Senior Architect - Application Cybersecurity
Description
The Senior Architect - Application Cybersecurity helps validate that our services, applications, and websites are designed and implemented in accordance with United’s secure development standards. The Senior Architect works closely with development teams, product teams, and other teams across the organization to integrate security into the product lifecycle from design through deployment.
- Defines security requirements
- Performs application security assessments
- Provides developers with remediation guidance and advice
- Conducts security architecture design reviews and threat modelling of our products (cloud and on-prem)
- Helps research, define, and communicate security best practices and standards
- Ensures products development teams understand them
- Improves the accessibility of security through automation, continuous integration pipelines, and other means
- Performs code analysis of applications, manually and using SAST, DAST, and SCA scanning solutions as well as conducting manual vulnerability analysis
- Technical point of contact for product teams as it relates to automation, CI/CD, and remediation guidance
Qualifications
- Bachelor's degree in STEM or Computer Science
- Minimum of 4 years of experience with any combination of the following: threat modeling, secure coding, identity management and authentication, software development, cryptography, system administration and network security, cloud computing
- Understanding of OWASP Top 10 and CWE 25; Ability to implement and integrate remediation strategies
- Ability to collaborate with development teams to build secure solutions, communicating risks and bringing consensus to diverse priorities
- Knowledge of common vulnerabilities and attack vectors, ubiquitous encryption technologies and common authentication protocols
- Familiarity with application risk assessment, risk categorization, and application security testing tools
- Knowledge of current industry standards, best practices, and reference architectures
- Understanding of secure network and system design in both cloud and conventional environments, as well as of network and web related protocols
- Understanding of web applications, web servers, layer 7 application technologies, frameworks and protocols with respect to application development and deployment
- Excellent problem solving, critical thinking, interpersonal, collaboration, written and verbal communication skills
- Must be legally authorized to work in the United States for any employer without sponsorship
- Successful completion of interview required to meet job qualification
- Reliable, punctual attendance is an essential function of the position
Preferred Qualifications
- Master's degree
- Certified Ethical Hacker (CEH)
- Giac Security Essentials (GSEC)
- Certified Information Security Manager (CISM)
- Comp TIA Security +
- Certified Information Systems Security Professional (CISSP)
- Certified Information Systems Auditor (CISA)
- Systems Security Certified Practitioner (SSCP)
- CompTIA Advanced Security Practitioner (CASP+)
- Offensive Security Certified Professional (OSCP)
- Minimum of 6 years of experience with any combination of the following: threat modeling, secure coding, identity management and authentication, software development, cryptography, system administration and network security, cloud computing
Pay and Benefits
The base pay range for this role is $112,480.00 to $146,540.00. The base salary range/hourly rate listed is dependent on job-related, factors such as experience, education, and skills. This position is also eligible for bonus and/or long-term incentive compensation awards. You may be eligible for the following competitive benefits: medical, dental, vision, life, accident & disability, parental leave, employee assistance program, commuter, paid holidays, paid time off, 401(k) and flight privileges.