Senior Information Security Architect

American Credit Acceptance
Meridian, ID, United States
23 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Microsoft Azure Burp Suite Cloud Computing Security Cyber Security DevOps Identity and Access Management Information Systems Security Architecture Professional Network Security PCI Data Security Standards Systems Development Life Cycle Fortify (Software)
+9 more
Secure Coding Software Engineering Data Logging Software Security Veracode HybridCloud Hardware Infrastructure Static Application Security Testing Dynamic Application Security Testing

Job description

American Credit Acceptance (ACA) is seeking a highly experienced and strategic Principal Security Architect to lead the design and implementation of secure architectures across our hybrid environment, including on-premise infrastructure, AWS, and Azure cloud platforms. This role will be pivotal in shaping our enterprise security posture, driving secure software development practices, and ensuring compliance with industry standards and regulatory requirements., * Design and maintain enterprise-wide security architecture frameworks that support business objectives and risk management strategies.

  • Lead the development of security reference architectures for cloud (AWS, Azure) and on-premise environments.

Application Security

  • Define and enforce secure coding standards and practices across development teams.
  • Oversee the implementation and integration of DAST (Dynamic Application Security Testing) and SAST (Static Application Security Testing) tools into CI/CD pipelines.
  • Collaborate with DevOps and engineering teams to embed security into the software development lifecycle (SDLC).

Cloud Security

  • Architect and implement security controls for AWS and Azure environments, including IAM, encryption, logging, and monitoring.
  • Evaluate and integrate cloud-native security services (e.g., AWS Security Hub, Azure Defender).

On-Premise Security

  • Ensure legacy and hybrid systems are aligned with modern security standards.
  • Lead risk assessments and remediation strategies for on-premise infrastructure.

Governance, Risk & Compliance

  • Align security architecture with NIST, ISO 27001, and other relevant frameworks.
  • Support internal and external audits, and ensure compliance with regulatory requirements (e.g., SOX, HIPAA, PCI-DSS).

Collaboration & Leadership

  • Serve as a trusted advisor to executive leadership on security strategy and risk.
  • Mentor junior architects and security engineers, fostering a culture of security-first thinking.

Requirements

  • 10+ years of experience in cybersecurity, with at least 5 years in a security architecture role.
  • Deep expertise in application security, including hands-on experience with DAST and SAST tools (e.g., Veracode, Fortify, Burp Suite).
  • Proven experience designing secure architectures in AWS and Azure environments.
  • Strong understanding of network security, identity and access management, encryption, and threat modeling.
  • Familiarity with on-premise infrastructure and hybrid cloud models.
  • Certifications such as CISSP, CCSP, AWS Certified Security - Specialty, or Azure Security Engineer Associate are highly desirable.

Preferred Attributes

  • Excellent communication and stakeholder management skills.
  • Ability to translate complex security concepts into business-friendly language.
  • Experience working in regulated industries or with compliance-heavy environments.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

4:36 min

Exploiting e-commerce basket identifiers with Burp Suite

Anna Bacher · LIVE

3:15 min

Correlating OpenSSF scorecard metrics with real vulnerability data

Niels Tanis Niels Tanis · World Congress 2024

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

Videos

See all

Related articles

See all