Sr Cybersecurity Architect

McGraw-Hill
Columbus, United States of America
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior
Compensation
$ 190K

Job location

Remote
Columbus, United States of America

Tech stack

Artificial Intelligence
Amazon Web Services (AWS)
Application Firewall
Software System Penetration Testing
Azure
Burp Suite
Cloud Computing
Cloud Computing Security
Computer Security
Digital Forensics
Middleware
Identity and Access Management
Systems Development Life Cycle
Role-Based Access Control
Cloud Services
Secure Coding
Software Deployment
Software Engineering
Systems Integration
Software Vulnerability Management
Web Applications
Cloud-native Network Functions (CNF)
Google Cloud Platform
Cloud Platform System
Software Security
Oracle Cloud Infrastructure
Devsecops
Static Application Security Testing
Vulnerability Analysis
Dynamic Application Security Testing

Job description

McGraw Hill is seeking a Cybersecurity Architect who can collaborate with development teams, business teams, and cross-functional technology. The role will lead efforts to secure cloud platforms, mitigate cyber risks, and ensure compliance with security policies and regulatory requirements. As a Cybersecurity Architect you should have experience in developer security (DevSecOps), cloud network security, cloud infrastructure vulnerabilities, vulnerability scanning tools, SAST, and working with teams to remediate vulnerabilities. The McGraw Hill Cybersecurity Team is a highly technical, metrics driven team, with a consistent focus on process optimization and automation to improve effectiveness. You must be able to report, quantify stats, trends, and metrics to articulate risk and results. This is an individual contributor role that will report to the VP of Cybersecurity.

This is a remote position open to applicants authorized to work for any employer within the United States.

What You'll Do:

  • Lead security architecture reviews for new digital product offerings or major changes to existing products to uphold MH's digital product security standards.
  • Design and implement a Static Application Security Testing (SAST) strategy to protect McGraw Hill's static code environment that will reduce vulnerabilities prior to production deployments.
  • Develop and maintain the strategy of the cloud security posture for all cloud accounts (AWS, Azure, OCI) belonging to the organization.
  • Collaborate with development teams, cloud operations, engineering, and IT teams to promote secure development practices and integrate security controls into CI/CD pipelines.
  • Present/articulate threats, vulnerabilities and risks to developers, stakeholders, and leadership.
  • Respond and triage security incidents related to digital products.
  • Provide support for web-app and cloud infrastructure vulnerabilities and findings discovered via tools, penetration testing, or by security researchers.
  • Conduct risk assessments on cloud systems and identify/remediate security gaps.
  • Maintain Identity and Access Management (IAM) policies, Role-based Access Control, and least-privileged access to the MH cloud environment.
  • Design and implement strategy to secure MH SDLC workflows.
  • Oversee Web Application Firewall strategy for MH customer-facing products.
  • Secure AI and MCP development workloads.

Requirements

  • Bachelors degree in related field or equivalent experience preferred.

  • 10+ years of applicable experience.

  • Candidates must hold a CISSP or have equivalent cybersecurity-related experience.

  • Candidates must hold certifications or have equivalent experience in Networking, Cloud Principles, and Incident Response.

  • Ability to present cybersecurity risks and remediation recommendations to senior leadership.

  • Ability to respond to security-related incidents and perform digital forensics.

  • Familiarity with IT Security Policies and Procedures.

  • Strong analytical and communication skills.

  • Thorough understanding of web-based applications, server & container instances, and middleware.

  • In-depth understanding of AWS architecture and accommodating security controls.

  • While minimal, ability to respond to night and/or weekend security incidents.

  • Experience working with Dynamic Application Security Testing (DAST) and Static Application Security Scanning (SAST).

  • Experience with using, maintaining, and reporting results of vulnerability scanning tools, such as Insight AppSec, Insight VM, Insight CloudSec, Burp Suite Pro.

  • Collaborate with developers and engineers to articulate vulnerabilities, risks, and remediations.

  • Foster cybersecurity culture throughout the McGraw Hill software development community.

Preferred:

  • Experience with maintaining and maturing a Vulnerability Management Program
  • Experience or familiarity with other cloud service providers, such as Azure, Google Cloud, Oracle Cloud.
  • Experience in securing custom AI/MCP applications and integrations.

Benefits & conditions

The work you do at McGraw Hill will be work that matters. We are collectively building experiences that will help shape the future of education. Play your part and experience a sense of fulfilment that will inspire you to even greater heights.

The pay range for this position is between $130,000 - $190,000 annually. However, base pay offered may vary depending on job-related knowledge, skills, experience, and location. An annual bonus plan may be provided as part of the compensation package, in addition to a full range of medical and/or other benefits, depending on the position offered. Click here to learn more about our benefit offerings.

Apply for this position