Responsibilities:
- Define reusable security architecture patterns and guardrails; drive secure-by-design early in the software architecture lifecycle.
- Represent security architecture in design authority/technical review forums; advocate risk-based security controls.
- Evaluate application software/infrastructure designs and define application controls aligned to enterprise standards.
- Produce security control architectures and design artifacts for business-critical systems; create reusable guidance/patterns.
- Collaborate with IT delivery/engineering to embed security into technical forums and SDLC.
- Support business & IT initiatives across architecture, design, implementation, deployment, and operational transition.
- Research and recommend new/updated security technologies; assess threats and recommend remedial actions.
- Advise application development/acquisition projects; ensure controls are implemented and remediation/compliance gaps are addressed.
- Foster security culture via education and improved security processes; ensure alignment with policies (e.g., code of conduct, GxP, data security, SDLC).
- Lead application threat modeling and propose design changes; integrate security with DevOps/operations.
Required:
- Bachelorโs (9 yrs) or Masterโs (8 yrs) or PhD (4 yrs) in information security or related (IT Audit, Risk Mgmt, Security Architecture).
- Strong application security knowledge (OWASP Top 10, SANS/CWE Top 25) and secure coding.
- Expertise: secure session management, token handling, authentication (OAuth, SAML, OpenID Connect); crypto/encryption/PKI.
- Experience with Docker/Kubernetes and AWS/Azure/GCP; code analysis/vuln scanning tools (e.g., SonarQube, Veracode, Burp Suite, Nessus).
- DevSecOps/secure CI/CD; self-starter; analytical/problem-solving; cross-functional influence.
- Cloud/identity security, least privilege/Zero Trust; federation and encryption technologies.
- Security architecture documentation; SOX/HIPAA ITGC experience.