Security Engineer / Architect
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+47 more
Job description
Amynta is seeking a skilled Security Engineer / Architect to join our infrastructure team. This role is focused on strengthening the security of our systems, applications, and infrastructure as we navigate ever-changing threats in today’s environment. In this position, you will partner with IT Security, Application Development, and engineering teams to implement and maintain security controls throughout our environment. Key ResponsibilitiesCloud Security
- Implement and enforce security controls in cloud environments (AWS, Azure, and/or GCP).
- Review and harden cloud configurations, governance, IAM policies, and resource permissions.
- Monitor cloud environments using CSPM tools and respond to misconfigurations and alerts.
- Support secure architecture design for cloud-native and hybrid workloads.
Network Security
- Provide oversight and architectural guidance for firewalls, IDS/IPS systems, VPNs, and network segmentation controls.
- Review and approve firewall rules, network policies, and security device configurations to ensure alignment with security standards.
- Conduct regular vulnerability assessments on network infrastructure and oversee remediation by relevant teams.
- Define and enforce network access control policies and zero-trust principles across the organization.
Application Security
- Champion and enforce secure development practices, ensuring development teams adhere to security principles throughout the SDLC.
- Define and maintain application security standards, policies, and guidelines for development teams to follow.
- Conduct periodic application security assessments and coordinate with teams on risk prioritization.
Infrastructure Security
-
Primary owner for execution of infrastructure remediation workstreams (patching/hardening/logging changes) and maintaining delivery cadence. *
- Own the external-facing findings workflow end-to-end (triage ticketing change control validation) under Infrastructure leadership working with IT Security team.
- Harden on-premises servers, endpoints, and critical services (e.g., Active Directory, Exchange, DNS).
- Track the existing patch management processes and ensure we are compliant.
- Evaluate security control around AI usage.
- Oversee data and SQL security practices, ensuring proper access controls, query validation, and protection against injection attacks and unauthorized data exposure.
- Build/maintain infra security standards/runbooks for Infrastructure teams and ensure ongoing compliance.
Requirements
- 3-5 years of experience in an information security or security engineering role.
- Hands-on experience with network security tools (firewalls, IDS/IPS, VPN, network monitoring).
- Familiarity with application security practices, OWASP Top 10, and common vulnerability types.
- Experience securing cloud environments in AWS, Azure, or GCP.
- Working knowledge of Windows and Linux system hardening and administration.
- Experience with SIEM platforms and log analysis (e.g., Splunk, Microsoft Sentinel, Elastic).
- Strong understanding of authentication protocols, TLS/SSL, PKI, and access management.
- Ability to communicate security risks clearly to both technical and non-technical audiences.
Preferred
- Relevant certifications such as Security+, CEH, OSCP, AWS Security Specialty, or CISSP (Associate).
- Experience with DevSecOps and embedding security into CI/CD pipelines.
- Familiarity with compliance frameworks such as NIST CSF, ISO 27001, SOC 2, or CIS Benchmarks.
- Scripting or automation skills in Python, PowerShell, or Bash.
- Experience with endpoint detection and response (EDR) tools.
Compensation Range: $110,000 - $145,000 and will depend on several factors including relevant experience, skills and knowledge pertaining to this role and industry., Access Control, Amazon Web Services (AWS), Analysis Skills, Applications Security, Architectural Design, Architectural Services, Artificial Intelligence (AI), Authentication, Bash Scripting, Benchmarking, CISSP - Certified Information Systems Security Professional, Cadence, Change Control, Cloud Architecture, Cloud Computing, Communication Skills, CompTIA Security+, Computer Security, Continuous Deployment/Delivery, Continuous Integration, DNS (Domain Name System), Environmental Monitoring, Equal Employment Opportunity (EEO), Establish Priorities, Firewalls, GCP (Good Clinical Practices), ISO (International Organization for Standardization), Information/Data Security (InfoSec), Injections, Intrusion Detection Systems, Intrusion Prevention Systems, Leadership, Linux Administration, Maintain Compliance, Microsoft Active Directory, Microsoft Exchange Server, Microsoft Product Family, Microsoft Windows Azure, Microsoft Windows Operating System, Network Access Control (NAC), Network Administration/Management, Network Monitoring, Network Performance/Analysis, Network Security, Public Key Infrastructure (PKI), Python Programming/Scripting Language, Risk, SQL (Structured Query Language), SSL-TLS (Secure Socket Layer - Transport Layer Security), Scripting (Scripting Languages), Security Analysis, Security Architecture, Security Information and Event Management (SIEM), Software Administration, Software Development Lifecycle (SDLC), Software Patches, Splunk, Team Player, U.S. National Institute of Standards and Technology (NIST), VPN (Virtual Private Network), Windows PowerShell
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.careerbuilder.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
The 12 Best Jobs for Software Engineers
9 Ways to Make Money Hacking
Top-Paying Tech Jobs (with Salaries)
The Most Popular IT Jobs on the Market