Principal Security Architect

Posted Sep 28

This is a fully remote position, open to applicants in Canada.

📋 Description

• Perform security design evaluations for both extensive product architectures and minor modifications, including integrations and interactions with AWS cloud infrastructure.

• Execute security code evaluations.

• Design and document integration and deployment processes for enterprise Hardware Security Modules and Key Management systems.

• Evaluate third-party software and SaaS solutions.

• Analyze designs and implementations that incorporate third-party software and SaaS.

• Supervise internal and third-party security evaluations.

• Conduct in-depth assessments of the impacts of third-party and product vulnerabilities.

• Monitor and evaluate the effects of emerging technologies, new web standards, and changes in browser behaviors on products.

• Support compliance and sales teams with the technical aspects of regulations and Requests for Proposals (RFPs).

• Engage in technical security conversations with clients.

• Assist in writing and reviewing patents.

• Generate and evaluate external technical documents, including blogs, white papers, and presentations.

• Innovate security-focused product features.


⛳️ Requirements

• Advanced understanding of applied cryptography, including Hardware Security Modules (HSMs) and Trusted Platform Modules (TPMs).

• Knowledge of the Key Management Life Cycle, covering key generation, storage, distribution, backup, rotation, revocation, and destruction.

• Extensive knowledge of web and browser technologies, including Same Origin Policy, Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), HTTP security headers, browser architecture, and JavaScript engine internals.

• Comprehensive understanding of networking and operating system fundamentals, including TCP, HTTP, TLS, DNS, firewalls, Web Application Firewalls (WAFs), Discretionary Access Control (DAC)/Mandatory Access Control (MAC), and sandboxing.

• Experience in AWS security, including Identity and Access Management (IAM), Organizations, EC2, and VPC.

• Familiarity with concepts and tools for static and dynamic analysis.

• Advanced proficiency in C/C++, particularly with an emphasis on secure coding practices.

• Knowledge of at least one additional programming language, preferably Python or JavaScript.

• A proactive attitude with a willingness to take hands-on approaches to complete tasks.

• Minimum of a Master's degree (MSc/MEng) or equivalent; a PhD is preferred.


🏝️ Benefits

• Eligibility for stock-based compensation grants contingent on both company and individual performance.

• Competitive total compensation and benefits package.

People also viewed

EXL1 day ago

AVP, Cyber Application Security Architect

US flagNew Jersey OnlyFull-timeCybersecurity / Security Engineer$160k – $195.1k/year
ApplyView job
Reli Group2 days ago

Senior Cybersecurity Disaster Recovery, Contingency Planning SME

US flagMaryland OnlyFull-timeCybersecurity / Security Engineer$140k – $150k/year
ApplyView job
Second Nature2 days ago

Cloud Specialist – Security SSR

AR flagArgentina OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
ASRC Federal2 days ago

Information Security Engineer

US flagVirginia OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Kyndryl2 days ago

Lead, Application Consulting – Workday Security

US flagIllinois, +1 more stateFull-timeCybersecurity / Security Engineer$92k – $174.8k/year
ApplyView job
HomeServe USA2 days ago

Senior Cybersecurity Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$114.5k – $167.9k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers