Architecture & Solution Design
Develop enterprise-wide security architectures aligned to NIST standards (e.g., NIST CSF, SP 800-53, SP 800-171, SP 800-207).
Design scalable, secure solutions that address identified risks and business objectives across cloud, on-premises, and hybrid environments.
Translate business and technical requirements into secure solution blueprints.
Contribute to the development of reference architectures and security patterns.
Leverage hands on engineering implementation experience to provide prescriptive guidance on best practices and possible pitfalls.
Solution Review & Risk Mitigation
Lead architecture and security reviews for new technologies, applications, and systems.
Identify gaps and weaknesses in proposed solutions and advise on appropriate risk mitigation strategies.
Collaborate with engineering and infrastructure teams to ensure secure deployment of systems and services.
Provide technical guidance to project and product teams throughout the system development lifecycle.
Governance & Standards
Develop and maintain security architecture standards, policies, and control frameworks in alignment with NIST and industry best practices.
Participate in or lead internal security governance boards and architecture review boards.
Ensure solutions meet internal risk, compliance, and regulatory requirements (e.g., CCPA, NYDFS, PCI DSS).
Contribute to maturity assessments and continuous improvement efforts for cybersecurity architecture.
Collaboration & Leadership
Act as a subject matter expert on cybersecurity architecture for stakeholders across IT, engineering, compliance, and risk teams.
Mentor junior architects and security engineers.
Communicate complex technical and risk concepts clearly to business leaders and non-technical audiences.
Stay up to date on emerging threats, technologies, and changes to the NIST ecosystem.
Required Qualifications
7–10 years of experience in cybersecurity, with 3+ years in a security architecture or similar role.
Deep working knowledge of NIST frameworks (CSF, SP 800-53, 800-171, 800-207 Zero Trust).
Demonstrated experience designing and reviewing secure architectures for enterprise systems and cloud environments (e.g., AWS, Azure).
Practical experience translating security architecture requirements into implemented controls, technical configurations, and operational procedures.
Strong understanding of cybersecurity domains including identity and access management (IAM), network security, data protection, and application security.
Strong understanding of LLMs, AI, and GenAI solutions including agentic AI and MCP hardening.
Experience validating control effectiveness through testing, monitoring, evidence collection, or audit support.
Experience working in a regulated environment and aligning technical controls to compliance frameworks. Excellent communication, collaboration, and documentation skills.
Preferred
Industry certifications such as CISSP, CISM, CISA, SABSA, or AWS Certified Security.
Experience with Zero Trust Architecture and modern security models.
Experience with security automation, control orchestration, policy-as-code, or continuous control monitoring.
Experience implementing security controls in cloud-native, hybrid, and complex enterprise-scale environments.
Familiarity with DevSecOps and infrastructure-as-code security.
OneMain Holdings, Inc. is an Equal Employment Opportunity (EEO) employer. Qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship status, color, creed, culture, disability, ethnicity, gender, gender identity or expression, genetic information or history, marital status, military status, national origin, nationality, pregnancy, race, religion, sex, sexual orientation, socioeconomic status, transgender or on any other basis protected by law.
Skills Required
- 7-10 years of experience in cybersecurity, with 3+ years in a security architecture or similar role
- Deep working knowledge of NIST frameworks (CSF, SP 800-53, SP 800-171, SP 800-207)
- Experience designing and reviewing secure architectures for enterprise systems and cloud environments (e.g., AWS, Azure)
- Practical experience translating security architecture requirements into implemented controls, technical configurations, and operational procedures
- Strong understanding of IAM, network security, data protection, and application security
- Strong understanding of LLMs, AI, and GenAI solutions including agentic AI and MCP hardening
- Experience validating control effectiveness through testing, monitoring, evidence collection, or audit support
- Experience working in a regulated environment and aligning technical controls to compliance frameworks
- Excellent communication, collaboration, and documentation skills
- Industry certifications such as CISSP, CISM, CISA, SABSA, or AWS Certified Security
- Experience with Zero Trust Architecture and modern security models
- Experience with security automation, control orchestration, policy-as-code, or continuous control monitoring
- Experience implementing security controls in cloud-native, hybrid, and complex enterprise-scale environments
- Familiarity with DevSecOps and infrastructure-as-code security
OneMain Financial Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about OneMain Financial and has not been reviewed or approved by OneMain Financial.
-
Retirement Support — Retirement benefits include a 401(k) with a dollar-for-dollar match up to 4% after six months, supporting long-term savings. An employee stock purchase plan with a 10% discount adds another ownership-oriented reward element.
-
Leave & Time Off Breadth — Time-off offerings include vacation that can grow to five weeks, paid holidays, personal days, sick time, and three paid volunteer days. Paid parental leave is offered at 100% pay for six weeks, adding to the overall leave mix.
-
Flexible Benefits — A broad menu of benefits spans HSAs/FSAs, disability coverage, life and long-term care solutions, tuition reimbursement, and voluntary options like pet insurance and legal assistance. Backup child/elder care and adoption assistance further widen the set of selectable supports.
OneMain Financial Insights
What We Do
OneMain provides personal loans with one on one, local service at branches nationwide. Our personalized loan solutions offer customers a simple and straightforward loan application, fixed rates, fixed payments, clear terms and multiple payment options.







