A career in IBM Consulting is built on long-term client relationships and close collaboration worldwide. You’ll work with leading companies across industries, helping them shape their hybrid cloud and AI journeys. With support from our strategic partners, robust IBM technology, and Red Hat, you’ll have the tools to drive meaningful change and accelerate client impact. At IBM Consulting, curiosity fuels success. You’ll be encouraged to challenge the norm, explore new ideas, and create innovative solutions that deliver real results. Our culture of growth and empathy focuses on your long-term career development while valuing your unique skills and experiences.
The Security AI Solution Architect owns the end-to-end security architecture for Tower 4 agentic, automation, and secure-by-default capabilities. Translates IBM security policy, client obligations, existing control evidence, and delivery risks into governed digital-agent patterns, control architectures, and reusable security blueprints
Define the Tower 4 reference architecture for controlled digital agents, security pattern libraries, evidence normalization, and secure-by-default implementation.
· Translate IBM internal security standards, SOC 2, ISO 27001, infrastructure checkpoint evidence, and cross-tower requirements into a common control and assessment architecture.
· Design human-in-the-loop controls, approval gates, audit logging, least-privilege access, rollback patterns, and exception handling for agentic workflows.
· Own security architecture decisions for agent-assisted discovery, IAM/offboarding assessment, vulnerability triage, AppSec/repository review, evidence reporting, and remediation workflow support.
· Partner with CISO, CSS, BISO, IBM Consulting Delivery CIO, PMO, and tower architects to align Tower 4 outputs with existing IBM control programs and shared services.
· Define secure-by-default patterns for new / existing Consulting assets and reusable remediation patterns for existing delivery exposure.
· Maintain Tower 4 architecture artifacts, decision records, control catalog, pattern catalog, and exception principles.
· Review and approve agentic designs before production use, especially where agents access security evidence, project data, repositories, ticketing systems, or control tooling.
•8+ years security architecture, solution architecture, or enterprise architecture experience in a consulting, managed services, or large enterprise environment.
· Strong working knowledge across identity and access, application security, data protection, infrastructure security, cloud security, monitoring, vulnerability management, and governance.
· Experience designing secure technical platforms that integrate multiple enterprise systems, security tools, workflow platforms, and reporting layers.
· Practical understanding of AI-assisted workflows, digital agents, tool access, workflow orchestration, auditability, and operational risk controls.
· Ability to translate executive security objectives into implementable architecture, control patterns, and delivery roadmaps.
· Strong written and verbal communication; capable of producing executive-ready architecture and risk materials.
• Cloud Security Architecture: Experience with designing and implementing cybersecurity solutions in hybrid and multi-cloud environments, ensuring alignment with industry best practices and the client's unique needs.
• Advanced Threat Management: Deep understanding of threat management principles, including threat detection, incident response, and mitigation strategies.
• Security Framework Development: Experience with developing and implementing security governance frameworks that align with organizational objectives, regulatory requirements, and industry standards.
Preferred Qualifications
· CISSP, SABSA, TOGAF, CISM, or equivalent architecture or security credential
· Experience with IBM security and delivery capabilities such as IBM AccessHub, IBM Verify, QRadar, Guardium, X-Force, IBM Consulting Advantage, or CSS shared services
· Experience with AI governance, model risk controls, prompt/tool governance, secure automation, or agentic workflow design
· Familiarity with NIST CSF, ISO 27001, SOC 2, ITSS, DS&P, and enterprise compliance evidence models
Seen 16 hours ago · IBM postings close after a median of 2 days.
Original posting on IBM's site ↗
Posting text belongs to the employer. Removal requests: contact us.
Nearby
Live postings like this one
Same employer first, then the same role elsewhere.
- 4h ago
- 4h ago
- 4h ago
- 4h ago
- 4h ago
- 4h ago
- 4h ago
- 4h ago
One job at a time
One posting. One CV. $25.
Pick the job you actually want and we write for it.