Senior Architect - Application Cybersecurity

United Continental Holdings, Inc.
Chicago, IL, United States
12 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Compensation
$112,480.0 - $146,540.0
Working hours
Regular working hours
Job source

Tech stack

Application Layers User Authentication Authentication Protocols Cloud Computing Static Program Analysis Cyber Security Information Systems Continuous Integration Digital Technology Web Servers Identity and Access Management Information Systems Security Architecture Professional
+12 more
Network Security Microsoft Security Essentials Open Web Application Security Secure Coding Software Engineering Web Applications Software Security Information Technology Data Analytics Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

United’s Digital Technology team is comprised of many talented individuals all working together with cutting-edge technology to build the best airline in the history of aviation. Our team designs, develops and maintains massively scaling technology solutions brought to life with innovative architectures, data analytics, and digital solutions., The Senior Architect - Application Cybersecurity helps validate that our services, applications, and websites are designed and implemented in accordance with United’s secure development standards. The Senior Architect works closely with development teams, product teams, and other teams across the organization to integrate security into the product lifecycle from design through deployment., The Senior Architect is responsible for defining security requirements, performing application security assessments, and providing developers with remediation guidance and advice. On any given day the Senior Architect can be pulled in to evaluate a new system, review a proposed application change, or provide guidance on application security/coding best practices.

  • Perform security architecture design reviews and threat modelling of our products (cloud and on-prem)
  • Help research, define and communicate security best practices and standards and ensure products development teams understand them
  • Learning & Continuous Improvement
  • Improve the accessibility of security through automation, continuous integration pipelines, and other means
  • Perform code analysis of applications, manually and using SAST, DAST, and SCA scanning solutions as well as conducting manual vulnerability analysis
  • Technical point of contact for product teams as it relates to automation, CI/CD, and remediation guidance

Requirements

What’s needed to succeed (Minimum Qualifications):

  • Bachelor’s degree
  • STEM, Computer Science
  • Minimum of 4 years of experience with any combination of the following: threat modeling, secure coding, identity management and authentication, software development, cryptography, system administration and network security, cloud computing
  • Understanding of OWASP Top 10 and CWE 25; Ability to implement and integrate remediation strategies
  • Ability to collaborate with development teams to build secure solutions, communicating risks and bringing consensus to diverse priorities
  • Knowledge of common vulnerabilities and attack vectors, ubiquitous encryption technologies and common authentication protocols
  • Familiar with application risk assessment, risk categorization, and application security testing tools
  • Knowledge of current industry standards, best practices, and reference architectures
  • Understanding of secure network and system design in both cloud and conventional environments, as well as of network and web related protocols
  • Understanding of web applications, web servers, layer 7 application technologies, frameworks and protocols with respect to application development and deployment
  • Ability to work independently and self-motivate
  • Excellent problem solving, critical thinking, interpersonal, collaboration, written and verbal communication skills
  • Must be legally authorized to work in the United States for any employer without sponsorship
  • Successful completion of interview required to meet job qualification
  • Reliable, punctual attendance is an essential function of the position

What will help you propel from the pack (Preferred Qualifications):

  • Master’s degree
  • Certified Ethical Hacker (CEH)
  • GIAC Security Essentials (GSEC)
  • Certified Information Security Manager (CISM)
  • Comp TIA Security + Certified Information Systems Security Professional (CISSP)
  • Certified Information Systems Auditor (CISA)
  • Systems Security Certified Practitioner (SSCP)
  • CompTIA Advanced Security Practitioner (CASP+)
  • Offensive Security Certified Professional (OSCP)
  • Minimum of 6 years of experience with any combination of the following: threat modeling, secure coding, identity management and authentication, software development, cryptography, system administration and network security, cloud computing

Benefits & conditions

The base pay range for this role is $112,480.00 to $146,540.00.

The base salary range/hourly rate listed is dependent on job-related, factors such as experience, education, and skills. This position is also eligible for bonus and/or long-term incentive compensation awards.

You may be eligible for the following competitive benefits: medical, dental, vision, life, accident & disability, parental leave, employee assistance program, commuter, paid holidays, paid time off, 401(k) and flight privileges.

About the company

Achieving our goals starts with supporting yours. Grow your career, access top-tier health and wellness benefits, build lasting connections with your team and our customers, and travel the world using our extensive route network.

Come join us to create what’s next. Let’s define tomorrow, together.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:07 min

Creating a hardware unlock interface utilizing a SvelteKit server

Daphne Oakes +1 · LIVE

2:59 min

Applying secure coding practices and proactive system monitoring

Mihaela-Roxana Ghidersa · LIVE

1:32 min

Structuring platforms for new services and data analytics

Nevelina Aleksandrova · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

10:35 min

Teaching and coaching security concepts for lasting impact

Tanya Janca · WWC 2021

2:17 min

Handling server headers and LLM injections

Jakub Andrzejewski · WWC 2023

Videos

See all

Related articles

See all