Security Architect Lead, Security Assurance
Job
Carlyle Investment Management L.L.C.
Washington, DC (In Person)
$180,000 Salary, Full-Time
Review key factors to help you decide if the role fits your goals.
Pay Growth
?
out of 5
Not enough data
Not enough info to score pay or growth
Job Security
?
out of 5
Not enough data
Calculating job security score...
Total Score
74
out of 100
Average of individual scores
Skill Insights
Compare your current skills to what this opportunity needs—we'll show you what you already have and what could strengthen your application.
Job Description
Basic information
Job Name:
Security Architect Lead, Security Assurance Location:
Washington, DC Line of Business:
Global Technology & Solutions Job Function:
Investor Services Date:
Monday, March 9, 2026 Position Summary The Senior Security Architect leads the design and evolution of Carlyle's enterprise application and security architecture capabilities. This role is responsible for establishing secure architecture frameworks, defining reference models and reusable design patterns, and embedding security-by-design principles across cloud, application, data, identity, and AI-driven systems. As the organization introduces AI-enabled platforms and GenAI capabilities, this role will architect secure patterns for AI/ML workloads, LLM integrations, data pipelines, and model governance to ensure responsible, secure, and compliant adoption. The Senior Security Architect partners closely with development, data science, platform, DevSecOps, infrastructure, and business leaders to ensure that AI-enabled architectures align with enterprise risk tolerance while enabling innovation.In-Office Requirement:
4 days per week Responsibilities 50%- Security Architecture Strategy & Design Design and maintain the enterprise Security Architecture Framework aligned with SABSA, TOGAF, and
NIST CSF
Establish enterprise application security architecture standards, baselines, and reusable reference models Develop secure design patterns for web, mobile, API, microservices, SaaS, cloud-native, and AI-enabled architectures Architect solutions for authentication, authorization, encryption, secure communications, and data protection Design and implement API security strategies including identity flows, gateway controls, throttling, and rate limiting Embed Zero Trust and least-privilege principles across enterprise ecosystems Establish cloud-native, container, serverless, Infrastructure-as-Code, and AI workload security guardrails Architect secure data handling practices, including encryption at rest and in transit Provide security architecture guidance for AI/ML and GenAI-integrated applications, ensuring secure model access, data boundary enforcement, and integration with enterprise identity and logging controls Assess architectural risks associated with AI-enabled systems, including third-party model integrations, API-based model consumption, and sensitive data exposure Lead security design reviews for new applications, AI-enabled solutions, and major system changes Assess SaaS platforms, third-party integrations, API-driven services, and AI service providers for architectural risk Develop and maintain security architecture roadmaps aligned with enterprise strategy 30% of time- Threat Modeling & Risk Integration Develop and mature enterprise threat modeling practices Facilitate threat modeling workshops with development and architecture teams Perform architecture risk assessments and recommend compensating controls Integrate architecture review outputs into enterprise risk management and governance processes 10% of time
- Governance, Enablement & Leadership Lead or support the Security Architecture Review Board (SARB) Develop and deliver security architecture guidance and training for developers and solution architects Mentor engineering and architecture teams to elevate secure design maturity Maintain documentation of architectural standards, decisions, and reference implementations Stay current on emerging threats, technologies, regulatory expectations, and industry best practices Lead cross-functional security initiatives with enterprise-wide impact 10% of time•DevSecOps & Secure SDLC Enablement.
NASDAQ:
CG) is a global investment firm with $477 billion of assets under management and more than half of the AUM managed by women, across 678 investment vehicles as of December 31, 2025. Founded in 1987 in Washington, DC, Carlyle has grown into one of the world's largest and most successful investment firms, with more than 2,500 professionals operating in 27 offices in North America, Europe, the Middle East, Asia and Australia. Carlyle places an emphasis on development, retention and inclusion as supported by our internal processes and seven Employee Resource Groups (ERGs). Carlyle's purpose is to invest wisely and create value on behalf of its investors, which range from public and private pension funds to wealthy individuals and families to sovereign wealth funds, unions and corporations. Carlyle invests across three segments- Global Private Equity, Global Credit and Carlyle AlpInvest
- and has expertise in various industries, including: aerospace, defense & government services, consumer & retail, energy, financial services, healthcare, industrial, real estate, technology & business services, telecommunications & media and transportation.
Similar remote jobs
LifeStance Health
Norfolk, VA
Posted1 day ago
Updated9 hours ago
CenterWell
Posted1 day ago
Updated9 hours ago
Allivet Pet Pharmacy - Miami Lakes, FL
Miami Lakes, FL
Posted1 day ago
Updated9 hours ago
Similar jobs in Washington, DC
Children's National Health System
Washington, DC
Posted1 day ago
Updated9 hours ago
DeSoto Parish School Board
Washington, DC
Posted1 day ago
Updated9 hours ago
Similar jobs in Washington, D.C. (District of Columbia)
Ingenovis Health
Washington, DC
Posted1 day ago
Updated9 hours ago