← Все вакансии/Senior/jobgether
SeniorRemoteUS

Information Security Architect

J
jobgether
Уровень
Senior
Формат
Remote
О роли

Описание вакансии

About the company

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Information Security Architect based in United States.

Responsibilities
  • Establish and enforce secure software development standards, cloud security practices, and architectural security guidelines across enterprise technology environments.
  • Lead the security lifecycle for applications and technologies by evaluating emerging technologies, evolving threats, industry trends, and end-of-life governance requirements.
  • Contribute to and mature the Architectural Review Board by applying security-focused principles to architecture reviews across all IT domains.
  • Review application architecture documentation, diagrams, technical designs, and operational runbooks to identify security risks and opportunities for improvement.
  • Partner with engineering and DevOps teams to integrate security governance, controls, and best practices into CI/CD pipelines and development workflows.
  • Conduct architecture risk assessments, threat modeling exercises, and secure design reviews for new and existing applications.
  • Develop security reference architectures, reusable design patterns, technical standards, and best practices for cloud-native and enterprise applications.
  • Lead application security initiatives covering SAST, DAST, software composition analysis, Infrastructure as Code scanning, container security, and API security.
  • Work closely with enterprise architecture leadership to ensure security architecture, governance, and technical guidance are consistently implemented across IT domains.
  • Assess cloud services, platforms, and third-party technologies for security risks, architectural weaknesses, and compliance requirements.
  • Collaborate with security operations, infrastructure, compliance, engineering, networking, cloud, and data teams to investigate and remediate security findings.
  • Serve as a trusted security advisor to technical teams, helping them design resilient applications and infrastructure that meet business, security, and regulatory requirements.
  • Ensure cloud-based applications and systems align with relevant security policies and regulatory frameworks, including PCI DSS, HIPAA, SOC 2, ISO 27001, NIST, and GDPR.
  • Provide technical leadership, guidance, and mentorship to development and engineering teams on secure coding, cloud security, and application security practices.
  • Contribute to additional security architecture, governance, and technology initiatives as required by the organization.
Requirements
  • Bachelor’s degree in Computer Science, Business, Information Technology, or a related discipline, or equivalent professional experience.
  • 7+ years of experience securing enterprise environments across on-premises, hybrid, and cloud infrastructures.
  • Strong knowledge of secure software development lifecycles and DevSecOps methodologies, with the ability to embed security throughout development and delivery processes.
  • Strong understanding of secure coding principles and common application vulnerabilities, including the OWASP Top 10 and API Security Top 10.
  • Hands-on experience with Azure DevOps, particularly CI/CD pipelines and Git repositories, with an understanding of how to integrate security controls into development workflows.
  • Strong knowledge of identity and access management, authentication, authorization, OAuth, OpenID Connect, SAML, risk management, and Zero Trust principles.
  • Familiarity with security technologies and platforms including SIEM, EDR/XDR, IAM, PAM, CASB, DLP, and vulnerability management solutions.
  • Strong expertise in cloud security architecture and modern cloud platforms such as AWS and Azure.
  • Knowledge of platform architecture, software development practices, cloud well-architected frameworks, application security, and enterprise security architecture.
  • Ability to translate business requirements, security policies, regulatory obligations, and risk findings into practical and effective technical architecture guidance.
  • Strong analytical and problem-solving skills, with the ability to investigate complex technical challenges and develop scalable security solutions.
  • Excellent communication and collaboration skills, with the ability to build relationships and influence stakeholders across multiple technical and business teams.
  • Strong organizational and time-management abilities, including the capacity to manage multiple business-critical initiatives simultaneously.
  • Understanding of security and compliance requirements within highly regulated environments; experience in healthcare is a plus.
  • CISSP certification is preferred.
Conditions
  • Competitive compensation aligned with the scope and seniority of the Information Security Architect role.
  • Opportunity to influence enterprise-wide security architecture, governance, and technology strategy.
  • Work with m
Стек и навыки

С чем работаем