Senior Data Security Architect

Job Level:  Director
Job Function:  Business Resilience & Security
Location: 

Charlotte, NC, US, 28202

Employment Type:  Full Time
Requisition ID:  8474

SMBC Group is a top-tier global financial group. Headquartered in Tokyo and with a 400-year history, SMBC Group offers a diverse range of financial services, including banking, leasing, securities, credit cards, and consumer finance. The Group has more than 130 offices and 80,000 employees worldwide in nearly 40 countries. Sumitomo Mitsui Financial Group, Inc. (SMFG) is the holding company of SMBC Group, which is one of the three largest banking groups in Japan. SMFG’s shares trade on the Tokyo, Nagoya, and New York (NYSE: SMFG) stock exchanges.

 

In the Americas, SMBC Group has a presence in the US, Canada, Mexico, Brazil, Chile, Colombia, and Peru. Backed by the capital strength of SMBC Group and the value of its relationships in Asia, the Group offers a range of commercial and investment banking services to its corporate, institutional, and municipal clients. It connects a diverse client base to local markets and the organization’s extensive global network. The Group’s operating companies in the Americas include Sumitomo Mitsui Banking Corp. (SMBC), SMBC Nikko Securities America, Inc., SMBC Capital Markets, Inc., SMBC MANUBANK, JRI America, Inc., SMBC Leasing and Finance, Inc., Banco Sumitomo Mitsui Brasileiro S.A., and Sumitomo Mitsui Finance and Leasing Co., Ltd.

Role Description

The Senior Data Security Architect is responsible for developing, governing, and advancing enterprise data security capabilities across structured and unstructured data environments. This role provides architectural leadership for data protection, data loss prevention, encryption, insider risk management, cloud data security, AI and analytics platforms, and data governance integration.

The individual will partner closely with business, technology, security, data governance, privacy, risk, and engineering teams to define security requirements, establish target-state architectures, and ensure sensitive information is appropriately protected throughout its lifecycle. The role serves as a senior technical advisor and subject matter expert responsible for translating security strategy into practical security architectures, standards, and control requirements.

Role Objectives

•    Design and govern enterprise data protection controls, including data discovery, classification, labeling, encryption, tokenization, masking, rights management, and secure data sharing.
•    Define security architectures and requirements to protect sensitive data at rest, in transit, and in use across on-premises, cloud, SaaS, and hybrid environments.
•    Lead the architecture and governance of Data Loss Prevention (DLP) and Insider Risk capabilities across email, endpoint, cloud, web, collaboration, and AI platforms.
•    Establish policies, detection capabilities, and monitoring controls to prevent unauthorized access, disclosure, misuse, or exfiltration of sensitive information.
•    Define and govern data security architectures for cloud platforms, data lakes, data warehouses, analytics platforms, AI/ML solutions, and modern data engineering environments.
•    Establish security requirements for data sharing, AI model development, data products, and emerging technologies while ensuring alignment with enterprise security standards.
•    Define enterprise standards and architectural requirements for encryption, cryptography, key management, secrets management, certificate management, and data protection technologies.
•    Partner with Infrastructure, Cloud Engineering, and Application teams to ensure cryptographic controls and key management practices are effectively implemented and governed across the enterprise.
•    Partner with Data Governance, Privacy, Legal, Compliance, and Risk teams to integrate security requirements into enterprise governance, classification, retention, and regulatory compliance processes.
•    Conduct security architecture reviews for applications, cloud services, data platforms, and strategic technology initiatives, identifying risks and recommending appropriate mitigations.
•    Serve as a trusted advisor to business, technology, and engineering teams, providing guidance on secure-by-design solutions, security best practices, and emerging data protection capabilities.
•    Support regulatory examinations, audits, risk assessments, and the development of security policies, standards, procedures, and control frameworks.

Qualifications and Skills

•    Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Systems, Engineering, or a related field. Equivalent experience will be considered.
•    8+ years of experience in cybersecurity, information protection, data security, or security architecture roles.
•    5+ years of experience designing and implementing enterprise-scale data protection and data security solutions.
•    Strong expertise in data security architecture, information protection, data loss prevention, and sensitive data protection programs.
•    Deep knowledge of data classification, data discovery, labeling, data lifecycle management, and data governance principles.
•    Strong understanding of encryption technologies, key management systems, certificate management, tokenization, and cryptographic controls.
•    Experience securing structured and unstructured data across on-premises, cloud, SaaS, and hybrid environments.
•    Demonstrated expertise in cloud security, cloud-native data platforms, and modern analytics architectures.
•    Experience with insider risk management, data monitoring, and data exfiltration prevention initiatives.
•    Knowledge of AI/ML, analytics, and emerging technology security risks and corresponding protection controls.
•    Strong understanding of identity and access management concepts as they relate to data security.
•    Experience with Microsoft Purview Information Protection, Data Loss Prevention, Insider Risk Management, and Data Governance capabilities.
•    Experience with Microsoft Defender, Microsoft Security solutions, and Microsoft cloud security technologies.
•    Familiarity with DSPM, data discovery, and data governance platforms.
•    Experience securing enterprise data platforms such as Databricks and cloud-native analytics environments.
•    Experience with SaaS security, CASB, cloud security posture management, and data protection technologies.
•    Familiarity with enterprise encryption, key management, and certificate management solutions.
•    Experience with AI governance, AI security controls, and AI data protection capabilities.
•    Demonstrated experience developing security architectures, standards, policies, and technical requirements.
•    Experience in financial services or another highly regulated industry.

Additional Requirements

•    Excellent written and verbal communication skills with the ability to communicate complex technical concepts to technical and non-technical audiences.
•    Strong executive presentation and stakeholder management skills.
•    Proven ability to build relationships and influence decisions across business and technology organizations.
•    Strong analytical, problem-solving, and critical-thinking capabilities.
•    Experience preparing architecture documents, standards, technical designs, security requirements, and executive-level presentations.
•    Strong documentation and technical writing skills with attention to detail and accuracy.
•    Ability to manage multiple priorities and operate effectively in a fast-paced, highly regulated environment.
•    Demonstrated leadership, collaboration, and consensus-building skills across geographically distributed teams.
•    Self-motivated with the ability to work independently while driving initiatives to completion.
•    Experience working within financial services or other highly regulated industries is strongly preferred.

SMBC’s employees participate in a Hybrid workforce model that provides employees with an opportunity to work from home, as well as, from an SMBC office. SMBC requires that employees live within a reasonable commuting distance of their office location. Prospective candidates will learn more about their specific hybrid work schedule during their interview process. Hybrid work may not be permitted for certain roles, including, for example, certain FINRA-registered roles for which in-office attendance for the entire workweek is required.

 

SMBC provides reasonable accommodations during candidacy for applicants with disabilities consistent with applicable federal, state, and local law. If you need a reasonable accommodation during the application process, please let us know at accommodations@smbcgroup.com.


Nearest Major Market: Charlotte