
Information Security Architect
Posted Sep 1

Posted Sep 1
This is a fully remote position, open to applicants in United States.
• Establish and uphold secure software development standards alongside cloud security best practices.
• Lead the security lifecycle by assessing emerging technologies, threats, and trends while enhancing end-of-life governance for applications and technologies.
• Engage in and advance the Architectural Review Board by applying a security-centric approach across IT domains.
• Review application architecture documents, including diagrams and runbooks.
• Collaborate with engineering and DevOps teams to integrate security governance and best practices into CI/CD pipelines.
• Conduct architecture risk evaluations, threat modeling, and secure design assessments.
• Develop security reference architectures, design patterns, and technical standards for cloud-native applications.
• Spearhead application security initiatives such as SAST, DAST, software composition analysis, IaC scanning, container security, and API security.
• Partner with the enterprise architect to implement enterprise security architecture, governance, and guidance across IT domains.
• Assess cloud services and third-party technologies for security vulnerabilities and compliance obligations.
• Work alongside security operations, infrastructure, compliance, and engineering teams to investigate and resolve security issues.
• Serve as a trusted advisor to development, infrastructure, network, cloud, data, and security teams.
• Ensure compliance of cloud applications with organizational policies and frameworks such as PCI DSS, HIPAA, SOC 2, ISO 27001, NIST, and GDPR.
• Offer technical leadership and mentorship on secure coding practices and cloud security.
• Execute other responsibilities as assigned by management.
• Bachelor’s degree in computer science, business, or a related field is required (or equivalent work experience).
• Over 7 years of experience in securing enterprise environments across on-premises, hybrid, and cloud infrastructures.
• Profound understanding of the secure software development lifecycle (SSDLC) and DevSecOps methodologies.
• Extensive knowledge of secure coding principles and common application vulnerabilities (OWASP Top 10, API Security Top 10).
• Solid experience with Azure DevOps technology, particularly in CI/CD pipelines and Git repositories.
• Strong understanding of identity and access management, authentication, authorization, OAuth, OpenID Connect, SAML, risk management, and Zero Trust principles.
• Familiarity with SIEM, EDR/XDR, IAM, PAM, CASB, DLP, and vulnerability management platforms.
• Experience in the healthcare sector is preferred.
• CISSP certification is preferred.
• Ability to interpret and translate business requirements into suitable technical application solutions.
• Capability to convert security policies, regulatory requirements, and risk findings into actionable architecture guidance.
• Exceptional communication and collaboration skills.
• Strong time management skills with the ability to juggle multiple business-critical projects simultaneously.
• Understanding of fundamental security and compliance principles within a healthcare setting.
• Excellent analytical and problem-solving skills for tackling complex technical challenges.
• Competitive salary and performance-based bonuses.
• Comprehensive health, dental, and vision insurance.
• Generous paid time off and holiday schedule.
• Opportunities for professional development and continued education.
• Flexible work arrangements, including remote work options.
GuidePoint Security
Gravie
Your Software Supplier
Dragonfli Group
Get handpicked remote jobs straight to your inbox weekly.