Sr. Engineer, Information Security Architect
LOVESAC COMPANY Stamford, Connecticut, United States · $95K–$125K/yr
Retail · 501-1,000 employees
About the role
The role involves designing and evolving the enterprise security architecture while managing security platforms and tools. It requires close collaboration with IT and application teams to embed security into cloud, data, and infrastructure designs.
What they look for
Requirements
Candidates must have a bachelor's degree in a relevant field and 5-8 years of experience in security engineering or operations. Professional certifications such as CISSP, CISM, or Security+ are required, along with hands-on experience in cloud and enterprise security environments.
Benefits
Full description
Job DetailsJob Location: Remote - Stamford, CTPosition Type: Full TimeSalary Range: $95,000.00 - $125,000.00 Salary/yearJob Category: CorporateAbout Lovesac
We are a young-at-heart, fast-growing furniture company, dedicated to helping people fill their homes with Total Comfort™. We do this by designing and innovating furniture solutions that are adaptable, washable, expandable, and delivered right-to-your-door-able, allowing our customers to live the life they want to live.
Our Designed for Life mission started with Sacs, a seat so much better than your classic beanbag made with repurposed Durafoam and designed to reduce environmental impact while providing unimaginable, cloud-like comfort. From there, we expanded the possibility for sustainable furniture with Sactionals, a customizable modular sectional that can be endlessly rearranged to evolve with you. Our product line has grown a lot since our Sacs days, but our goal will always remain the same – to create truly adaptable, comfortable furniture that can be with you for life.
About our Culture
At Lovesac, we strive to be an employer of choice by embodying a culture that encourages team members to think and dream big. We call this Top Ambition. We aim to not only excel within our industry but also make a meaningful impact on the world. Above all else, we’re driven by love (because it matters) and are dedicated to promoting love and happiness in all aspects of our work. It’s about success, of course, but it’s also about making a positive impact on everyone our business touches.
About the Role
The Information Security Architect and Sr. Engineer is a technical role responsible for designing, engineering, and evolving Lovesac’s information security architecture, platforms, and services while partnering closely with Enterprise Architecture, IT Operations, and technology teams across the organization. This role helps define the long-term security architecture vision, translates business and technology strategy into scalable security patterns and standards, and ensures information security capabilities are engineered and operated effectively as the business grows. This role balances strategic architecture leadership with hands-on engineering and platform execution. This role is also responsible for both the cyber department’s footprint, including security platforms, tooling, integrations, automation, and control patterns—and for advising and supporting secure design across enterprise solutions. Working alongside Enterprise Architects, IT, and application teams, this role embeds security into application, cloud, data, infrastructure, and platform designs early in the lifecycle while also ensuring those designs are implemented, maintained, and optimized in practice. The position plays a critical role in shaping Lovesac’s security posture by standardizing controls, reducing architectural and operational risk, and enabling consistent, defensible security decisions across the enterprise. This role ensures information security platforms are reliable, well-integrated, and aligned with approved designs, while helping Lovesac scale securely through a combination of strong architecture, disciplined engineering, and continuous improvement.
What You’ll Do
Security Architecture Strategy, Design, and Engineering
Define and evolve the enterprise security architecture vision and roadmap. Establish security architecture principles aligned with Zero Trust and industry frameworks. Create and maintain security reference architectures, design patterns, and implementation standards. Design and engineer security capabilities that support business growth, cloud adoption, and omnichannel operations. Evaluate emerging technologies and recommend secure, operationally viable architectural approaches. Provide architectural and engineering input into security platform selection, capability development, and modernization efforts.
Security Platform Engineering and Operations
Engineer, configure, maintain, and optimize information security-owned platforms, including SIEM, SOAR, EDR, vulnerability management, EntraID, Data Loss Prevention, network security, AI security, and related security tools. Perform routine platform administration, upgrades, health monitoring, and maintenance activities. Ensure security platforms are properly configured, tuned, and operating in alignment with approved architectures and standards. Troubleshoot platform issues and partner with vendors and internal teams to resolve incidents and service gaps. Maintain configuration standards, technical documentation, and operational runbooks. Support capacity planning, performance optimization, and long-term platform modernization initiatives.
Enterprise Solution Architecture and Integration Support
Participate in enterprise architecture and solution design reviews for both cyber and non-cyber platforms. Advise on secure design for applications, cloud services, data platforms, network-connected systems, and enterprise integrations. Implement and maintain integrations between security platforms and enterprise systems. Document data flows, trust boundaries, integration patterns, and security control placements. Work with solution and application architects to balance security, usability, scalability, and operational effectiveness. Ensure security requirements are clearly articulated, technically feasible, and consistently applied across projects.
Automation, Detection, and Operational Enablement
Support automation and orchestration efforts to improve detection, response, and operational efficiency. Assist with data ingestion, normalization, enrichment, and platform connectivity across security tooling. Provide engineering support for Information Security department, including onboarding new detection use cases and response workflows. Support incident response by ensuring platform data, integrations, and tooling are available and reliable. Partner with threat intelligence, identity, ITSM, and incident response teams to operationalize new requirements. Contribute to reducing manual effort through scripting, workflow integration, and response automation.
Architecture Governance, Continuous Improvement, and Collaboration
Develop and maintain security architecture standards, guidelines, and approved implementation patterns. Support governance processes, including design reviews, exception handling, and technical evidence for audits and assessments. Ensure architecture and engineering decisions align with internal policies and external regulatory requirements. Identify architectural gaps, operational inefficiencies, technical debt, and improvement opportunities. Partner closely with Enterprise Architects, Information Security team members, and other IT teams to align roadmaps and delivery priorities. Continuously refine standards, platforms, and engineering practices based on threat evolution, business change, and operational lessons learned. QualificationsWho You Are
A senior security professional who is equally comfortable designing architecture and building or maintaining platforms. Comfortable influencing without authority and operating in a matrixed, cross-functional environment. Able to translate complex security concepts into clear architectural guidance and practical engineering outcomes. Detail-oriented, with strong documentation, design communication, and operational discipline. Able to troubleshoot complex systems, assess risk thoughtfully, and work through issues methodically. Passionate about building secure, scalable, reliable systems that enable the business.
Core Values: Top Ambition, We All Win Together, Conscious Operations, Do Less and Do Best, Love Matters
Table-Stake Values: Willing to Sweep Floors, Grit, Positive, Self-Aware, Self-Starting, Insatiable Learners, Transparency, Customer-Centric
Our Lovesac Core Competencies: Builds Customer Centricity, Drives Remark-able Results, Collaborates Effectively, Makes Good Decisions, Demonstrates Self-Awareness
Requirements
Bachelor’s degree in information security, Computer Science, or related discipline (or equivalent experience) required. CISSP, CISM, Security+, GCED, GCIH, or equivalent security certification; cloud, networking, or vendor-specific platform certifications required. 5-8 years of experience in security engineering or security operations roles. Demonstrated experience designing and implementing security architectures for cloud, SaaS, enterprise, and distributed environments and hands-on experience administering security platforms such as SIEM, EDR, and vulnerability management tools. Experience participating in or leading architecture and design review processes. Strong background collaborating with enterprise architecture, IT, application, and security operations teams. Experience supporting SOC operations and incident response tooling. Familiarity with cloud and SaaS-based security platforms. Familiarity with network operations and network security platforms. Experience operating in an enterprise or distributed environment preferred.
Solid understanding of security architecture concepts, including Zero Trust, defense-in-depth, and secure-by-design. Working knowledge of security monitoring, endpoint protection, and vulnerability management. Experience with platform integration and API-based data ingestion. Familiarity with automation and scripting (e.g., PowerShell, Python). Ability to develop and implement approved architectural designs. Experience operating in an enterprise or distributed environment preferred. Ability to assess architectural risk and recommend appropriate controls. Familiarity with security and privacy frameworks such as NIST CSF, ISO, HIPAA, GDPR, CCPA, COBIT, etc. Exemplify each of our Lovesac values, at all times, be results driven and utilize knowledge to meet or exceed key performance indicators (KPIs), goals and deadlines. Must be able to travel using various forms of transportation, as required by the Company in its sole discretion, for mandatory meetings and conferences held either at our offices or offsite (i.e. quarterly team connection weeks, companywide meetings and events, vendor visits). Must comply with all policies and procedures outlined in the Lovesac Employee Handbook and work collaboratively with fellow employees, treating all clients, both internal and external with dignity and respect at all times.
Preferred Attributes:
Experience working with managed security service providers Strong troubleshooting and operational problem-solving skills Comfort working in an execution-driven role with defined priorities
Full Time Benefits*
Financial Benefits: Annual Bonus Program, Inaugural Grant Equity Awards, 401K Matching Contribution, Financial Wellness Tools. Health and Wellness Benefits: Medical, Dental, Vision, Health Savings and Flexible Spending Accounts, Paid Parental Leave, Life/AD&D, Short Term and Long-Term Disability, Critical Illness and Accident Insurance, Employee Assistance Program. Paid Time Off: Up to 160 hours of paid time off within our fiscal calendar year, prorated from date of hire, 8 paid company recognized holidays. Pet Insurance and generous Associate Discounts.
*Eligibility and terms for all benefits listed are as outlined in Lovesac’s policy and plan documents.
Associate pay will vary based on factors such as qualifications, experience, skill level and competencies.
Lovesac is an Equal Opportunity Employer and considers all applicants for employment without regard to race, color, religious creed, ancestry, national origin, ethnicity, religion, sex, sexual orientation, gender (including gender-related identity, gender nonconformity, or status as a transgender or transsexual individual), pregnancy, age, national origin, marital status, physical or mental disability, military status, genetic information or any other characteristic protected by applicable law.
Non-New York City Applicants Only: To the extent permitted by law, conditional offers of employment will be contingent upon successful completion of a background check, including but not limited to education verification, employment history verification, reference checks, criminal history and motor vehicle history (if vehicle required). All qualified applicants with criminal histories will be considered in accordance with applicable local, state, and federal law.
Lovesac participates in E-Verify as required by law. Immigration sponsorship is not available for this role.
Lovesac is committed to the principles of equal employment opportunity and providing reasonable accommodations to candidates and employees with disabilities, protected medical conditions, and religious beliefs. If you need an accommodation during the application or interview process, please reach out to us at: accommodations@lovesac.com.