We are seeking a Security Architect to design, evaluate, and strengthen the security posture of the organization's applications, infrastructure, cloud environments, and data ecosystems. This role partners with engineering, infrastructure, and business teams to embed security into solutions from inception through deployment, ensuring that systems are resilient, compliant, and aligned with industry best practices.
Responsibilities
- Conduct end-to-end security architecture reviews for applications, SaaS platforms, and infrastructure projects
- Evaluate proposed designs against established security standards, identify gaps and risks, and recommend practical mitigations
- Partner with project teams early in the design lifecycle to ensure secure-by-design principles are applied
- Perform data risk assessments by analyzing how data flows across systems, where it is stored, and how it is accessed
- Provide architectural guidance on data security tooling such as Databricks security configurations and Varonis for data classification, access auditing, and insider threat monitoring
- Lead security assessments of cloud environments and workloads, evaluating configurations, network segmentation, identity boundaries, logging, and workload protections
- Provide architectural oversight for application security activities including penetration testing, SAST, and DAST
- Assess API security designs including authentication, authorization, rate limiting, and the proper handling of API keys, secrets, and tokens through approved secrets management solutions
- Apply IAM and PAM principles to architectural decisions, ensuring least privilege, separation of duties, and strong authentication patterns
- Champion phishing-resistant MFA approaches across critical systems and provide guidance on MDM and MAM strategies for mobile and endpoint devices
- Evaluate network architectures, segmentation strategies, and perimeter and zero-trust controls, and collaborate on vulnerability remediation
- Serve as a trusted advisor on security architecture matters, document architectural decisions, and maintain reference architectures and security patterns
Requirements
- 2+ years of experience performing security architecture reviews across applications, SaaS solutions, and infrastructure
- Strong background in data security, including data flow analysis, data risk assessments, and tooling such as Databricks and Varonis
- Hands-on knowledge of cloud security assessments and cloud-native security controls
- Solid understanding of API security patterns and management of keys, secrets, and tokens
- Working knowledge of IAM and PAM concepts, including authentication, authorization, privilege management, and identity governance
- Familiarity with phishing-resistant MFA technologies and modern authentication standards
- Knowledge of MDM and MAM platforms and mobile/endpoint security strategies
- Understanding of networking fundamentals (TCP/IP, segmentation, firewalls) and vulnerability remediation practices
- Application security experience, including familiarity with penetration testing, SAST, and DAST tools and processes
- Experience with Cyber Resilience capabilities and Disaster Recovery technologies
- Ability to translate complex security concepts into clear, actionable recommendations for technical and non-technical audiences
- Excellent written and verbal communication skills, with experience producing architecture documents, assessment reports, and design diagrams
- English proficiency at B2 level or higher
Nice to have
- Certifications such as CISSP, CCSP, SABSA, or AWS/Azure/GCP security certifications
- Experience aligning security architecture work to frameworks such as NIST CSF, ISO 27001, CIS, or zero-trust reference models
- Prior experience in regulated environments (e.g., HIPAA, PCI, SOX, GDPR)