Cybersecurity Architect - Information Technology
Ai Security
Application Security
Cloud Platforms
Cloud Security
Cloud Security Architecture
Data Security
Facilities Management
Identity and Access Management
Information Security
InfoSec
Project Management
Risk Management
Security
Security Architecture
Security Automation
Security Compliance
Security Operations
Security Standards
Security Testing
Solution Architecture
Job Description
Fisher Dynamics is seeking a Cybersecurity Architect to design and implement security architecture and controls for an ERP platform and AI/LLM infrastructure.
Responsibilities
- Design end-to-end security architecture for the custom ERP platform across application, data, infrastructure, and AI layers
- Run threat modeling and risk assessments for ERP modules, workflows, and integrations
- Define security controls, best practices, and standards for the platform and development lifecycle
- Architect authentication and authorization (RBAC), encryption, and data protection mechanisms
- Design secure APIs, data access patterns, and audit logging for tracking activity and changes
- Set secure coding standards and OWASP compliance requirements for development teams
- Review architecture and code to identify vulnerabilities and recommend remediation actions
- Perform security reviews of APIs, integrations, and third-party connections
- Implement SAST and DAST security testing in CI/CD pipelines
- Design protections against common attack classes, including SQL injection, cross-site scripting, and privilege escalation
- Build data protection architecture for sensitive ERP data such as financial records, supplier information, and production data
- Implement encryption standards for data at rest and in transit
- Establish data access controls and audit logging to track data usage and modifications
- Design privacy controls aligned with data governance and regulatory requirements
- Ensure compliance with data retention, purging, and archival policies
- Design ML/AI model and feature pipeline security controls to mitigate model poisoning and tampering
- Implement monitoring for adversarial model attacks and anomalous predictions
- Secure model serving infrastructure and ensure integrity of model outputs
- Design data isolation and access controls for training and inference data
- Create audit trails for model decisions and predictions
- Design secure cloud architecture on AWS, GCP, or Azure with security groups, VPCs, and network segmentation
- Lead infrastructure hardening, patch management, and vulnerability remediation
- Design secrets management, key rotation, and credential security
- Set up monitoring, logging, and alerting for security incidents
- Support disaster recovery and business continuity planning with security considerations
- Establish security policies, standards, and procedures aligned with industry best practices
- Ensure compliance with relevant regulations including SOX, GDPR, and manufacturing standards
- Implement compliance-focused audit logging and reporting
- Design security incident response and escalation procedures
- Conduct security awareness training and promote a security-focused culture
- Perform regular security assessments, penetration testing, and vulnerability scanning
- Identify, prioritize, and track vulnerabilities through remediation
- Conduct security testing of new features and system changes before deployment
- Monitor emerging threats and security advisories; recommend updates
- Support production security incident investigation and resolution
Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, Information Security, or related field
- Master’s degree preferred
- CISSP, CCSK, or similar certifications strongly preferred
- 5-8 years of professional cybersecurity and security architecture experience
- Demonstrated experience designing security architectures for large-scale systems or enterprise platforms
- Expert knowledge of security architecture, threat modeling, and risk assessment
- Advanced understanding of application security, secure coding, and OWASP Top 10
- Deep expertise in cryptography, encryption standards, and key management
- Strong knowledge of network security including firewalls, VPNs, and network segmentation
- Experience with cloud security patterns on AWS, GCP, and/or Azure
- Proficiency with security tools such as vulnerability scanners, SIEM, and intrusion detection
- Knowledge of compliance frameworks including SOX, GDPR, HIPAA, and PCI-DSS
- Experience with identity and access management: IAM, RBAC, OAuth, and SAML
- Understanding of API security and authentication/authorization protocols
- Familiarity with ML/AI security and model integrity concerns
- Strong knowledge of incident response and forensics
- Experience with penetration testing and security assessments
- Excellent communication skills presenting security concepts to technical and executive audiences
- Security certifications (CISSP, CCSK, CEH) preferred
- Collaboration with technical teams; requires on-call availability for security incidents
- Ability to lift 40 lbs
Technologies
- ERP, AI, LLM
- RBAC, OWASP
- SAST, DAST, CI/CD
- SQL injection, cross-site scripting
- AWS, GCP, Azure, VPC, VPN, firewalls
- SIEM, intrusion detection
- IAM, OAuth, SAML
- Cryptography, encryption, key management
- HIPAA, PCI-DSS
Benefits
- 401(k)
- 401(k) matching
- Dental insurance
- Employee assistance program
- Employee discount
- Flexible schedule
- Flexible spending account
- Health insurance
- Health savings account
- Life insurance
- Paid time off
- Professional development assistance
- Tuition reimbursement
- Vision insurance
Location: Saint Clair Shores, MI (onsite)