Senior Security Architect [AQ-12143]
Aquent · San Francisco, CA · 2 wk ago
RemoteRemoteInformation TechnologyContract
About the role
Aquent is partnering with a leading financial technology company dedicated to building secure and cutting-edge products and services. This organization fosters a highly collaborative environment, working across engineering, product, and design teams to ensure the highest security standards and regulatory adherence. As a visionary leader, you will drive the end-to-end security of a dynamic digital ecosystem, making critical security decisions, leading initiatives that support business objectives, and ensuring unwavering trust through unparalleled security.
Responsibilities
- Champion cybersecurity architecture, translating complex security concepts into actionable strategies for product and engineering teams.
- Seamlessly integrate new and existing security tools, standards, and processes into the entire development lifecycle.
- Provide expert guidance on the secure design of product and application architecture, articulating clear security requirements through well-defined user stories, initiatives, and epics.
- Conduct thorough security design reviews and comprehensive threat modeling for both infrastructure and application projects.
- Perform in-depth security reviews and assessments of critical applications and platforms to proactively identify vulnerabilities and ensure continuous compliance with security standards.
- Review and secure APIs, implementing robust authentication, authorization, and data validation mechanisms to safeguard data integrity.
- Collaborate closely with development teams, offering proactive and security-specific feedback on new features and functionalities.
- Analyze and evaluate evolving cloud security trends and vulnerabilities, providing continuous feedback to refine and implement best practices.
- Develop comprehensive security test plans for new products and design scalable security solution blueprints that anticipate future needs.
- Automate security checklists and implement “security as code” leveraging advanced cloud services and continuous integration/continuous delivery (CI/CD) components.
- Conduct continuous threat modeling for new features and product offerings within a fast-paced agile delivery environment.
- Perform business-level security architecture assessments to evaluate existing security programs and cloud application architectures, identifying weaknesses and recommending strategic improvements.
- Partner with risk and compliance teams, contributing to critical security risk impact assessments and shaping information security policies, standards, and guidelines.
- Work with engineering teams to ensure application security risks are effectively identified using market-leading tools and appropriately addressed, balancing robust security with optimal usability.
- Architect, design, prioritize, coordinate, and communicate the necessary security technologies to maintain a highly secure yet user-friendly computing environment.
Requirements
- Strong understanding of cloud services, major cloud platforms, AI Security, SaaS security, and the Well-Architected Framework security pillar.
- Proven experience with threat modeling or other advanced risk identification techniques.
- Demonstrated ability to conduct architecture reviews to identify and evaluate application and infrastructure security risks.
- Deep understanding of containerization technologies like Docker, orchestration platforms such as Kubernetes, and robust CI/CD pipelines.
- Comprehensive knowledge of network and web-related protocols (e.g., TCP/IP, UDP, IPSEC, HTTP, HTTPS, routing protocols).
- Expertise in Identity and Access Management (IAM), including authentication and authorization protocols like OIDC, OAuth2.0, and SAML.
- Proficiency in web application security, microservices architecture, and API design patterns.
- Experience with service mesh concepts, microsegmentation, and advanced network security principles.
- Familiarity with cryptographic protocols and standards for secure data encryption.
- Demonstrated knowledge of the current threat landscape, security threat and vulnerability management, and sophisticated security monitoring and analytics.
- Ability to prioritize and manage multiple work streams effectively in a dynamic environment.
- Excellent written and verbal communication skills, capable of conveying complex security concepts and solutions to diverse audiences.
- Solid understanding of secure software development lifecycle (SDLC) principles and “Shift Left” methodologies.
Qualifications
- Bachelor’s degree in Computer Science or an equivalent field from a fully-accredited college or university.
- 8+ years of experience in infrastructure and product security architecture.
- Experience with cloud-native products and an in-depth understanding of microservice topologies and implementations.
- 8+ years of hands-on experience with cloud technologies.
- Demonstrated ability to think strategically about complex business, product, and technical challenges.
- Proven ability to work with compliance frameworks and requirements such as PCI, GLBA, HIPAA, GDPR, SOX, etc.
- Ability to effectively manage relationships with other business units, external vendors, and stakeholders when IT security risks are present and system or process changes are required to mitigate risk.
- Familiarity with major cloud platforms and at-scale services.
- Ability to thrive and contribute significantly in a fast-paced and Agile development environment.
- Collaborative spirit, essential for success in a team-oriented and innovative environment.
Preferred Qualifications
- Relevant industry certifications such as CISSP, CISM, or GSEC.
- Master’s or PhD in Computer Science or Engineering.
- Experience within the financial services industry.
Benefits
Eligible talent get access to amazing benefits including:
- Subsidized health, vision, and dental plans.
- Paid sick leave.
- Retirement plans with a match.
- Free online training through Aquent Gymnasium.