
Information Security Architect
Posted Sep 1

Posted Sep 1
This is a fully remote position, open to applicants in United States.
• Develop and uphold secure software development standards alongside best practices for cloud security.
• Direct the security lifecycle by analyzing emerging technologies, threats, and trends, while enhancing end-of-life governance for applications and technologies.
• Engage in and enhance the Architectural Review Board by applying a security-centric approach across all IT domains.
• Examine application architecture documentation, including diagrams and runbooks, with a focus on security.
• Collaborate with engineering and DevOps teams to integrate security governance and best practices into CI/CD pipelines.
• Perform architecture risk assessments, threat modeling, and secure design evaluations for both new and existing applications.
• Create security reference architectures, design patterns, and technical standards for cloud-native applications.
• Spearhead application security initiatives such as SAST, DAST, software composition analysis (SCA), Infrastructure as Code (IaC) scanning, container security, and API security.
• Work closely with the enterprise architect to ensure that enterprise security architecture, governance, and guidance are applied across all IT domains.
• Assess cloud services and third-party technologies for security vulnerabilities and compliance obligations.
• Collaborate with security operations, infrastructure, compliance, and engineering teams to investigate and address security issues.
• Serve as a trusted advisor to development, infrastructure, network, cloud, data, and security teams.
• Ensure that cloud applications adhere to organizational policies and regulatory frameworks such as PCI DSS, HIPAA, SOC 2, ISO 27001, NIST, and GDPR.
• Provide technical leadership and mentorship to development teams regarding secure coding practices and cloud security.
• Undertake additional responsibilities as assigned by management.
• A Bachelor’s degree in computer science, business, or a related field is required, or equivalent work experience.
• Over 7 years of experience in securing enterprise environments across on-premises, hybrid, and cloud infrastructures.
• In-depth understanding of the secure software development lifecycle (SSDLC) and DevSecOps practices.
• Comprehensive knowledge of secure coding principles and common application vulnerabilities, including OWASP Top 10 and API Security Top 10.
• Solid experience with Azure DevOps technology, focusing on CI/CD pipelines and Git repositories.
• Strong knowledge of identity and access management, authentication, authorization, OAuth, OpenID Connect, SAML, risk management, and Zero Trust principles.
• Familiarity with SIEM, EDR/XDR, IAM, PAM, CASB, DLP, and vulnerability management platforms.
• Experience in the healthcare industry is preferred.
• CISSP certification is preferred.
• Ability to comprehend and align business needs with suitable technical application solutions.
• Capability to convert security policies, regulatory requirements, and risk findings into actionable architecture guidance.
• Exceptional communication and collaboration skills, with the capacity to work alongside multiple teams concurrently.
• Strong time management abilities and the capability to manage multiple business-critical projects at once.
• Understanding of fundamental security and compliance principles within a healthcare context.
• Excellent analytical and problem-solving skills, with the ability to resolve complex technical issues.
• No specific benefits or compensation extras stated in the posting.
Robots & Pencils
Latitude IT Solutions | SDVOSB
Latitude IT Solutions | SDVOSB
11:11 SYSTEMS
Get handpicked remote jobs straight to your inbox weekly.