The primary purpose of this position is to assist with developing secure architectures for new and existing projects. The role requires solid foundations in secure architecture, secure software development, application security, and application security frameworks.
- Builds relationships with development teams to understand product, business, and security needs.
- Collaborates with development teams to design secure solutions and security features.
- Develops standard secure architecture models that Implement Secure by Design and Default.
- Assists with threat modeling.
- Conducts security architecture and design reviews.
- Creates short- and long-term roadmaps to address identified application security opportunities.
- Assists with audits pertaining to security and works with development teams to ensure compliance to industry security frameworks and regulatory requirements.
- Stays current on threat landscapes, industry best practices, and regulatory requirements, and integrates into secure architecture designs.
Education Requirements
Education Level
Bachelor Degree **
Area of Specialization (Marketing, Finance, Pharmacy, Engineering/IT, etc)**
Information Security or Software Development.
Additional years of relevant experience, training, and/or professional certifications will qualify in lieu of a degree. **
Knowledge, Skills And Abilities**
Knowledge, Skills and Abilities
Familiarity with OWASP, CAPEC, CWE, CVE, ATT&CK, NIST, ISO/IEC 27034, or equivalent frameworks.
Experience with the OWASP Top 10 and the CWE Top 25.
Extensive experience designing architectures for cloud, web, mobile, thick-client, API, and database applications.
Experience with Application Security and knowledge of Software Development Lifecycles/Processes
Experience with common developer technologies (Azure DevOps, Git, Confluence, Jira, etc.)
Cloud application security knowledge and experience with GCP, AWS, and Azure.
Proven capacity for thinking leadership and problem solving.
Excellent analytical and interpersonal skills.
Ability to write and verbally communicate effectively to express technical information clearly to both technical and non-technical audiences. **
Experience**
WORK EXPERIENCE
Areas Of Experience (Pharmacy, Compliance, E-commerce, Retail, Etc)
7 years of experience in Security engineering and architecture roles
5 years of experience in Performing threat modeling, security and vulnerability assessments, and security architecture risk reviews
7 years of experience in Information Security or Software Development
The salary range for this position will likely be in the $132-150k range.