Negotiable
Outside
Remote
USA
Summary: The Security Architect role requires a seasoned professional with over 7 years of experience in security engineering or architecture, focusing on secure design, threat modeling, and vulnerability management. The position emphasizes expertise in web application security, secure coding practices, and the design of secure architectures for both on-premises and cloud environments. A strong understanding of authentication mechanisms and encryption technologies is essential, along with familiarity with network protocols and incident response strategies.
Key Responsibilities:
- Conduct secure design reviews and threat modeling.
- Manage vulnerabilities and implement secure coding practices.
- Design secure architectures for on-premises and cloud environments.
- Implement authentication and authorization mechanisms, including multi-factor authentication.
- Utilize encryption technologies and understand network protocols.
- Develop and apply defense-in-depth strategies and incident response plans.
Key Skills:
- 7+ years of experience in security engineering or architecture.
- In-depth knowledge of web application security principles.
- Proficiency in designing secure architectures for AWS and Azure.
- Strong understanding of OAuth and authentication mechanisms.
- Experience with encryption technologies.
- Familiarity with network protocols and defense-in-depth strategies.
- Experience in incident response.
Salary (Rate): undetermined
City: undetermined
Country: USA
Working Arrangements: remote
IR35 Status: outside IR35
Seniority Level: undetermined
Industry: IT
Skill Required:
- 7+ years of experience in a security engineering or architecture role, with a demonstrated focus on secure design reviews, threat modeling, and vulnerability management.
- In-depth knowledge of web application security principles, secure coding practices, and addressing common vulnerabilities (e.g., OWASP Top 10).
- Proficiency in designing secure architectures for on-premises and cloud environments (e.g., AWS, Azure).
- Strong understanding of OAuth, authentication and authorization mechanisms, including multi-factor authentication, single sign-on, and emerging technologies like password-less authentication.
- Experience in encryption technologies, such as certificate-based and token-based cryptography.
- Familiarity with network protocols, topologies, and defense-in-depth strategies.
- Experience with defense-in-depth strategies, understanding of incident response.