
Principal Security Architect
Posted Sep 28

Posted Sep 28
This is a fully remote position, open to applicants in Canada.
• Perform security design evaluations for both extensive product architectures and minor modifications, including integrations and interactions with AWS cloud infrastructure.
• Execute security code evaluations.
• Design and document integration and deployment processes for enterprise Hardware Security Modules and Key Management systems.
• Evaluate third-party software and SaaS solutions.
• Analyze designs and implementations that incorporate third-party software and SaaS.
• Supervise internal and third-party security evaluations.
• Conduct in-depth assessments of the impacts of third-party and product vulnerabilities.
• Monitor and evaluate the effects of emerging technologies, new web standards, and changes in browser behaviors on products.
• Support compliance and sales teams with the technical aspects of regulations and Requests for Proposals (RFPs).
• Engage in technical security conversations with clients.
• Assist in writing and reviewing patents.
• Generate and evaluate external technical documents, including blogs, white papers, and presentations.
• Innovate security-focused product features.
• Advanced understanding of applied cryptography, including Hardware Security Modules (HSMs) and Trusted Platform Modules (TPMs).
• Knowledge of the Key Management Life Cycle, covering key generation, storage, distribution, backup, rotation, revocation, and destruction.
• Extensive knowledge of web and browser technologies, including Same Origin Policy, Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), HTTP security headers, browser architecture, and JavaScript engine internals.
• Comprehensive understanding of networking and operating system fundamentals, including TCP, HTTP, TLS, DNS, firewalls, Web Application Firewalls (WAFs), Discretionary Access Control (DAC)/Mandatory Access Control (MAC), and sandboxing.
• Experience in AWS security, including Identity and Access Management (IAM), Organizations, EC2, and VPC.
• Familiarity with concepts and tools for static and dynamic analysis.
• Advanced proficiency in C/C++, particularly with an emphasis on secure coding practices.
• Knowledge of at least one additional programming language, preferably Python or JavaScript.
• A proactive attitude with a willingness to take hands-on approaches to complete tasks.
• Minimum of a Master's degree (MSc/MEng) or equivalent; a PhD is preferred.
• Eligibility for stock-based compensation grants contingent on both company and individual performance.
• Competitive total compensation and benefits package.
EXL
Reli Group
Second Nature
ASRC Federal
Get handpicked remote jobs straight to your inbox weekly.