Назад
Company hidden
1 день назад

Application & Platform Security Architect (Cloud Security)

141 500 - 268 500$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application & Platform Security Architect (Cloud Security): Designing and implementing security architectures, reusable guardrails, and controls for business-critical applications and cloud environments with an accent on secure-by-design practices, identity security, DevSecOps, and regulatory compliance. Focus on application threat modeling, securing APIs and CI/CD pipelines, evaluating cloud and container architectures, and mitigating risks across complex enterprise systems.

Location: North Chicago, Illinois, United States; onsite role.

Salary: USD 141,500–268,500 per year.

Company

hirify.global develops innovative medicines and healthcare solutions across immunology, oncology, neuroscience, and aesthetics.

What you will do

  • Define reusable security architecture patterns, guardrails, application controls, and implementation guidance for high-risk business applications.
  • Drive secure-by-design practices across the software architecture lifecycle and represent security architecture in design authority boards and technical review councils.
  • Evaluate application, infrastructure, cloud, and container designs with architects and engineers to align solutions with enterprise security standards.
  • Integrate security into software development, DevOps, deployment, and operational transition processes.
  • Lead application threat modeling, identify security risks, recommend mitigations, and support remediation and compliance activities.
  • Research emerging information security threats and technologies while developing security strategies, policies, standards, and education initiatives.

Requirements

  • Bachelor's degree with 9 years of experience, master's degree with 8 years, or PhD with 4 years in information security or a related function.
  • Strong application security knowledge, including OWASP Top 10, SANS/CWE Top 25, secure coding, session management, token handling, OAuth, SAML, and OpenID Connect.
  • Experience with cryptography, encryption, PKI, identity security, least privilege, separation of duties, and Zero Trust principles.
  • Experience with Docker, Kubernetes, AWS, Azure, or GCP, including container, Kubernetes, IAM, network, secrets, and data protection security.
  • Knowledge of DevSecOps and CI/CD security, code analysis and vulnerability scanning tools such as SonarQube, Veracode, Burp Suite, and Nessus.
  • Significant SOX and HIPAA experience, including IT general controls, audit, remediation, or computer system validation, plus strong communication and influencing skills.

Nice to have

  • CISSP or another information security qualification.
  • Experience with incident management, access control, federated identity services, Windows, Unix/Linux, and public cloud infrastructure.

Culture & Benefits

  • Comprehensive benefits package including paid vacation, holidays, and sick leave.
  • Medical, dental, and vision insurance for eligible employees.
  • 401(k) plan for eligible employees.
  • Eligibility to participate in long-term incentive programs.
  • Collaborative work with information security, application development, DevOps, operations, and business stakeholders.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →