Security Engineer / Architect

Amynta Group
United States
6 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$110,000.0 - $145,000.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Active Directory Artificial Intelligence Amazon Web Services User Authentication Authentication Protocols Microsoft Azure Bash Shell Cloud Computing Cloud Engineering Encodings CompTIA Security+
+47 more
Cyber Security Computer Networks Continuous Delivery Continuous Integration Data Security Linux Domain Name System (DNS) Microsoft Exchange Server Identity and Access Management Intrusion Detection Systems Virtual Private Networks (VPN) Information Systems Security Architecture Professional Python (Programming Language) Network Security Linux System Administration Log Analysis Microsoft Software Network Architecture Network Monitoring Network Segmentation Network Administration Open Web Application Security Public Key Infrastructure Windows PowerShell Systems Development Life Cycle Cadence Virtuoso Zero Trust Network Access Server Administration Service Pack Security Information and Event Management Software Engineering SQL Databases Data Logging Scripting Transport Layer Security Network Access Control Cloud Platform System In-Plane Switching (IPS) Software Security Firewalls (Computer Science) Patch Management Microsoft Sentinel CIS Benchmarks Firewall Services Module Splunk Devsecops Vulnerability Analysis

Job description

Amynta is seeking a skilled Security Engineer / Architect to join our infrastructure team. This role is focused on strengthening the security of our systems, applications, and infrastructure as we navigate ever-changing threats in today’s environment. In this position, you will partner with IT Security, Application Development, and engineering teams to implement and maintain security controls throughout our environment. Key ResponsibilitiesCloud Security

  • Implement and enforce security controls in cloud environments (AWS, Azure, and/or GCP).
  • Review and harden cloud configurations, governance, IAM policies, and resource permissions.
  • Monitor cloud environments using CSPM tools and respond to misconfigurations and alerts.
  • Support secure architecture design for cloud-native and hybrid workloads.

Network Security

  • Provide oversight and architectural guidance for firewalls, IDS/IPS systems, VPNs, and network segmentation controls.
  • Review and approve firewall rules, network policies, and security device configurations to ensure alignment with security standards.
  • Conduct regular vulnerability assessments on network infrastructure and oversee remediation by relevant teams.
  • Define and enforce network access control policies and zero-trust principles across the organization.

Application Security

  • Champion and enforce secure development practices, ensuring development teams adhere to security principles throughout the SDLC.
  • Define and maintain application security standards, policies, and guidelines for development teams to follow.
  • Conduct periodic application security assessments and coordinate with teams on risk prioritization.

Infrastructure Security

  • Primary owner for execution of infrastructure remediation workstreams (patching/hardening/logging changes) and maintaining delivery cadence. *

  • Own the external-facing findings workflow end-to-end (triage ticketing change control validation) under Infrastructure leadership working with IT Security team.
  • Harden on-premises servers, endpoints, and critical services (e.g., Active Directory, Exchange, DNS).
  • Track the existing patch management processes and ensure we are compliant.
  • Evaluate security control around AI usage.
  • Oversee data and SQL security practices, ensuring proper access controls, query validation, and protection against injection attacks and unauthorized data exposure.
  • Build/maintain infra security standards/runbooks for Infrastructure teams and ensure ongoing compliance.

Requirements

  • 3-5 years of experience in an information security or security engineering role.
  • Hands-on experience with network security tools (firewalls, IDS/IPS, VPN, network monitoring).
  • Familiarity with application security practices, OWASP Top 10, and common vulnerability types.
  • Experience securing cloud environments in AWS, Azure, or GCP.
  • Working knowledge of Windows and Linux system hardening and administration.
  • Experience with SIEM platforms and log analysis (e.g., Splunk, Microsoft Sentinel, Elastic).
  • Strong understanding of authentication protocols, TLS/SSL, PKI, and access management.
  • Ability to communicate security risks clearly to both technical and non-technical audiences.

Preferred

  • Relevant certifications such as Security+, CEH, OSCP, AWS Security Specialty, or CISSP (Associate).
  • Experience with DevSecOps and embedding security into CI/CD pipelines.
  • Familiarity with compliance frameworks such as NIST CSF, ISO 27001, SOC 2, or CIS Benchmarks.
  • Scripting or automation skills in Python, PowerShell, or Bash.
  • Experience with endpoint detection and response (EDR) tools.

Compensation Range: $110,000 - $145,000 and will depend on several factors including relevant experience, skills and knowledge pertaining to this role and industry., Access Control, Amazon Web Services (AWS), Analysis Skills, Applications Security, Architectural Design, Architectural Services, Artificial Intelligence (AI), Authentication, Bash Scripting, Benchmarking, CISSP - Certified Information Systems Security Professional, Cadence, Change Control, Cloud Architecture, Cloud Computing, Communication Skills, CompTIA Security+, Computer Security, Continuous Deployment/Delivery, Continuous Integration, DNS (Domain Name System), Environmental Monitoring, Equal Employment Opportunity (EEO), Establish Priorities, Firewalls, GCP (Good Clinical Practices), ISO (International Organization for Standardization), Information/Data Security (InfoSec), Injections, Intrusion Detection Systems, Intrusion Prevention Systems, Leadership, Linux Administration, Maintain Compliance, Microsoft Active Directory, Microsoft Exchange Server, Microsoft Product Family, Microsoft Windows Azure, Microsoft Windows Operating System, Network Access Control (NAC), Network Administration/Management, Network Monitoring, Network Performance/Analysis, Network Security, Public Key Infrastructure (PKI), Python Programming/Scripting Language, Risk, SQL (Structured Query Language), SSL-TLS (Secure Socket Layer - Transport Layer Security), Scripting (Scripting Languages), Security Analysis, Security Architecture, Security Information and Event Management (SIEM), Software Administration, Software Development Lifecycle (SDLC), Software Patches, Splunk, Team Player, U.S. National Institute of Standards and Technology (NIST), VPN (Virtual Private Network), Windows PowerShell

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerbuilder.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

Videos

See all

Related articles

See all