Responsibilities:
- Define reusable security architecture patterns and guardrails for consistent secure implementation.
- Drive secure-by-design by integrating security early in the software architecture lifecycle and influencing enterprise architecture direction.
- Represent security architecture in design authority boards and technical review councils, advocating risk-based controls.
- Collaborate with IT customers (application architects/engineers) to evaluate designs and define application controls aligned with enterprise standards.
- Define application-specific security control architectures and produce design artifacts for business-critical systems.
- Develop reusable implementation guidance and design patterns to scale.
- Partner with security leadership to enforce security requirements and address infrastructure/application risks.
- Serve as a security architecture liaison to IT delivery and engineering teams, embedding security into technical delivery and architecture reviews.
- Support business & IT initiatives across architecture, design, implementation, deployment, and operational transition.
- Research/evaluate/test/recommend new or updated security technologies.
- Advise in application development or acquisition projects to ensure security requirements/controls are implemented; drive remediation and gap closure.
- Identify threats via application threat modeling and propose mitigations.
Qualifications (Required):
- Bachelorโs + 9 years OR Masterโs + 8 years OR PhD + 4 years in information security/related (IT Audit, Risk Mgmt, Security Architecture).
- Strong ability to assess/communicate security concepts to business and IT stakeholders.
- In-depth SDLC knowledge and application security (OWASP Top 10, SANS/CWE Top 25, secure coding).
- Expertise: secure session management, token handling, authentication (OAuth, SAML, OpenID Connect).
- Knowledge of cryptography, encryption protocols, and PKI.
- Experience with Docker/Kubernetes and AWS/Azure/GCP.
- Familiarity with code analysis and vulnerability scanning tools (e.g., SonarQube, Veracode, Burp Suite, Nessus).
- Understanding of DevSecOps and CI/CD pipeline security.
- Self-starter; strong problem-solving/analytical skills.
- Cross-functional influence and collaboration.
- Cloud/security concepts: virtualization, microservices, serverless, IAM, network security, auditing, secrets management, data protection, container/Kubernetes security, securing CI/CD.
- Identity security: least privilege, separation of duties, Zero Trust.
- Federation/encryption technologies and standards; security architecture plans/documentation (strategic/tactical/project).
- Significant SOX and HIPAA experience with ITGC (audit/remediation/validation).
- Strong knowledge of ISO/NIST and security/architecture trends; excellent communication/influencing skills.