Enterprise Architect - Information Security and Compliance
We tailor your resume to this role and apply for you in seconds.
Apply to Enterprise Architect - Information Security and Compliance at Costco WholesaleJob details
- Location
- Issaquah, Washington
- Work type
- Onsite
- Compensation
- $171,000 - $240,000/yr
- Posted
- today
- Apply on
- phf.tbe.taleo.net
About this role
Costco IT is responsible for the technical future of Costco Wholesale, the third largest retailer in the world with wholesale operations in fourteen countries. Despite our size and explosive international expansion, we continue to provide a family, employee centric atmosphere in which our employees thrive and succeed.
This is an environment unlike anything in the high-tech world and the secret of Costco’s success is its culture. The value Costco puts on its employees is well documented in articles from a variety of publishers including Bloomberg and Forbes. Our employees and our members come FIRST. Costco is well known for its generosity and community service and has won many awards for its philanthropy. The company joins with its employees to take an active role in volunteering by sponsoring many opportunities to help others.
Come join the Costco Wholesale IT family. Costco IT is a dynamic, fast-paced environment, working through exciting transformation efforts. We are building the next generation retail environment where you will be surrounded by dedicated and highly professional employees.
Enterprise Architects work with stakeholders, leadership, and subject matter experts to build a holistic view of the organization's value streams, goals, strategies, capabilities, processes, information, and information technology assets. The role of the enterprise architect is to ensure that the business and IT are in alignment. The enterprise architect links the business mission, strategy, capabilities and processes of an organization to its IT strategy, documents this using multiple architectural models or views that show how the current and future needs of an organization will be met in an efficient, sustainable, agile, and adaptable manner, and fosters the changes needed to achieve.
Costco’s Architecture team is looking for a highly ambitious, self-motivated, experienced technical individual to fill the role of Enterprise Architect with a focus on Information Security and Compliance. This architect will partner with IT business areas to govern, design and implement secure information systems that support Costco’s global system architecture. They will translate business objectives and risk management strategies into enterprise standards, reference architectures, and secure-by-design patterns across on-prem, hybrid, and cloud environments, and will guide the secure adoption of emerging technologies, including AI. This architect must possess demonstrable knowledge of cloud security, networking, identity and access management, and regulatory compliance, and will serve as a senior trusted advisor to project teams and IT leaders.
If you want to be a part of one of the worldwide BEST companies “to work for”, simply apply and let your career be reimagined.
ROLE
Partners with Enterprise Architecture to develop strategies, standards, and secure reference architectures for enterprise solutions.
Reviews and designs new systems, embedding security and compliance requirements.
Creates reusable security design patterns and reference architectures; drives zero trust and secure-by-design adoption across the enterprise.
Creates design Security reference architectures, technical target architectures, conceptual solution architectures and patterns that can be repeatedly utilized across Costco systems and ensures these architectures are documented and periodically ratified.
Identifies dependencies with Costco value streams and shared services based on enterprise security architectures.
Identifies and integrates essential safeguards and practices into the overall solution design of technology initiatives to deliver security requirements, documenting any residual risks.
Maintains Security related Business Capability Hierarchies and collaborates with Security delivery teams to assess maturity of the capabilities resulting in heat maps and road maps.
Analyzes technical risks, conducts threat modeling and security architecture reviews, and advises on risk mitigation strategies.
Defines security patterns for machine and non-human identities (service accounts, workload identities, API keys, and AI agents), including credential lifecycle, least-privilege scoping, and workload identity federation.
Establishes software supply chain security requirements, including third-party and open-source software risk, SBOM visibility, and secure software development lifecycle practices aligned to NIST SSDF (SP 800-218).
Takes responsibility for the technical content (architecture and design), integrity, quality, and security of solutions.
Addresses compliance requirements such as Payment Card Industry (PCI), Health Insurance Portability and Accountability Act (HIPAA), Personally Identifiable Information (PII), and Sarbanes-Oxley (SOX).
Designs and deploys secure cloud solutions and applies best practices in security for cloud, hybrid, and on-prem applications.
Defines secure patterns, standards, and governance for the adoption of AI/ML, generative AI, and agentic AI systems.
Serves as a senior trusted advisor, providing security-focused architecture consulting to project teams and IT leaders.
Defines data protection architectures spanning data classification, data loss prevention (DLP), encryption and key management, tokenization, and data security posture management (DSPM) across cloud and on-prem data stores.
Develops secure API and integration patterns (API gateways, service-to-service authentication and authorization) for internal and partner-facing services.
Partners with Security Operations and Incident Response to translate incident findings, threat intelligence, and red/purple team results into architectural improvements and updated patterns.
Co-designs the security related integration and deployment architectures for our on-premise and Cloud Networks.
Supports the development of product roadmaps based on delivery or prioritized features.
Evaluates and recommends security technologies and services (RFI/RFP, proof of concept) and drives consolidation and rationalization of the enterprise security tooling portfolio.
Coaches and mentors peers and associates in Costco’s architecture framework.
Measures and matures Costco’s Enterprise Architects practice.
Establishes and maintains Costco's Architectural Framework and Governance Model.
Participates in team planning and activities for improving skills, knowledge, and quality of work.
Continues personal growth in the areas of technology, business knowledge, and company policies.
REQUIRED
Interpersonal skills, including collaboration, facilitation, and negotiation.
Experience with architecture frameworks, methods, and tools.
Graphical modeling skills.
Analytical skills.
Planning and organizational skills.
Applied broad knowledge of technical domains (application, information, integration, and infrastructure) and business functional domains.
Ability to assess risks and apply risk profiles to Enterprise Architects alternatives.
Ability to estimate the financial impact of Enterprise Architects alternatives.
Understands the political climate of an enterprise and how to navigate the politics.
10+ years’ of professional Information Technology experience in solutioning, designing, development, and delivering Architecture solutions for larger enterprise.
5+ years’ experience in a senior architecture role, with expertise across security disciplines such as identity and access management (IAM), networking, application security, and infrastructure, Security operations.
5+ years’ enterprise-level experience designing and deploying secure cloud solutions (Azure, GCP, or AWS), integrating identity and access management, network security, data protection, and encryption.
5+ years’ of technical team leadership experience.
Experience designing security standards and patterns to ensure compliance with regulatory requirements and industry frameworks such as PCI, SOX, HIPAA, GDPR, ISO 27001, and NIST.
Experience with zero trust architecture, threat modeling, and security architecture reviews.
Experience applying industry security architecture frameworks and references such as SABSA, NIST Cybersecurity Framework (CSF) 2.0, CIS Controls, and MITRE ATT&CK.
Demonstrates a strong understanding of emerging technologies, including AI/ML, and their security and governance implications.
Excellent verbal and written communication skills; ability to translate technical designs and security trade-offs to multiple audiences, including Executives.
Proven skills in leadership, collaboration, governance, and consensus building within a large, matrixed organization.
Recommended
Bachelor’s degree or equivalent experience in computer science, information systems, cybersecurity, or related fields.
Industry certifications such as CISSP, CCSP, CISM, or TOGAF.
Cloud security certifications (e.g., AWS Certified Security – Specialty, Google Professional Cloud Security Engineer, Microsoft Azure security certifications), SABSA (SCF), or CCSK.
Experience with AI security and governance frameworks (e.g., NIST AI RMF, ISO/IEC 42001).
Experience securing generative and agentic AI systems and their non-human identities (e.g., OWASP Top 10 for LLM Applications, OWASP Agentic Security guidance, MCP/A2A protocol security considerations).
Experience with containers (Kubernetes, Docker), Infrastructure as Code, and DevSecOps practices.
Experience and understanding of Costco’s business model and legacy systems.
Extensive knowledge in one or more of the following areas: Identity and Access Management, Cloud Security, Cloud Networking, Data Security, Infrastructure Security, Zero Trust, Security Ops, Security Engineering.
Proficient in Google Workspace applications, including Sheets, Docs, Slides, and Gmail.
Required Documents
● Cover Letter
● Resume
California applicants, please click here to review the Costco Applicant Privacy Notice.
Pay Ranges:
Level 3 - $171,000 - $205,000, Bonus and Restricted Stock Unit (RSU) eligible
Level 4 - $201,000 - $240,000, Bonus and Restricted Stock Unit (RSU) eligible
We offer a comprehensive package of benefits including paid time off, health benefits - medical/dental/vision/hearing aid/pharmacy/behavioral health/employee assistance, health care reimbursement account, dependent care assistance plan, short-term disability and long-term disability insurance, AD&D insurance, life insurance, 401(k), stock purchase plan to eligible employees.
Costco is committed to a diverse and inclusive workplace. Costco is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or any other legally protected status. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request to [email protected]
If hired, you will be required to provide proof of authorization to work in the United States. In some cases, applicants and employees for selected positions will not be sponsored for work authorization, including, but not limited to H1-B visas.