> Markdown version of [/jobs/ext/1316124-security-architect-i-cloud-infrastructure](https://www.wearedevelopers.com/jobs/ext/1316124-security-architect-i-cloud-infrastructure). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Architect I, Cloud & Infrastructure - **Company:** Cambridge Mobile Telematics - **Location:** Cambridge, MA, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Geographic Information Systems, Application Programming Interfaces (APIs), Artificial Intelligence, User Authentication, Cloud Computing, Cyber Security, Key Management, Machine Learning, Open Web Application Security, Systems Development Life Cycle, Reverse Engineering, Secure Coding, Mobile Security, Software Engineering, Systems Architecture, Large Language Models, Software Security, Backend, Data Pipelines - **Published:** July 17, 2026 - **Apply:** https://www.dice.com/job-detail/9f4776e3-ee0f-4b42-9e6c-2c0e15ad2818 ## About the Role * Bachelor's degree or equivalent years of experience and/or certification in a related field * 7+ years of experience in security, with deep, hands-on expertise in application and product security architecture * Proven ability to provide technical leadership and drive security initiatives through influence * Strong software engineering foundation with experience reviewing code and system architecture * Deep knowledge of threat modeling, secure SDLC, OWASP, authentication, cryptography, API security, and mobile security * Experience securing products that process sensitive personal data and support regulatory requirements * Working knowledge of AI/ML and LLM security, including secure AI adoption * Excellent written and verbal communication skills Nice to Haves: * Experience with mobile SDK security, reverse engineering, and anti-tampering * Familiarity with data-intensive architectures and ML-driven products * Experience developing AI governance or secure AI adoption programs * Experience in telematics, IoT, connected vehicles, fintech, or other high-trust industries * Relevant certifications such as CSSLP, OSCP, or GWEB ## Description We're hiring a Principal Security Architect I, Cloud & Infrastructure to own the security architecture of CMT's products, from our mobile SDKs and APIs to the services that power our platform. This is a highly autonomous individual contributor role where you'll set the technical direction for product security and influence engineering teams to deliver secure solutions. You'll stay hands-on with architecture while shaping security strategy across the organization through technical leadership, collaboration, and sound engineering judgment rather than people management. You'll also define how we securely build AI-powered products and adopt AI development tools, establishing the guardrails that enable innovation while reducing security risk., * Own the end-to-end security architecture for CMT's products, including mobile SDKs, backend services, APIs, data pipelines, and partner integrations * Define security standards, reference architectures, and engineering guardrails, and drive adoption across teams * Embed security into the SDLC through threat modeling, secure design reviews, and actionable engineering requirements * Lead threat modeling and translate findings into prioritized engineering work * Define application security strategy for testing, secure coding, secrets management, and software supply chain security * Own security architecture for protecting sensitive driver and location data * Define security architecture and guardrails for AI/ML features and AI development tools * Own the AppSec and Product Security roadmap, including technology strategy and prioritization * Serve as the senior security authority for architecture reviews, risk decisions, and technical guidance * Support customer and partner security reviews and mentor engineers on secure design * Complete any additional tasks as they arise ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Why and when should we consider Stream Processing frameworks in our solutions](https://www.wearedevelopers.com/videos/1085-why-and-when-should-we-consider-stream-processing-frameworks-in-our-solutions) - [Nest.js - TypeScript in the backend can also be clean](https://www.wearedevelopers.com/videos/1033-nest-js-typescript-in-the-backend-can-also-be-clean) - [How GitHub secures open source](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)