Sr. Security Architect with Cryptography/ Kernel & Runtime Defense
Location: Frisco, TX (Onsite)
Duration: 12 Months
About the Role
Client is launching a critical, top-priority security modernization initiative. We are seeking a visionary Lead Cryptography & Next-Gen Infrastructure Security Architect to shield our cloud-native platforms from the next decade of digital threats. This role operates at the cutting edge of frontier security engineering. You will spearhead our transition into Post-Quantum Cryptography (PQC), architect advanced privacy-preserving runtimes, implement real-time kernel-level observability, and construct highly secure AI/LLM inference pipelines.
Mandatory Niche Skillset
- Advanced Cryptography: Production-grade implementation of Homomorphic Encryption, Secure Multi-party Computation (SMPC), and Zero Knowledge Proofs (ZKP).
- Kernel & Runtime Defense: Deep expertise in eBPF Security Monitoring and Runtime Application Self-Protection (RASP) frameworks.
Qualifications & Experience
- 10+ years of progressive experience in enterprise cybersecurity architecture and infrastructure engineering.
- Post-Quantum Strategy: Proven track record designing and implementing Post-Quantum Cryptography (PQC) strategies alongside robust crypto-agility frameworks.
- Confidential Computing: Hands-on mastery of hardware-level Confidential Computing using Trusted Execution Environments (TEEs).
- Identity & Zero Trust: Experience deploying Identity Threat Detection & Response (ITDR) solutions and establishing workload identities with SPIFFE/SPIRE for service-to-service authentication.
- AI Pipeline Security: Hardened experience protecting live AI inference pipelines built on TensorRT-LLM and Triton Inference Server.
- Cloud-Native Governance: Extensive familiarity managing Kubernetes-native security policies via Kyverno to guarantee multi-cluster policy-as-code enforcement.
- Platform Engineering Integration: Experience embedding security guardrails natively into developer workflows utilizing Backstage IDP.
- Cost Governance: Ability to design security structures that remain strictly aligned with enterprise FinOps principles.
Responsibilities
- Crypto-Agility & Evolution: Formulate and roll out enterprise-wide, future-proofed cryptographic standards resilient against quantum threats.
- Advanced Defense Deployment: Architect systems using SMPC, Homomorphic Encryption, and ZKPs to protect multi-tenant enterprise workflows.
- Runtime Guardrails: Oversee deployment of eBPF-based security monitoring tools and RASP configurations to track and prevent active zero-day runtime exploits.
- AI Infrastructure Hardening: Partner with AI/ML infrastructure squads to guarantee total data isolation and isolation boundaries for foundational large language models.
- Cross-Functional Governance: Sync with risk management, platform infrastructure, and compliance leads to ensure alignment with standard threat modeling frameworks (STRIDE, MITRE ATT&CK).
Pre-Screening Questions
- Does he/she have experience with Post-Quantum Cryptography (PQC) strategies and crypto-agility frameworks?
- Does he/she have experience using Trusted Execution Environments (TEEs)?
- Does he/she have experience leveraging SPIFFE/SPIRE for zero-trust service-to-service authentication?
- Does he/she have experience in utilizing TensorRT-LLM?
- Does he/she have experience in building policies using Kyverno?
- Does he/she have knowledge of FinOps principles?
- Does he/she have experience in implementation of Homomorphic Encryption, Secure Multi-party Computation (SMPC), and Zero Knowledge Proofs (ZKP)?
- Does he/she have experience in eBPF Security Monitoring and Runtime Application Self-Protection (RASP) frameworks?
- Does he/she have experience with threat modeling frameworks (STRIDE, MITRE ATT&CK)?
Note: If the candidate lacks direct experience with a specific tool or framework mentioned, they must explicitly state the alternative technologies they have utilized in their resume.