Security Architect

C4 Technical Services
United States
11 days ago

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Application Programming Interfaces (APIs) Artificial Intelligence Computing Platforms User Authentication Microsoft Azure Cloud Computing Cloud Computing Security Cyber Security Continuous Integration Data Validation Distributed Systems
+23 more
Github Key Management Network Segmentation Open Web Application Security Secure Coding Session Management Software Engineering SonarQube Software Vulnerability Management Datadog Data Processing Cloud Platform System Spring Cloud Delivery Pipeline Sonatype Software Security Information Technology Devsecops Serverless Computing Security Orchestration, Automation & Response Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

This role acts as a strategic partner to engineering, architecture, product, platform, and operations teams to ensure security is embedded throughout the software development lifecycle. The Security Architect will define security standards, lead security assessments of mission-critical applications, guide remediation, implement scalable security capabilities, and help build a culture where security is everyone’s responsibility., Security Governance and Architecture

  • Define, maintain, and evolve enterprise security policies, standards, patterns, and architectural guardrails.
  • Establish security governance processes that integrate with architecture reviews, roadmap planning, project delivery, and operational practices.
  • Develop reusable security reference architectures for common product and platform patterns.
  • Partner with Enterprise Architecture to ensure security requirements are reflected in platform strategies, modernization efforts, and engineering standards.
  • Align security practices to relevant industry frameworks such as NIST CSF, NIST SSDF, OWASP, ISO 27001, and
  • SOC 2 where applicable.

Application Security

  • Review mission-critical applications and services for architectural and implementation-level security risk.
  • Lead threat modeling exercises and identify risks early in solution design.
  • Review vulnerability findings and provide clear, risk-based remediation guidance to engineering teams.
  • Partner with development teams to improve secure coding practices and reduce repeat vulnerability patterns.
  • Define practical security requirements for APIs, distributed systems, identity flows, data handling, cloud-native services, and AI-enabled capabilities.

Platform Security Capabilities

  • Partner with platform engineering teams to implement security capabilities that improve the security posture of all product teams.
  • Advance tooling and controls for SAST, DAST, SCA, secret scanning, dependency management, container security, infrastructure-as-code scanning, and CI/CD enforcement.
  • Design automated controls that can be embedded into build, test, release, and deployment pipelines.
  • Develop security metrics and dashboards that provide leadership visibility into vulnerability backlog, remediation progress, policy adherence, and platform risk.
  • Promote secure-by-default capabilities that reduce security burden on individual product teams.

Security Awareness and Enablement

  • Establish and lead a Security Champions model across engineering teams.
  • Security Architect Job Description IDeaS
  • Deliver targeted security awareness and secure development enablement for developers, architects, product owners, and technical leaders.
  • Provide consultative coaching to teams without becoming a delivery bottleneck.
  • Create practical guidance, playbooks, and reusable examples that make secure behavior easier to adopt.
  • Promote a culture of shared accountability where security is built into normal engineering practice.

Security Automation

  • Automate security governance and validation processes to reduce manual review overhead.
  • Improve automated vulnerability detection, triage, and remediation workflows.
  • Partner with teams to build automated policy checks, compliance evidence, and exception tracking where appropriate.
  • Continuously evaluate tools and platform investments that improve security outcomes at scale.

Requirements

  • Application Security
  • AWS Cloud & Platform Security
  • DevSecOps
  • Tooling Familiarity
  • Local to Twin Cities

Application Security - Secure design, secure coding principles, API security, authentication, authorization, session management, input validation, dependency risk, and data protection.

Cloud and platform security - Cloud security principles, network segmentation, workload identity, secrets management, container security, infrastructure-as-code security, and least-privilege design.

DevSecOps - Security integration with CI/CD pipelines, automated controls, security gates, vulnerability triage, build/release enforcement, and developer feedback loops.

Architecture and governance - Reference architectures, design review practices, risk-based decisions, policy creation, reusable patterns, exception handling, and architecture guardrails.

Tooling familiarity Experience - with tools such as GitHub Advanced Security, SonarQube, Snyk, Datadog, Azure Defender/Security Center, vulnerability scanners, container scanners, or equivalent platforms. -, The ideal candidate combines hands-on technical depth, architectural judgment, organizational influence, and automation-first thinking to improve security posture across modern cloud-based, distributed software platforms.

Technical Skills: Application Security - Secure design, secure coding principles, API security, authentication, authorization, session management, input validation, dependency risk, and data protection.

Cloud and platform security - Cloud security principles, network segmentation, workload identity, secrets management, container security, infrastructure-as-code security, and least-privilege design.

DevSecOps - Security integration with CI/CD pipelines, automated controls, security gates, vulnerability triage, build/release enforcement, and developer feedback loops.

Architecture and governance - Reference architectures, design review practices, risk-based decisions, policy creation, reusable patterns, exception handling, and architecture guardrails.

Tooling familiarity Experience - with tools such as GitHub Advanced Security, SonarQube, Snyk, Datadog, Azure Defender/Security Center, vulnerability scanners, container scanners, or equivalent platforms., * Bachelor’s degree in Computer Science, Cybersecurity, Software Engineering, or a related field, or equivalent professional experience.

  • 8+ years of experience in software engineering, platform engineering, application security, cloud security, or security architecture.
  • 3+ years in a security-focused technical leadership or architecture role.
  • Demonstrated experience securing cloud-native applications, distributed systems, APIs, and CI/CD delivery models.
  • Hands-on experience with secure SDLC practices, threat modeling, vulnerability management, and engineering remediation workflows.
  • Ability to influence architects, engineers, and leaders through practical guidance, clear tradeoff analysis, and collaborative problem solving.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:37 min

Executing verified publishing workflows on Sonatype Maven Central

Johan Hutting Johan Hutting · WWC 2024

5:34 min

Managing token budgets and enterprise usage of coding agents

Chris Heilmann +2 · LIVE

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · WWC 2023

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:44 min

Integrating static security scanning in the build phase

Milecia Mcgregor · LIVE

1:08 min

Analyzing error logs and root causes using artificial intelligence

Nishil Patel Nishil Patel · WWC 2025

Videos

See all

Related articles

See all