Responsibilities:
- Define reusable security architecture patterns and guardrails for high-risk business applications.
- Drive secure-by-design by integrating security early in the software architecture lifecycle and influencing enterprise architecture direction.
- Represent security architecture in design authority boards and technical review councils with risk-based controls.
- Partner with IT customers to evaluate application software/infrastructure designs and define application controls aligned with enterprise standards.
- Define application-specific security control architectures and create design artifacts for secure implementation of business-critical systems.
- Develop reusable implementation guidance and design patterns to scale secure delivery.
- Work with security leadership to enforce security requirements and address risks across infrastructure and applications.
- Liaison with IT delivery/engineering teams to embed security principles into technical delivery and architecture review forums.
- Support business & IT initiatives across architecture, design, implementation, deployment, and operational transition.
- Research, evaluate, design, test, and recommend implementation of new/updated information security technologies.
- Advise in application development or acquisition projects to assess requirements/controls and ensure planned implementation; drive remediation and compliance gap closure.
- Research and assess new information security threats and recommend remedial actions.
- Foster an information security culture through education and effective processes/practices.
- Adhere to applicable policies (e.g., code of conduct, GxP compliance, data security, SDLC).
- Design application security architecture to meet best practices and regulatory compliance.
- Integrate security into SDLC with software development, DevOps, and operations.
- Lead application threat modeling and propose design changes to mitigate threats.
Qualifications:
Required:
- Bachelorโs + 9 years OR Masterโs + 8 years OR PhD + 4 years in information security or related (IT Audit, Risk Management, Security Architecture).
- Exceptional ability to assess/communicate security concepts with business and IT stakeholders.
- In-depth knowledge of SDLC and application development technologies.
- Strong application security knowledge (OWASP Top 10, SANS/CWE Top 25) and secure coding.
- Expertise in secure session management, token handling, and auth mechanisms (OAuth, SAML, OpenID Connect).
- Knowledge of cryptography, encryption protocols, and PKI.
- Experience with Docker/Kubernetes and cloud platforms (AWS, Azure, GCP).
- Familiarity with code analysis (SonarQube, Veracode) and vulnerability scanning (Burp Suite, Nessus).
- Understanding of DevSecOps and CI/CD pipeline security.
- Self-starter; strong problem-solving/analytics; cross-functional collaboration and influence.
- Cloud principles and risk/security coverage (IAM, network, auditing, encryption, secrets, CI/CD).
- Identity security (least-privilege, separation of duties, Zero Trust) and federation/encryption technologies.
- Experience developing/documenting security architecture and plans (strategic/tactical/project).
- Significant SOX and HIPAA experience with IT general controls (ITGC) via audit/remediation/validation.
- Knowledge of security frameworks and practices (e.g., ISO, NIST).
- Strong communications/influencing skills and mentoring ability.