> Markdown version of [/jobs/ext/2097296-security-architect](https://www.wearedevelopers.com/jobs/ext/2097296-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Architect - **Company:** Informa USA Inc - **Location:** Newton, MA, United States (Remote available) - **Experience:** Expert - **Salary:** $175,000.0 - $200,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Agile Methodology, Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Unix, Cloud Computing, Cloud Computing Security, Control Objectives for Information and Related Technology (COBIT), Cyber Security, DevOps, Identity and Access Management, Key Management, Network Security, Network Configuration and Change Management, Open Web Application Security, Software Architecture, Systems Development Life Cycle, Cloud Services, Zero Trust Network Access, Web Application Security, Information Technology Security Auditing, Security Information and Event Management, Software Engineering, Tripwire, Software Vulnerability Management, Web Applications, Data Logging, Large Language Models, Multi-Cloud, Amazon Virtual Private Cloud (VPC), Containerization, Information Technology, Cybercrime, Devsecops, Docker, Vulnerability Analysis - **Published:** August 17, 2026 - **Apply:** https://jobs.smartrecruiters.com/InformaGroupPlc/744000143863995-security-architect ## About the Role * Bachelor's or master's degree in computer science, information technology or a related field * 7+ years of cybersecurity experience with deep cloud security expertise * Proven track record leading enterprise security architecture in multi-cloud environments * Deep understanding of cloud service provider security best practices around (AWS, GCP) + Organization Policies + Automated threat detection tools + Central logging/Siem practices + Lest privilege architecture + VPC design/perimeter controls + Data Exfiltration prevention + Encryption/Key Management design + Identity and Access Management (IAM) best practices. * Web application security testing: Expertise in identifying and mitigating vulnerabilities in web applications, leveraging tools and methodologies like OWASP. * Network vulnerability scanning: Skilled in detecting and addressing vulnerabilities in network configurations and infrastructure. * Container and Kubernetes security: Proficiency in securing containerized environments, including Docker and Kubernetes, using best practices and tools like Trivy or Aqua Security. * Experience with security testing tools and platforms: Familiarity with industry-standard tools for vulnerability scanning, penetration testing, and security auditing. * Ability to lead security discussions with system architects and business leaders. * Strong analytical and computer skills Expert level understanding of cybersecurity and how it affects the modern business world. * Thorough understanding of Unix operation systems * Awareness of frameworks such as NIST, COBIT, ISO and Soc2 * Certifications: CISSP, CCSP, AWS Security Specialty, or Google Professional Cloud Security Engineer ## Description We are seeking a strategic Security Architect to define and drive our cloud and enterprise security architecture. You will own the security architecture vision, establish governance frameworks, and partner with Product, Engineering, and Infrastructure teams to embed security throughout our technology ecosystem. Core Responsibilities * Strategic Architecture & Governance * Own and evolve the enterprise security architecture, including long-term roadmap and reference architectures for cloud, hybrid, and on-premises environments * Define organizational security principles, frameworks, and standards that align with business objectives and regulatory requirements * Develop and present security strategy, roadmaps, and strategic initiatives to executive leadership and stakeholders * Establish security metrics and KPIs to measure architecture effectiveness and communicate security posture to senior leadership * Ensure compliance with industry regulations and standards including ISO 27001, SOC 2, GDPR, and SOX * Lead security audits and assessments, driving remediation plans and continuous improvement initiative Cloud & Infrastructure Security * Own cloud security architecture across AWS and GCP, including Cloud Security Posture Management (CSPM), Cloud Infrastructure Entitlement Management (CIEM), and Wiz remediation strategies * Design and implement Identity and Access Management (IAM) architecture based on least privilege principles and Zero Trust security models * Architect secure network segmentation strategies and defense-in-depth controls across all infrastructure layers * Own the architecture and strategic direction for key security platforms including SIEM, vulnerability management, endpoint security, and threat detection systems * Manage and optimize internal security platforms to ensure robust protection of organizational assets * Design secure cloud infrastructures and hybrid environment protections that scale with business growth * Conduct threat modeling and risk analyses to identify infrastructure vulnerabilities and recommend mitigation strategies Application & Development Security * Lead Secure Software Development Lifecycle (SDLC) and DevSecOps initiatives across the organization * Integrate security controls into CI/CD pipelines, championing shift-left security practices in collaboration with DevOps leadership * Ensure software architecture and applications are designed to mitigate vulnerabilities and prevent exploits * Provide technical guidance and mentorship to development and DevOps teams on secure coding practices and emerging threats * Collaborate with cross-functional teams to embed security throughout the system development lifecycle * Define security requirements and controls that support agile development while maintaining strong security posture Innovation & Technical Leadership * Lead security architecture for emerging technologies including AI/LLM initiatives, ensuring responsible and secure implementation * Serve as the technical authority on security architecture, advising on security-related technologies and assessing risks associated with proposed changes * Stay current with emerging security threats, vulnerabilities, and technologies to drive continuous innovation in security practices * Inspire and influence engineering teams to execute security principles and adopt security-first mindsets * Mentor and provide technical guidance to DevOps, operations, and development teams on security best practices * Partner strategically with Product, Engineering, and Infrastructure leaders to align security architecture with business innovation * Drive thought leadership through security documentation, architecture diagrams, design specifications, and security control matrices Additional Responsibilities * Lead incident response management and develop security policies that protect organizational assets from cyber threats * Identify organizational vulnerabilities and weaknesses through systematic security assessments * Recommend and implement security controls and solutions that balance security requirements with business enablement ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [WeAreDevelopers LIVE - Node and Package Security](https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)