arrangement Hybrid Description & Requirements We are a global team of creators, storytellers, technologists, experience originators, innovators and so much more. We believe amazing games and experiences start with teams as diverse as the players and communities we serve. At Electronic Arts, the only limit is your imagination.• **Open to Remote***We are looking for an experienced senior security architect to join our team. You will design the security architecture for our enterprise core products, with a focus on securing users & administrators, enterprise applications, data, and systems. You will also lead the strategy and work with teams on security mission-critical products such as Active Directory, Entra ID, M365, Device Authentication & Posture management, Red forest/Enhanced Security Admin Environment (ESAE) for Admins.You will also lead EA’s technical security standard track based on CIS benchmarks to maintain compliance on enterprise systems, and applications. We are looking for a candidate with understanding of security principles, technologies, and best practices across several domains, including network security, application security, data protection, identity management, and cloud security.You will report to the Director of the Enterprise Security Engineering Core & Admin teamResponsibilities• Lead the enhancement of a secure administrative platform for administrators based on Enhanced Security Admin Environment (ESAE) architecture & privileged access strategy• Secure Active Directory, Okta and Entra ID, ensuring that directory services are protected against unauthorized access and vulnerabilities.• Lead the strategy and architecture for compliance with EA’s security standards based on CIS benchmarks for enterprise systems.• Perform application security reviews and threat modeling on mission-critical systems, & enterprise applications to find and address potential security risks.• Lead the strategy and architecture for device authentication and posture management solution for application access.• Lead the implementation of a zero-trust security model across the organization, ensuring protection of user and admin accounts, systems and data.• Stay up to date with the latest industry security trends, threats, and technologies, and improve the security posture of our enterprise systems, and M365 environments.• Periodically update security policies to incorporate the latest security controls.• Lead the cloud enclave strategy and design to ensure that critical services such as Active Directory can be securely hosted in the cloud enclave.• Ensure that we have a thoroughly tested recovery plan in place to recover from service failures or compromises for services such as Active directory, Okta, Entra ID, and Secure Administrative platforms/Red Forest.• Work with EA’s principal cloud security architect and help engineer and development of security architectures and solutions that ensure the protection of our cloud-based systems and data in M365, AWS & GCP.• Create comprehensive documentation for security architectures, procedures & best practices.Qualifications• 10+ years of experience in information security, with at least 4 years in a senior or architectural role• Technical skills in areas such as network security, cryptography, identity management, threat modeling, application security, and risk management.• Experience with zero trust security models, identity and access management, directory synchronization, and federation services.• Experience integrating enterprise Identity and Access Management (IAM) with CSPs such as Azure, AWS, and GCP.• Experience with device authentication solutions and posture management strategies using Entra ID, Opswat, and Intune.• Expertise in securing directory services such as Active Directory, Okta and Entra ID.• Familiarity with CIS benchmarks and other industry security standards.• Knowledge of authentication standards/protocols (NTLM, Kerberos, LDAP, SAML, FIDO2/WebAuthN, OIDC, OAuth2.0).• Experience developing and testing recovery plans for service failures or compromises for critical services such as Active directory, Entra ID.• Experience with cloud security architectures and solutions (AWS, Azure, Google Cloud) with a emphasis on securing the M365 ecosystem.• Experience with network protocols, encryption techniques, and security frameworks such as NIST and ISO/IEC 27001.• Relevant certifications such as CISSP, CISM, CCSP, or similar• Experience with infrastructure as code (IaC) and automation tools (Terraform, Ansible)COMPENSATION AND BENEFITS The ranges listed below are what EA in good faith expects to pay applicants for this role in these locations at the time of this posting. If you reside in a different location, a recruiter will advise on the applicable range and benefits. Pay offered will be determined based on a number of relevant business and candidate factors (e.g. education, qualifications, certifications, experience, skills, geographic location, or business needs). BASE SALARY RANGES• California (depending on location e.g. Los Angeles vs. Sacramento)• $138,200 - $219,000 USD• Colorado (depending on location e.g. Denver vs. Colorado Springs)• $153,100 - $206,200 USD• Jersey City, NJ• $171,100 - $219,000 USD• New York (depending on location e.g. Manhattan vs. Buffalo)• $136,600 - $219,000 USD• Washington (depending on location e.g. Seattle vs. Spokane)• $136,600 - $202,300 USDIn the US, we offer a package of benefits including paid time off (3 weeks per year to start), 80 hours per year of sick time, 16 paid company holidays per year, 10 weeks paid time off to bond with baby, medical/dental/vision insurance, life insurance, disability insurance, and 401(k) to regular full-time employees. Certain roles may also be eligible for bonus and equity.

Average salary estimate

$169450 / YEARLY (est.)
min
max
$136600K
$202300K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior Security Architect, Electronic Arts

At Electronic Arts, we’re looking for an experienced Senior Security Architect to join our dynamic team in Kirkland, WA. This role is crucial as you'll be shaping the security architecture for our enterprise products. Your expertise will be key in ensuring robust security for users, administrators, and our critical applications. You’ll take ownership of mission-critical products including Active Directory, Entra ID, and M365, while leading strategies centered around device authentication and posture management. Above all, you'll spearhead the implementation of a zero-trust security model across our organization, working with cutting-edge technologies to protect user accounts, systems, and sensitive data. With at least 10 years of experience in information security, you're well-versed in network security, cryptography, and identity management. Your strong understanding of CIS benchmarks and cloud security solutions will be assets as you craft comprehensive documentation on security practices and lead us in maintaining compliance. Join us, and let’s innovate together, shaping the future of gaming security!

Frequently Asked Questions (FAQs) for Senior Security Architect Role at Electronic Arts
What responsibilities does a Senior Security Architect at Electronic Arts have?

The Senior Security Architect at Electronic Arts is responsible for designing and leading the security architecture for enterprise core products. This includes securing user accounts, administrators, and critical applications such as Active Directory and Entra ID. The role requires enhancing the security of systems through strategy implementation, leading compliance initiatives based on CIS benchmarks, and performing application security reviews to identify potential risks. Additionally, you'll oversee the integration of device authentication and posture management solutions, all while keeping the organization's security posture up to date with the latest industry trends.

Join Rise to see the full answer
What qualifications are necessary for the Senior Security Architect position at Electronic Arts?

To qualify for the Senior Security Architect role at Electronic Arts, candidates should have a minimum of 10 years in information security, including at least 4 years in a senior or architectural capacity. Key qualifications include expertise in areas such as network security, application security, identity management, and a solid understanding of zero-trust models. Familiarity with CIS benchmarks, cloud security architectures, and relevant security certifications like CISSP or CISM is essential. Additionally, experience in integrating enterprise IAM with cloud service providers is highly valued.

Join Rise to see the full answer
What is the work environment for a Senior Security Architect at Electronic Arts?

The work environment for a Senior Security Architect at Electronic Arts is characterized by hybrid flexibility, allowing for a mix of remote and on-site collaboration. You’ll be part of a global team of innovators and technologists working together to create exceptional gaming experiences. Engaging with various departments, you’ll collaborate closely with cloud security architects and engineering teams to enhance security across all platforms while contributing to a culture of diversity and creativity.

Join Rise to see the full answer
How does Electronic Arts ensure career growth for a Senior Security Architect?

At Electronic Arts, career growth for a Senior Security Architect is supported through continuous learning and professional development opportunities. Employees are encouraged to stay up to date with the latest security trends and advancements through workshops, certifications, and training programs. The organization fosters an environment where team members can take on challenging projects, gain new skills, and progress into higher leadership roles, ensuring that their career ambitions align with the company’s innovative goals.

Join Rise to see the full answer
What are the key security initiatives a Senior Security Architect at Electronic Arts will lead?

A Senior Security Architect at Electronic Arts will lead key initiatives such as the implementation of a zero-trust security model and the development of security strategies that align with the company’s standards based on CIS benchmarks. This includes enhancing the security of systems such as Active Directory, Entra ID, and securing cloud environments like AWS, Azure, and Google Cloud. Additionally, conducting application security reviews and establishing best practices for recovery plans will be crucial responsibilities to protect the organization from risks effectively.

Join Rise to see the full answer
Common Interview Questions for Senior Security Architect
Can you describe your experience with zero-trust security models?

In answering this question, detail your hands-on experience in designing and implementing zero-trust architectures. Discuss specific projects where you applied zero-trust principles, such as validating user identity continuously, restricting access based on user roles, and incorporating adaptive security measures. Highlight how these efforts enhanced security within your organization.

Join Rise to see the full answer
How do you approach threat modeling for applications?

When discussing threat modeling, explain your methodology, such as using techniques like STRIDE or PASTA. Share a specific example of an application security review where you identified potential threats and vulnerabilities, and elaborate on the steps taken to mitigate these risks.

Join Rise to see the full answer
What best practices do you follow when securing Active Directory?

Talk about your routine practices for securing Active Directory, like implementing strict password policies, ensuring regular audits, using tiered administration, and monitoring logs for suspicious activities. Providing examples of past successful implementations will strengthen your answer.

Join Rise to see the full answer
Describe a time you had to recover from a service failure. What steps did you take?

Use the STAR method to communicate your experience with recovery planning. Describe the scenario, your role, the specific actions you took to restore services, and the outcomes. Highlight how you integrated lessons learned into future recovery plans.

Join Rise to see the full answer
How do you keep updated with the latest industry security trends?

Mention the resources you rely on, such as attending industry conferences, participating in webinars, and following leading cybersecurity blogs or publications. Also, discuss how you translate this knowledge into actionable strategies within your role.

Join Rise to see the full answer
What is your experience with integrating identity and access management solutions with cloud service providers?

Discuss your specific experiences and the technologies you’ve used, like Azure IAM or AWS IAM. Highlight key projects, the challenges you faced, and how you resolved them to ensure seamless integration and security.

Join Rise to see the full answer
Can you explain your experience with CIS benchmarks?

Talk about your familiarity with CIS benchmarks, emphasizing how you've used them to assess current security configurations in past roles. Share specific scenarios where adherence to these benchmarks led to improved security measures within your organization.

Join Rise to see the full answer
What is your methodology for conducting application security reviews?

Outline your structured approach, which could include threat modeling, code reviews, and vulnerability assessment tools. Give examples where your thorough analysis identified significant vulnerabilities that were subsequently addressed.

Join Rise to see the full answer
Describe a complex security architecture you designed. What considerations did you take into account?

Provide a detailed account of a specific project where you designed security architecture, discussing factors such as scalability, regulatory compliance, and integrating existing security measures. Mention the stakeholders involved and the impact of your design.

Join Rise to see the full answer
What strategies do you advocate for device authentication and posture management?

Discuss the principles of device authentication, emphasizing approaches like adaptive authentication and conditional access. Mention how you've applied these in previous roles to effectively manage device posture and regulate access.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 9 days ago
Photo of the Rise User
Customer-Centric
Empathetic
Feedback Forward
Transparent & Candid
Reward & Recognition
Collaboration over Competition
Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)
Photo of the Rise User
Posted 11 days ago
Posted 2 days ago
Photo of the Rise User
GCM Grosvenor Hybrid Chicago, Illinois, United States
Posted 2 days ago
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
No info
LOCATION
No info
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
December 18, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!