Overview
Who we are
Collaborative. Respectful. A place to dream and do. These are just a few words that describe what life is like at Toyota. As one of the world’s most admired brands, Toyota is growing and leading the future of mobility through innovative, high-quality solutions designed to enhance lives and delight those we serve. We’re looking for talented team members who want to Dream. Do. Grow. with us.
An important part of the Toyota family is Toyota Financial Services (TFS), the finance and insurance brand for Toyota and Lexus in North America. While TFS is a separate business entity, it is an essential part of this world-changing company- delivering on Toyota's vision to move people beyond what's possible. At TFS, you will help create best-in-class customer experience in an innovative, collaborative environment.
Toyota does not offer support or sponsorship of job applicants for employment-based visas or any other work authorization for this role now or in the future. You must have the right to work in the United States and not require Toyota support or sponsorship for immigration-related employment (e.g., H-1B, O-1, E-3, H-1B1, TN, F-1 OPT, F-1 STEM OPT, F-1 CPT, TN, ‘job flexibility benefits’ (also known as I-140 or Adjustment of Status portability), etc. now or in the future. You should not apply for this role if you will require Toyota to assist with immigration support or sponsorship now or in the future.
Who we’re looking for
Toyota Financial Services (TFS) Technology is seeking a highly experienced and outcome-driven Lead Security Architect to define, govern, and advance a threat-informed, data-centric security architecture across enterprise platforms and business services.
This role is accountable for embedding Data-Centric Threat Modeling (NIST SP 800-154) into the architecture lifecycle ensuring that security decisions are driven by how data is created, processed, stored, and exposed, rather than relying solely on perimeter or technology-centric controls. The ideal candidate will operate as a senior technical authority, influencing design decisions, enforcing architectural standards, and driving measurable improvements in control effectiveness across TFS environments.
What you’ll be doing
Lead Data-Centric Threat Modeling
Own and operationalize Data-Centric Threat Modeling (NIST SP 800-154) across application, cloud, and enterprise architectures
Identify threats, attack paths, and control gaps based on data flows, sensitivity, and business impact
Integrate threat modeling into solution design, architecture reviews, and delivery pipelines
Drive consistency through standardized methodologies and tooling (e.g., Threat Modeler, IriusRisk)
Define & Enforce Security Architecture
Establish and govern security architecture standards, patterns, and reference models aligned to TFS policy and risk tolerance
Lead architecture design reviews and provide binding security decisions for critical initiatives
Ensure solutions align to Zero Trust principles, least privilege access, and data protection requirements
Drive Risk-Based Decision Making
Translate threat models and architectural assessments into actionable risk insights for executives and stakeholders
Support risk acceptance, exception handling, and architectural trade-offs with clear business impact articulation
Identify control gaps and redundancies across security tooling; recommend optimization and rationalization strategies
Partner Across the Organization
Collaborate with engineering, infrastructure, data, and application teams to embed security early in the development lifecycle
Influence third-party and vendor design reviews using threat-informed architecture criteria, not just checklist-based assessments
Align with risk and compliance teams to ensure regulatory expectations (e.g., financial services controls) are integrated into design
Evaluate Control Effectiveness
Move beyond artifact review (e.g., SOC 2, ISO 27001) to assess real-world control effectiveness against identified threats
Correlate assurance evidence with actual attack scenarios and data exposure risks
Drive continuous improvement in architecture based on evolving threats and control performance
What you bring
Deep expertise in enterprise security architecture across cloud, application, identity (Identity and Access Management), and network domains
Proven experience applying threat modeling methodologies, especially data-centric approaches (NIST SP 800-154)
Hands-on experience with threat modeling tools (e.g., IriusRisk/Threat Modeler, Microsoft Threat Modeling Tool, or equivalents) — strongly preferred
Strong understanding of data protection, data flow analysis, and sensitive data handling within financial services environments
Experience influencing complex, cross-functional architecture decisions at scale
Ability to translate technical threats into business risk and executive-lev
Added bonus if you have
Certified Information Systems & Security Professional (CISSP), Certified Information Security Manager (CISM), or equivalents
What we’ll bring
During your interview process, our team can fill you in on all the details of our industry-leading benefits and career development opportunities.
A few highlights include:
• A work environment built on teamwork, flexibility and respect
• Professional growth and development programs to help advance your career, as well as tuition reimbursement
• Team Member Vehicle Purchase Discount
• Toyota Team Member Lease Vehicle Program (if applicable)
• Comprehensive health care and wellness plans for your entire family
• Toyota 401(k) Savings Plan featuring a company match, as well as an annual retirement contribution from Toyota regardless of whether you contribute
• Paid holidays and paid time off
• Referral services related to prenatal services, adoption, childcare, schools and more
• Tax Advantaged Accounts (Health Savings Account, Health Care FSA, Dependent Care FSA)
• Relocation assistance (if applicable)
Belonging at Toyota
Our success begins and ends with our people. We embrace all perspectives and value unique human experiences. Respect for all is our North Star. Toyota is proud to have 10+ different Business Partnering Groups across 100 different North American chapter locations that support team members’ efforts to dream, do and grow without questioning that they belong.
Applicants for our positions are considered without regard to race, ethnicity, national origin, sex, sexual orientation, gender identity or expression, age, disability, religion, military or veteran status, or any other characteristics protected by law.
Have a question, need assistance with your application or do you require any special accommodations? Please send an email to talent.acquisition@toyota.com.