368,530open jobs
9,432companies
50,439added this week
Browse all
Salary
$179k – $205k per year
Location
In office (Nashville)
Seniority
Architect · 7+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Creative Artists Agency (CAA) is a global talent and sports agency headquartered in Los Angeles, California, and founded in 1975. The company provides representation and business development services for professionals in film, television, music, sports, gaming, and digital media, while also offering brand consulting and investment banking through its various divisions. It operates through numerous international offices across North America, Europe, and Asia, serving a diverse roster of high-profile clients and corporate brands.

Job Description

Who We Are

Creative Artists Agency (CAA) is the leading entertainment and sports agency, with global expertise in filmed and live entertainment, digital media, publishing, sponsorship sales and endorsements, media finance, consumer investing, fashion, trademark licensing, and philanthropy. Distinguished by its culture of collaboration and exceptional client service, CAA’s diverse workforce identifies, innovates, and amplifies opportunities for the people and organizations that shape culture and inspire the world. The trailblazer of the agency business, CAA was the first to build a sports business, create an investment bank, launch a venture fund, found technology start-up companies, establish a philanthropic arm, build a business in China, and form a brand marketing services division, among other innovations. Named Most Valuable Sports Agency by Forbes for eight consecutive years, CAA represents more than 2,000 of the world’s top athletes in football, baseball, basketball, hockey, soccer, in addition to coaches, on-air broadcasters, and sports personalities and works in the areas of broadcast rights, corporate marketing initiatives, social impact, and sports properties for sales and sponsorship opportunities. Founded in 1975, CAA is headquartered in Los Angeles, and has offices in New York, Nashville, Memphis, Chicago, Miami, London, Munich, Geneva, Stockholm, Shanghai, and Beijing, among other locations globally.

The Role

  • We are seeking a strategic and hands-on Cybersecurity Architect to join our Purple Team, responsible for designing, validating, and continuously evolving enterprise security architecture in alignment with real-world adversarial threats. This role operates at the intersection of offensive and defensive security, leveraging Red Team insights and Blue Team capabilities to ensure systems are secure by design, resilient by default, and continuously tested against emerging attack techniques.

  • As a key leader in our security organization, the Cybersecurity Architect will drive the development of secure design principles, reference architectures, and security standards across a modern, SaaS-enabled and cloud-first ecosystem. This includes securing complex identity flows, third-party integrations, APIs, and distributed systems while addressing the shared responsibility model inherent in SaaS platforms.

  • The ideal candidate brings a deep understanding of attacker methodologies and defensive controls, applying that knowledge to proactively identify architectural weaknesses, reduce attack surface, and enhance detection and response capabilities. This individual will work closely with engineering, cloud, and product teams to embed security into the software development lifecycle, ensuring that security is not an afterthought but a foundational component of system design.

  • This role requires a balance of technical depth and strategic influence, with responsibility for translating complex threats into actionable architectural improvements and guiding the organization toward Zero Trust and secure-by-design maturity. Success in this position will be measured by the organization’s ability to prevent, detect, and respond to sophisticated threats, as well as by the strength and scalability of its security architecture across both enterprise and SaaS environments.

Responsibilities

  • Design and evolve enterprise security architecture with a strong emphasis on secure-by-design principles, ensuring security is embedded early in system and application lifecycles

  • Lead the development and adoption of secure design patterns and reference architectures, particularly for cloud-native and SaaS-based environments

  • Act as a key liaison between Red Team and Blue Team, translating adversarial findings into architectural improvements, detection use cases, and resilient system designs

  • Plan and execute Purple Team exercises to validate security controls across infrastructure, applications, and SaaS platforms, ensuring visibility and response capabilities are effective

  • Develop and maintain threat models for critical systems, including SaaS integrations, APIs, and identity flows, identifying attack paths and prioritizing mitigations

  • Define and enforce security architecture standards for SaaS adoption

  • Assess and secure SaaS ecosystems, including third-party integrations, OAuth applications, and API exposure risks

  • Evaluate and recommend controls for modern architectures, including Zero Trust, microservices, containers, and serverless environments

  • Drive improvements in detection engineering by mapping adversary TTPs (e.g., via MITRE ATT&CK) to logging, alerting, and response capabilities

  • Collaborate with cloud and platform teams to ensure secure configuration and continuous compliance across SaaS and IaaS environments

  • Conduct architecture risk assessments and provide actionable remediation strategies aligned with business risk tolerance

  • Promote security observability across SaaS platforms by ensuring proper logging, telemetry, and integration with SIEM/SOAR solutions

  • Mentor engineers and architects on secure design principles, SaaS security risks, and adversarial thinking

Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, or related experience

  • 7+ years of experience in cybersecurity, with at least 2-3 years in architecture or senior engineering roles

  • Hands on experience in Cyber Threat and Offensive Security operations to test and validate the effective operation of security controls, measuring the ability to stop threats and attacks at the earliest point in the kill chain

  • Strong knowledge of network security, cloud security (AWS/Azure/GCP), and enterprise architectures

  • Strong understanding of the fundamental operations of servers, operating systems, networks, cloud applications and infrastructure along with an advanced understanding of the key controls required for secure operation of these systems

  • Experience scripting in at least one of the following languages: PowerShell, Python, JavaScript

  • Experience in aligning threat and vulnerability management efforts to frameworks and control objectives - MITRE ATT&CK, NIST CSF, ISO27001, Center for Internet Security, OWASP,

  • Experience integrating the following tools and capabilities into a successful threat and vulnerability program - Security Orchestration Automation and Response, Security Information and Event Management, Vulnerability Scanning, Security Threat Feeds, Red Team Tooling

  • Knowledge of Zero Trust architecture and modern identity security practices

Location

This role is hybrid, based in our Nashville office.

Compensation

The annual base salary for this position is in the range of $179,000 - $205,000 in Nashville. This position is also eligible for benefits and a discretionary bonus. Ultimately, the salary may vary based upon, but not limited to, relevant experience, time in the role, business sector, and geographic location, among other criteria. Please talk with a CAA Recruiter to learn more.

Creative Artists Agency, LLC (the “Company”) is committed to a policy of Equal Employment Opportunity and will not discriminate on the basis of race (inclusive of traits historically associated with race, including hair texture and protective hairstyles), color, religion, creed, gender or sex (including pregnancy, childbirth, breastfeeding or related medical conditions), national origin, ancestry, age, physical disability, mental disability, medical condition, genetic information, family and medical care leave status, military or veteran status, marital status, family status, sexual orientation, gender identity, gender expression, political affiliation, an employee’s or their dependent’s reproductive health decision making (e.g., the decision to use or access a particular drug, device or medical service), or any other characteristic protected by applicable law.The absence of a permanent address is not a bar to employment. The Company does not discriminate against individuals based on housing status, including the absence of a fixed address.The Company also complies with the Americans with Disabilities Act and applicable state and local laws with regard to providing reasonable accommodation for qualified individuals with disabilities.CAA does not accept unsolicited resumes from third-party recruiters unless they were contractually engaged by CAA to provide candidates for a specified opening. Any such employment agency, person or entity that submits an unsolicited resume does so with the acknowledgement and agreement that CAA will have the right to hire that applicant at its discretion without any fee owed to the submitting employment agency, person or entity.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,530 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Nashville
$220k – $325k per year • Remote/Hybrid • Full-Time • 15+ years exp • New York
DevOps
AWS
Azure
CI/CD
GCP
Kubernetes
Platform Engineering
Cybersecurity
Threat Modeling
Apply
Remote/Hybrid • 7+ years exp • Bachelor's Degree
C#
JavaScript
Python
SQL
TypeScript
C#
ASP.NET Core
Blazor
Dapper
Databases
Oracle
Frontend
Angular
Bootstrap
JQuery
Vue.js
DevOps
AWS
Azure
Azure DevOps
CI/CD
Git
Apply
In office • Contractor • Dublin
DevOps
Azure
Cybersecurity
Okta
Management
Google Workspace
Jira
Slack
Apply
$21k – $57k per year (Estimated) • Remote/Hybrid • Full-Time • 6+ years exp • Bachelor's Degree • Noida
C#
SQL
TypeScript
JavaScript
C#
.NET
Frontend
Angular
DevOps
Azure
Azure DevOps
CI/CD
Git
TeamCity
Apply
$16k – $42k per year (Estimated) • Remote/Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Noida
C#
SQL
TypeScript
JavaScript
C#
.NET
Frontend
Angular
DevOps
Azure
Azure DevOps
CI/CD
Git
TeamCity
Apply
Insights Analyst 7 days ago
$73k – $87k per year • In office • Full-Time • 2+ years exp • Bachelor's Degree • Los Angeles
Analytics
Tableau
Apply
$93k – $115k per year • In office • Full-Time • 6+ years exp • Bachelor's Degree • New York
Apply
$71k – $90k per year • In office • Full-Time • 4+ years exp • Los Angeles • New York
Design
Adobe After Effects
Adobe Photoshop
Figma
Apply
$121k – $135k per year • In office • Full-Time • 6+ years exp • Bachelor's Degree • Nashville
PowerShell
Python
DevOps
AWS
Azure
GCP
Cybersecurity
Crowdstrike
FedRAMP
GDPR
ISO 27001
PCI DSS
Management
ServiceNow
Apply
$155k – $177k per year • In office • Full-Time • 6+ years exp • Bachelor's Degree • Nashville
JavaScript
Node JS
Ruby
TypeScript
Python
Ruby
Ruby on Rails
Python
Django
Databases
MySQL
PostgreSQL
Frontend
Angular
Bootstrap
React.js
Tailwind CSS
Vue.js
DevOps
AWS
Azure
GCP
Git
QA
Cypress
Jest
Apply
$70k – $206k per year • In office • Full-Time • 12+ years exp • Associate's Degree • Chicago • Milwaukee • Dallas • Columbus • Kirkland
AI/ML
AI Agents
Apply
$94k – $294k per year • In office • Full-Time • 12+ years exp • Associate's Degree • Chicago • Portland • Milwaukee • Dallas • Columbus
Apply
$70k – $206k per year • In office • Full-Time • 12+ years exp • Associate's Degree • Chicago • Milwaukee • Dallas • Columbus • Kirkland
AI/ML
AI Agents
Apply
$143k – $258k per year (Estimated) • Remote/Hybrid • Full-Time • 12+ years exp • Associate's Degree • Chicago • Milwaukee • Dallas • Columbus • Kirkland
JavaScript
Python
TypeScript
Python
pySpark
AI/ML
Prompt Engineering
Spark
DevOps
AWS
Azure
CI/CD
GCP
Git
Jenkins
GitHub
GitLab
Analytics
ETL/ELT
Apply
$163k – $434k per year • Remote/Hybrid • Full-Time • 12+ years exp • Associate's Degree • Chicago • Milwaukee • Dallas • Columbus • Kirkland
JavaScript
Python
TypeScript
Python
pySpark
AI/ML
Prompt Engineering
Spark
DevOps
AWS
Azure
CI/CD
GCP
Git
Jenkins
GitHub
GitLab
Analytics
ETL/ELT
Apply
See all jobs
This is one of many
368,530 more open roles from verified company boards, updated every day.