Security Architect
Own and evolve security architecture across cloud infrastructure, applications, and APIs while working hands-on with engineers to remediate vulnerabilities and embed secure development practices. The role also leads audits, customer security reviews, regulatory controls, and incident readiness, with a path to manage a growing security team.
About the job
Responsibilities
- Own end-to-end security architecture across cloud infrastructure, applications, and APIs.
- Identify, prioritize, remediate, and validate security issues with engineering teams.
- Perform threat modeling and security design reviews; embed secure coding, code review, CI/CD, dependency, and container security controls.
- Define security standards, reference architectures, and hardening baselines, and drive adoption.
- Lead penetration testing, vulnerability management, and remediation tracking.
- Translate regulatory and privacy requirements into practical technical and organizational controls.
- Own technical support for SOC 2, ISO 27001, enterprise customer, and regulatory audits, including evidence, control mapping, and remediation.
- Represent security in customer security questionnaires, due-diligence calls, and auditor discussions.
- Partner with privacy and data-protection teams on GDPR and personal and biometric data controls.
- Contribute to incident detection, investigation, response, and post-incident improvement.
- Mentor and eventually manage junior security engineers.
Requirements
- 7–9 years of experience in security engineering, security architecture, or a closely related field.
- Hands-on ability to assess application code, cloud infrastructure, and API design and remediate issues with engineers.
- Strong cloud security expertise, including network segmentation, IAM, secrets and key management, workload and container security, and infrastructure as code.
- Deep application and API security knowledge, including access-control flaws, injection, SSRF, authentication, authorization, secure design patterns, and secure SDLC practices.
- Current understanding of SOC 2, ISO/IEC 27001, GDPR, and related security and privacy frameworks.
- Experience handling certification, enterprise-client, and regulatory audits and driving findings to closure.
- Excellent communication with engineers, executives, auditors, and customers.
- Sound judgment balancing security, business needs, and delivery.
Nice to Have
- Experience in fintech, regtech, identity verification, or another regulated, data-sensitive domain.
- Experience handling personal, biometric, and identity data.
- Background in penetration testing, red teaming, or vulnerability research.
- Familiarity with privacy regulations beyond GDPR and DevSecOps tooling.
- CISSP, CCSP, OSCP, CIPP, CIPT, or similar certifications.
- Experience mentoring or leading engineers and building a team.
Skills
Cloud Security, Network Segmentation, IAM, Secrets Management, Key Management, Container Security, Infrastructure As Code, Api Security, Threat Modeling, Secure Sdlc, Penetration Testing, Vulnerability Management, SOC 2, ISO 27001, GDPR
Similar jobs
Security Engineering jobsLeads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.
Own detection engineering and lead incident response across corporate and production environments, building cloud, endpoint, runtime, and Kubernetes coverage. The role requires 6+ years in security, hands-on detection development, and end-to-end incident leadership.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Own Anyscale’s secure software development lifecycle, partner with engineering on secure architecture and features, and lead vulnerability management and remediation. The role requires 8+ years of product or application security experience and strong hands-on secure-development expertise.
Senior product security engineer responsible for embedding security across the SDLC, building security automation, conducting reviews and penetration testing, and leading vulnerability response. Requires 5+ years of security experience, strong web and mobile security expertise, and hands-on AWS, CI/CD, and security tooling knowledge.