Responsibilities:
- Define reusable security architecture patterns and guardrails for high-risk business applications.
- Drive secure-by-design by integrating security early in the software architecture lifecycle and influencing enterprise architecture direction.
- Represent security architecture in design authority boards/technical review councils and advocate for risk-based security controls.
- Collaborate with IT customers (application architects/engineers) to evaluate designs and define application controls aligned with enterprise standards.
- Define application-specific security control architectures and produce design artifacts for business-critical systems.
- Create reusable implementation guidance/design patterns to scale.
- Partner with information security leadership to enforce security requirements and address risks in infrastructure/applications.
- Act as security architecture liaison to IT delivery/engineering; embed security into delivery and architecture reviews.
- Support security aspects of business & IT initiatives across architecture/design/implementation/deployment/operational transition.
- Research, evaluate, test, recommend, and plan implementation of new/updated information security technologies.
- Advise on application development/acquisition projects; assess security requirements/controls and drive remediation for compliance/security gaps.
- Research and assess new security threats and recommend remedial actions.
- Foster security culture via education/skill development and effective security processes.
- Design application security architecture to meet best practices and regulatory compliance.
- Integrate security into SDLC with software development, DevOps, and operations.
- Lead application threat modeling and propose design changes to mitigate risks.
Qualifications:
Required:
- Bachelorโs + 9 years OR Masterโs + 8 years OR PhD + 4 years in information security or related (IT Audit/Risk Management/Security Architecture).
- Exceptional ability to assess/communicate security concepts with business and IT stakeholders.
- In-depth systems development lifecycle and application development knowledge.
- Strong application security principles (OWASP Top 10, SANS/CWE Top 25) and secure coding.
- Secure session management, token handling, authentication (OAuth, SAML, OpenID Connect).
- Cryptography, encryption protocols, and PKI management.
- Experience with Docker/Kubernetes and cloud (AWS/Azure/GCP).
- Code analysis and vulnerability scanning tools (e.g., SonarQube/Veracode; Burp Suite/Nessus).
- DevSecOps and CI/CD pipeline security.
- Self-starter; manage multiple projects; strong analytical/problem-solving skills.
- Cross-functional influence and collaboration.
- Cloud security knowledge (IAM, network security, auditing, secrets management, data protection, container/Kubernetes/CI/CD security).
- Identity security expertise (least privilege, separation of duties, Zero Trust).
- Federation tech (WS-Fed, OAuth, OpenID, SAML) and encryption standards.
- Experience developing/documenting security architecture plans (strategic/tactical/project).
- Significant SOX/HIPAA experience with IT general controls; hands-on audit/remediation/validation.
- Knowledge of security frameworks (e.g., ISO, NIST) and current security/architecture trends.
Benefits:
- Paid time off (vacation, holidays, sick), medical/dental/vision insurance, 401(k) for eligible employees; long-term incentive program eligibility.
Application instructions:
- Not specified in provided text.