Full-Time

Security Architect

Chicago, IL

Posted on 5/9/2025

GuidePoint Security

GuidePoint Security

1,001-5,000 employees

Cybersecurity consulting, software solutions, managed services

No salary listed

Chicago, IL, USA

Hybrid

Remote work allowed when not visiting clients; travel up to 75% within North Central territory.

Category
IT & Security (1)
Required Skills
Vulnerability Analysis
Risk Management
Linux/Unix
Data Analysis
Requirements
  • MUST be located in Chicago, IL and open to local/regional travel for customer/vendor partner events
  • Minimum 5 years in an enterprise level security consultative, vendor, or operational role building and assessing Information Security architectures and programs
  • Proficiency in multiple security technologies, including: network security and architecture, Next-Generation Firewall, cloud security, Data Security, Vulnerability & Risk Management, Proxy, Endpoint Detection and Response, Identity and Access Management, Security Information and Event Management & Analytics
  • A good listener to work with clients to understand issues/gaps in their security programs and works alongside them to provide solutions
  • Proactively research and engage emerging vendors and technologies to understand how they may be used to solve our clients challenges
  • Excellent soft skills with the ability to articulate complex technical content to both technical and non-technical audiences
  • Proactively works to mature the business, including improving existing offerings and creating new offerings
  • Author comprehensive business and technical collateral to support the business that is proficiently tailored to both technical and managerial audiences
  • Security Engineers work from remote/virtual when not visiting client locations or attending events/meetings
  • Position will require travel within the Chicago metro area
  • Expectations for this role is 70% Presales and 30% delivery
  • Deep proficiency in multiple security technologies, including: network security, Next-Generation Firewall, cloud security, Data Loss Prevention, Cloud Access Security Broker, Proxy, Identity and Access Management, Security Information and Event Management/Analytics
  • Deep expertise architecting and designing enterprise scale security solutions
  • Strong networking and security troubleshooting
  • Deep proficiency in various client and server operating systems (Windows, Linux, macOS)
  • Working technical knowledge of advanced security concepts (Zero Trust, defense in depth)
Responsibilities
  • Engage in the complete security technologies opportunity lifecycle from pre-sales through delivery and have the freedom and control over how engagements are scoped and delivered
  • Collaborate with clients to understand issues and gaps in their security programs and provide solutions
  • Proactively research and engage emerging vendors and technologies to understand how they may be used to solve clients challenges
  • Create comprehensive business and technical collateral to support the business tailored to technical and managerial audiences
  • Work remotely and travel within the Chicago metro area as needed
  • Balance presales activities (approximately 70 percent) with delivery (approximately 30 percent)
  • Architect and design enterprise-scale security solutions and provide guidance on security architecture
  • Communicate complex technical content to both technical and non-technical audiences
  • Contribute to advancing and expanding GuidePoint's security offerings and capabilities
  • Provide technical leadership during pre-sales engagements and delivery engagements
Desired Qualifications
  • Bachelor’s degree in a relevant discipline or equivalent experience
  • 5+ years of security engineering experience in the Information Security industry OR as a technical lead for an internal Information Security program
  • Previous pre-sales experience strongly preferred
  • Experience with security technologies including Symantec Data Loss Prevention, ForeScout, Palo Alto, Check Point, CrowdStrike, Splunk, and AWS/Azure/GCP

GuidePoint Security helps organizations assess and reduce cybersecurity risk through a mix of security technologies, consulting, and managed security services for enterprise and government clients. It works by assessing a client’s security posture, recommending and deploying appropriate tools and controls, and continuously monitoring and managing security operations to detect and respond to threats. The company differentiates itself with deep industry knowledge and hands-on practitioner experience from the DoD, Intelligence Communities, and Fortune 500, enabling tailored solutions for complex, mission-critical needs instead of generic products. Its goal is to help clients make informed security decisions, lower risk exposure, and defend against evolving cyber threats using a combination of technology, expertise, and managed services.

Company Size

1,001-5,000

Company Stage

Growth Equity (Non-Venture Capital)

Total Funding

N/A

Headquarters

Reston, Virginia

Founded

2011

Simplify Jobs

Simplify's Take

What believers are saying

  • Red Sift partnership brings email security to enterprise customers expanding reseller lineup.
  • CNAPP Enablement Service streamlines cloud-native security for large organizations.
  • Veza integration strengthens identity security with proactive risk management insights.

What critics are saying

  • Mandiant erodes market share with superior AI-powered MDR in 12-18 months.
  • CrowdStrike Falcon causes client attrition via advanced automation in 6-12 months.
  • AWS Bedrock Guardrails commoditizes AI governance undercutting reseller demand in 6-12 months.

What makes GuidePoint Security unique

  • GuidePoint aligns AI Readiness Assessments with NIST AI RMF's Map, Measure, Manage, Govern functions.
  • Tailored Regulatory Compliance Strategy navigates EU AI Act's global standards for clients.
  • Ed's red team expertise oversees generative AI implementations enhancing cybersecurity.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Paid Holidays

Unlimited Paid Time Off

Remote Work Options

Phone/Internet Stipend

401(k) Retirement Plan

Pet Insurance

Company News

FAIR Institute
Dec 9th, 2025
Four Findings from FAIRCON25

Four findings from FAIRCON25. I had the fun, engaging, energizing, and informative pleasure of attending the 10th Annual FAIR Conference in New York City this year with its team from GuidePoint Security. This blog post is contributed by GuidePoint Security, a FAIR Institute sponsor. Author Ben Moreland is Risk Practice Director at GuidePoint Security The cyber risk management community there was great, breakout sessions were packed with lessons learned, and the sessions, education, and content were extremely engaging. I took away more than four findings, but I couldn't resist the consonance of this catchy title. Here are four findings (or key takeaways) that resonated with me: * How you COMMUNICATE risk is as important as how you MEASURE risk. Jack Jones and the FAIR community have given scientific and mathematical rigor to risk modeling and analysis. But that doesn't mean you need to be a mathematician to know, understand, and communicate cyber risk. Using the FAIR model provides measurable, data-driven analysis that enables decision making. Being able to communicate risk in dollars and probabilities is one of many frequencies that may resonate with your board or audit committee. Traditional qualitative "measures" and stoplight colors provide an at-a-glance understanding of risk; but having measured, accurate, risk ranges with impact and probability add significantly more confidence to the executive team for conversations around information and cybersecurity investments, trade-offs, and prioritization. * Risk decision intelligence is a force multiplier Reframing "Cyber Risk Quantification" to "Cyber Decision Intelligence" was a challenge posed to conference attendees by Saket Modi, CEO of SAFE. Thinking of it another way, cyber risk quantification is the action, but decision intelligence is the outcome. The late, great, venerated General Colin Powell was quoted with "Perpetual optimism is a force multiplier". I'm a huge fan of Colin Powell and would like to borrow from him in stating "risk decision intelligence is (also) a force multiplier". When I led Information Security for a media company I was often asked by peers and other executives: "Are we secure?". As simple and generic as that statement is - they were serious. And as CEOs, CIOs, CFOs, and other executives rely on big data and business intelligence to amplify their ability to make decisions that drive and grow their business, so, too, should CISOs and other cyber executives. * Compliance is your floor, not your ceiling "Compliance is your floor, not your ceiling", are words I've heard Alla Valente, Principal Analyst at Forrester, utter before, but at FAIRCON, they hit a nerve. Compliance is important - AND - you don't have to stop there. At GuidePoint Security, FAIR Institute Inc. help manage and treat risk for so many customers. In contrast, I've seen too many organizations limit their IT+information+cyber-security programs to meet compliance requirements and audit standards. Sometimes a shiny new tool or popular platform that vendors are marketing and CISOs are raving about get added to the security stack too. But, as FAIR Institute Inc. know, being compliant and having cool security tools doesn't make your organization and data "secure". While 100% cyber risk elimination isn't possible in today's digital age, compliance with regulations and standards linked to SOX, PCI, CMMC, HIPAA, NIST and others is only the beginning, a catalyst. Governance, Risk and Compliance (GRC) leaders need to correlate risks in the context of business strategies. Cyber risk quantification or - to use a new and emerging term - cyber business intelligence - aims to do just that. So I encourage GRC leaders, risk managers, cyber executives to evolve their programs beyond compliance if they're not doing so already. * Quantifying cyber risk is a journey, FAIR Institute Inc. is all at different stages FAIR Institute Founder, Nick Sanna, opened the FAIRCON25 welcome address with "The Future of Cyber Risk Management Starts Here." As I met with, spoke with, and listened to attendees, I really understood the journey FAIR Institute Inc. is on together. Students I met from Georgetown University and Harvard are learning fundamentals and frameworks around cyber risk management. Several risk managers I spoke with or heard from identified pain points and lessons learned in moving qualitative third-party risk management to a more continuous, autonomous, quantitative risk-aligned program. Executive speakers demonstrated a variety of ways risk may be communicated and reported. Each offered valuable insights into risk management stages. The best part of the conference for me was knowing I'm on the journey with a like-minded community all focused on a similar mission to improve cyber risk management. Learn more about quantifying your cyber risk.

ChannelE2E
Sep 15th, 2025
Red Sift Joins GuidePoint Security's Lineup of Reseller Offerings

Red Sift has partnered with GuidePoint Security in a new reseller partnership that brings Red Sift's email security and attack surface management platform to GuidePoint's enterprise customers.

GuidePoint Security
Jul 21st, 2025
GuidePoint Security Launches New Cyber Risk Quantification Service To Help Organizations Make Smarter Security Investments

GuidePoint Security launches new Cyber Risk Quantification Service to help organizations make smarter security investments.

ADD-USA, Inc.
Jun 17th, 2025
GitGuardian Partners with GuidePoint Security to Strengthen Application Security Offerings

GitGuardian partners with GuidePoint Security to strengthen application security offerings.

Cyber Technology Insights
May 21st, 2025
Bitwarden Now Offered Through GuidePoint Security

Bitwarden, the trusted leader in password, passkey, and secrets management, announced a strategic reseller partnership with GuidePoint Security, a leading cybersecurity solutions provider.

INACTIVE