> Markdown version of [/jobs/ext/1487731-security-architect](https://www.wearedevelopers.com/jobs/ext/1487731-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Architect - **Company:** Budd Thyssenkrupp Company - **Location:** Southfield, MI, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Application Programming Interfaces (APIs), Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Multi-Factor Authentication, Identity and Access Management, Information Systems Security Architecture Professional, Microsoft Security Essentials, Systems Development Life Cycle, Zero Trust Network Access, Software Vulnerability Management, Software Security, Skills Cloud, Microsoft Sentinel, Data Management, Plan of Action and Milestones, Static Application Security Testing, Dynamic Application Security Testing - **Published:** July 29, 2026 - **Apply:** https://jobs.mitalent.org/job-seeker/job-details/JobCode/397968517 ## About the Role Bachelor's degree or equivalent professional experience required, Master's degree preferred. 7+ years of experience in information security, including handson security architecture or application security experience. Strong experience securing Microsoft 365 GCCHigh and Azure Government environments. Demonstrated expertise with cloud security, identity and access management, application security, and incident response. Experience supporting regulated environments (CMMC, ITAR, DFARS, or similar). Certifications All relevant security and cloud certifications preferred, including CISSP, CCSP, CISM, GIAC, and Microsoft security certifications. Skills Cloud & Identity: Azure Gov, M365 GCCHigh, Entra ID, Zero Trust, Conditional Access, MFA, PIM Application Security: Threat modeling, SAST/DAST/SCA, API and container security Monitoring & Response: Microsoft Sentinel, Defender XDR, automation and incident response Compliance: CMMC 2.0, NIST 800171/172, ITAR, risk management ## Description thyssenkrupp Materials NA is a subsidiary of the internationally operating thyssenkrupp Group. Headquartered in Southfield, Michigan, thyssenkrupp Materials NA is a leading provider of production materials and integrated service solutions with almost 2,900 employees and more than 95 locations in North America. With annual sales of $2.9 billion, the company is focused on value-added processing and distribution of a full line of aluminum, stainless, copper, brass, specialty metals, steel, and plastics products. Supply chain management, transportation and logistics, and production support outsourcing solutions are among the many services provided to customers. Business units include Copper and Brass Sales, Engineered Plastics, Ken-Mac Metals, OnlineMetals, thyssenkrupp Steel Services, thyssenkrupp Supply Chain Services, and thyssenkrupp Materials de Mexico. Your responsibilities Job Summary The Security Architect is a technical leader responsible for designing, implementing, and advancing enterprise security across cloud, application, and infrastructure environments, with a primary focus on Microsoft GCCHigh and Microsoft Commercial platforms. This role partners closely with IT, Engineering, Compliance, and business leaders to embed securitybydesign, strengthen CMMC and ITAR compliance, and enhance security operations and risk management capabilities., Design and govern secure architectures across cloud, identity, applications, and data platforms. Lead application security initiatives including assessments, threat modeling, secure SDLC practices, and vulnerability remediation. Support CMMC 2.0 Level 2+ readiness, including NIST 800 171/172 control implementation, SSP/POA&M management, and audit support. Architect and operate security capabilities within Microsoft GCC High and Azure Government, including Defender, Sentinel, Purview, and Entra ID. Provide senior level guidance during security incidents, investigations, and post incident remediation. Translate regulatory and business requirements into scalable security roadmaps and standards. Serve as a trusted advisor to engineering, IT, and leadership teams, mentor security professionals. Meets TKMNA Employee Attributes / Competencies The above is intended to describe the general content of and requirement for the performance of this job. It is not to be construed as an exhaustive statement of duties, responsibilities or requirements. ## Related Videos - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems)