Enterprise Security Architect

Box Box · Enterprise · United States · Remote · Security

Box is seeking an Enterprise Security Architect to design and scale security systems protecting their corporate environment. The role involves architecting and implementing security solutions across identity, endpoint, network, SaaS, and AI-enabled systems, with a focus on evolving towards a zero-trust, AI-enabled future. Responsibilities include leading security architecture reviews, threat modeling, developing security standards, and partnering with various teams. The role emphasizes leveraging AI for security operations, including LLM-based tooling and automation.

What you'd actually do

  1. Design, build, deploy, and maintain comprehensive security systems that protect Box's corporate infrastructure, workforce, and SaaS environments while driving the evolution of our security architecture toward a zero-trust, AI-enabled future.
  2. Architect and implement cutting-edge security solutions across critical enterprise domains including endpoint protection, zero trust networking (ZTNA), identity and privileged access management, SaaS security, and AI-enabled systems
  3. Lead the transformation of Box's security architecture toward a fully realized zero-trust model, encompassing device trust frameworks, identity-centric access controls, and continuous verification mechanisms
  4. Pioneer the adoption of AI-augmented security operations, including LLM-based investigative tooling and automated threat threat analysis
  5. Identify and implement opportunities to automate security workflows through scripting, infrastructure-as-code, and orchestration platforms

Skills

Required

  • corporate/enterprise security engineering (endpoint, network security, cloud security, SaaS security, identity, or a combination)
  • macOS security
  • Windows security
  • ChromeOS security
  • scripting
  • infrastructure-as-code
  • orchestration platforms

Nice to have

  • identity and privileged access management
  • zero trust networking (ZTNA)
  • SaaS security

What the JD emphasized

  • AI-enabled systems
  • AI-augmented security operations
  • LLM-based investigative tooling