Skip to main content
Back to jobs

Cybersecurity Architect - Threat and Vulnerability Management

External
caa logoCaa · Nashville, TN
Full-timeHybrid1w ago
ComplianceMicroservicesOAuthObservabilityServerlessSystem Design
Cover LetterConnect

Prepare for this interview

Elite

AI-generated questions, company research, and talking points tailored to this role


About the role

Creative Artists Agency (CAA) is the leading entertainment and sports agency, with global expertise in filmed and live entertainment, digital media, publishing, sponsorship sales and endorsements, media finance, consumer investing, fashion, trademark licensing, and philanthropy. Distinguished by its culture of collaboration and exceptional client service, CAA's diverse workforce identifies, innovates, and amplifies opportunities for the people and organizations that shape culture and inspire the world. The trailblazer of the agency business, CAA was the first to build a sports business, create an investment bank, launch a venture fund, found technology start-up companies, establish a philanthropic arm, build a business in China, and form a brand marketing services division, among other innovations. Named Most Valuable Sports Agency by Forbes for eight consecutive years, CAA represents more than 2,000 of the world's top athletes in football, baseball, basketball, hockey, soccer, in addition to coaches, on-air broadcasters, and sports personalities and works in the areas of broadcast rights, corporate marketing initiatives, social impact, and sports properties for sales and sponsorship opportunities. Founded in 1975, CAA is headquartered in Los Angeles, and has offices in New York, Nashville, Memphis, Chicago, Miami, London, Munich, Geneva, Stockholm, Shanghai, and Beijing, among other locations globally. We are seeking a strategic and hands-on Cybersecurity Architect to join our Purple Team, responsible for designing, validating, and continuously evolving enterprise security architecture in alignment with real-world adversarial threats. This role operates at the intersection of offensive and defensive security, leveraging Red Team insights and Blue Team capabilities to ensure systems are secure by design, resilient by default, and continuously tested against emerging attack techniques. As a key leader in our security organization, the Cybersecurity Architect will drive the development of secure design principles, reference architectures, and security standards across a modern, SaaS-enabled and cloud-first ecosystem. This includes securing complex identity flows, third-party integrations, APIs, and distributed systems while addressing the shared responsibility model inherent in SaaS platforms. The ideal candidate brings a deep understanding of attacker methodologies and defensive controls, applying that knowledge to proactively identify architectural weaknesses, reduce attack surface, and enhance detection and response capabilities. This individual will work closely with engineering, cloud, and product teams to embed security into the software development lifecycle, ensuring that security is not an afterthought but a foundational component of system design. This role requires a balance of technical depth and strategic influence, with responsibility for translating complex threats into actionable architectural improvements and guiding the organization toward Zero Trust and secure-by-design maturity. Success in this position will be measured by the organization's ability to prevent, detect, and respond to sophisticated threats, as well as by the strength and scalability of its security architecture across both enterprise and SaaS environments.

Responsibilities

  • Design and evolve enterprise security architecture with a strong emphasis on secure-by-design principles, ensuring security is embedded early in system and application lifecycles
  • Lead the development and adoption of secure design patterns and reference architectures, particularly for cloud-native and SaaS-based environments
  • Act as a key liaison between Red Team and Blue Team, translating adversarial findings into architectural improvements, detection use cases, and resilient system designs
  • Plan and execute Purple Team exercises to validate security controls across infrastructure, applications, and SaaS platforms, ensuring visibility and response capabilities are effective
  • Develop and maintain threat models for critical systems, including SaaS integrations, APIs, and identity flows, identifying attack paths and prioritizing mitigations
  • Define and enforce security architecture standards for SaaS adoption
  • Assess and secure SaaS ecosystems, including third-party integrations, OAuth applications, and API exposure risks
  • Evaluate and recommend controls for modern architectures, including Zero Trust, microservices, containers, and serverless environments
  • Drive improvements in detection engineering by mapping adversary TTPs (e.g., via MITRE ATT&CK) to logging, alerting, and response capabilities
  • Collaborate with cloud and platform teams to ensure secure configuration and continuous compliance across SaaS and IaaS environments
  • Conduct architecture risk assessments and provide actionable remediation strategies aligned with business risk tolerance
  • Promote security observability across SaaS platforms by ensuring pro

Benefits

Vision insuranceEquity / stock options

Additional Information

Job Description


Your Match

How well this role fits your profile.

Company Intel

What employees say

Worked at caa? Share your experience

Interested in this role?

Apply on the company's website.

Cover LetterConnect