Назад
Company hidden
7 дней назад

Application & Platform Security Architect (Cloud Security)

141 500 - 268 500$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application & Platform Security Architect (Cloud Security): Designing and implementing security architecture, controls, and guardrails for business-critical applications and cloud environments with an accent on secure-by-design development, identity security, application protection, and regulatory compliance. Focus on threat modeling, securing APIs and CI/CD pipelines, integrating DevSecOps practices, and influencing architecture decisions across software development and infrastructure teams.

Location: North Chicago, Illinois, United States

Salary: $141,500–$268,500 per year

Company

hirify.global develops medicines and healthcare solutions across immunology, oncology, neuroscience, and Allergan Aesthetics.

What you will do

  • Define reusable security architecture patterns, controls, and guardrails for high-risk business applications.
  • Integrate security requirements into software architecture, application development, DevOps, deployment, and operational transition.
  • Evaluate application and infrastructure designs, produce security architecture artifacts, and advise architecture review boards.
  • Lead application threat modeling, identify risks, and recommend design changes and remediation activities.
  • Research and assess emerging security technologies and threats, recommending improvements to information security strategy.
  • Collaborate with application architects, engineers, IT stakeholders, vendors, and security leadership to implement secure solutions.

Requirements

  • Bachelor’s degree with 9 years of relevant experience, Master’s degree with 8 years, or PhD with 4 years in information security or a related function.
  • Strong knowledge of application security, OWASP Top 10, SANS/CWE Top 25, secure coding, session management, token handling, and authentication.
  • Experience with OAuth, SAML, OpenID Connect, cryptography, encryption, PKI, IAM, Zero Trust, and least-privilege principles.
  • Experience with Docker, Kubernetes, AWS, Azure, GCP, cloud security, microservices, serverless computing, and container security.
  • Knowledge of code analysis and vulnerability scanning tools, DevSecOps, CI/CD security, ISO and NIST frameworks, and security architecture documentation.
  • Hands-on SOX and HIPAA experience, including IT general controls, audits, remediation, or computer system validation, plus strong stakeholder communication skills.

Nice to have

  • CISSP or another information security qualification.
  • Experience with identity management, federated identity services, incident management, access control, application vulnerability testing, Windows, Unix/Linux, and public cloud infrastructure.

Culture & Benefits

  • Full-time position within the Information Security and Information Technology functions.
  • Paid vacation, holidays, and sick leave.
  • Medical, dental, and vision insurance for eligible employees.
  • 401(k) and eligibility for long-term incentive programs.
  • Collaborative work with cross-functional teams and opportunities to mentor colleagues and strengthen information security practices.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →