> Markdown version of [/jobs/ext/2696849-security-architect-product-security](https://www.wearedevelopers.com/jobs/ext/2696849-security-architect-product-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Architect, Product Security - **Company:** Humana Inc. - **Location:** Nashville, TN, United States (Remote available) - **Experience:** Experienced - **Salary:** $89,000.0 - $121,400.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Cloud Computing Security, Cyber Security, Internet Services, Open Source Technology, Systems Development Life Cycle, Software Engineering, Software Vulnerability Management, Enterprise Software Applications, Software Security, GWAPT, Information Technology, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 3, 2026 - **Apply:** https://dejobs.org/x/x/C7F21753659148CDA57CFCEB19FA55BF/job/ ## About the Role This position is ideal for professionals with approximately 2-5 years of cybersecurity, application security, product security, or related security architecture experience who are looking to expand their expertise within a large enterprise environment. The successful candidate will have experience analyzing vulnerabilities, assessing risk, communicating remediation recommendations, and partnering with technical teams throughout the Software Development Life Cycle (SDLC)., * 2-5 years of relevant cybersecurity, application security, information security, product security, or security architecture experience. * Practical experience analyzing vulnerabilities and evaluating security risk. * Ability to provide clear, actionable remediation guidance to technical teams. * Working knowledge of: * Static Application Security Testing (SAST) * Software Composition Analysis (SCA) * Secrets Scanning * Secure SDLC practices * Understanding of common application security and software security concepts. * Strong critical thinking, problem-solving, and analytical skills. * Demonstrated collaboration and communication skills, including the ability to work effectively with software engineers, architects, and security professionals. * Bachelor's degree preferred; equivalent combination of education and relevant experience will be considered. Preferred Qualifications * Experience with enterprise security tooling and vulnerability management workflows. * Experience supporting application security, product security, cybersecurity, or information security programs. * Experience with cloud security, container security, API security, DAST, or SaaS security platforms. * Experience creating documentation, technical guidance, playbooks, or operational processes. * Experience mentoring junior analysts or supporting team development initiatives. * Security certification such as Security+, CISSP, CSSLP, GSEC, GWAPT, or similar. * Bachelor's or Master's degree in Computer Science, Cybersecurity, Information Security, Information Technology, or related technical field. * Experience working within regulated industries such as healthcare, finance, or insurance. ## Description The Security Architect II supports Humana's Product Security program by partnering with engineering, architecture, and security teams to identify and address security risks across enterprise applications. This role analyzes security findings, provides risk-based remediation guidance, and helps drive secure development practices while building expertise in product security and security architecture., The Security Architect II supports Humana's Product Security program by helping identify, assess, and reduce security risk across enterprise applications and technology solutions. Working closely with software engineering, architecture, and security teams, this role serves as a security subject matter expert supporting vulnerability triage, secure software development practices, and security consultation efforts., * Serve as a Level 2 Security SME supporting Product Security Scan & Triage activities. * Analyze, investigate, and adjudicate complex vulnerability findings and security tool results. * Assess security risk and provide practical, risk-based remediation guidance to engineering teams. * Support secure software development lifecycle (SDLC) practices across enterprise technology initiatives. * Support static application security testing (SAST), software composition analysis (SCA), secrets detection, and open-source/package security activities. * Partner with development teams to review security findings and improve application security posture. * Participate in security exception and risk acceptance workflows. * Assist with the development and improvement of runbooks, knowledge articles, escalation criteria, and operational processes. * Collaborate with cybersecurity, information security, architecture, and technology teams to address application security risks and improve security outcomes., To ensure Home or Hybrid Home/Office employees' ability to work effectively, the self-provided internet service of Home or Hybrid Home/Office employees must meet the following criteria: * At minimum, a download speed of 25 Mbps and an upload speed of 10 Mbps is required; wireless, wired cable or DSL connection is suggested. * Satellite, cellular and microwave connection can be used only if approved by leadership. * Employees who live and work from Home in the state of California, Illinois, Montana, or South Dakota will be provided a bi-weekly payment for their internet expense. * Humana will provide Home or Hybrid Home/Office employees with telephone equipment appropriate to meet the business requirements for their position/job. * Work from a dedicated space lacking ongoing interruptions to protect member PHI / HIPAA information. ## Related Videos - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)