> Markdown version of [/jobs/ext/3345708-cyber-security-architect](https://www.wearedevelopers.com/jobs/ext/3345708-cyber-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Architect - **Company:** Goldenpick Technologies - **Location:** New York, NY, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Microsoft Windows, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Architectural Patterns, Microsoft Azure, Cloud Computing Security, Cloud Engineering, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Continuous Integration, Information Leak Prevention, Data Security, Linux, Disaster Recovery, Github, Identity and Access Management, Intrusion Detection Systems, Virtual Private Networks (VPN), Information Systems Security Architecture Professional, Python (Programming Language), Key Management, Network Security, OAuth, OpenID, Open Web Application Security, PCI Data Security Standards, Windows PowerShell, Role-Based Access Control, Openid Connect, Zero Trust Network Access, JSON Web Token, Sherwood Applied Business Security Architecture, Security Assertion Markup Language (SAML), Secure Coding, Security Information and Event Management, Systems Integration, Tokenization, Virtualization Technology, Privacy Controls, Data Logging, Google Cloud, Enterprise Software Applications, Data Classification, In-Plane Switching (IPS), DevOps Tools - Open-source, Large Language Models, Software Security, Mitre Att&ck, Firewalls (Computer Science), Gitlab-ci, Kubernetes, Data Management, CIS Benchmarks, Terraform, Devsecops, Serverless Computing, Docker, Security Orchestration, Automation & Response, Jenkins, Static Application Security Testing, Vulnerability Analysis, Microservices, Dynamic Application Security Testing - **Published:** September 2, 2026 - **Apply:** https://www.dice.com/job-detail/bbbe6763-91bc-4e63-b2d6-5586545df3ed ## About the Role * 8-12 years of experience in cybersecurity, information security, infrastructure security, cloud security, or security architecture. * 3+ years of experience designing and reviewing enterprise security architectures. * Strong knowledge of network security, application security, cloud security, IAM, cryptography, and security operations. * Experience with threat modelling frameworks such as STRIDE, MITRE ATT&CK, or equivalent methodologies. * Strong understanding of security principles including least privilege, zero trust, defense in depth, secure-by-design, and separation of duties. * Experience conducting security risk assessments and developing risk-treatment plans. * Hands-on knowledge of security controls, vulnerabilities, penetration testing, incident response, and disaster recovery. * Experience working with architecture frameworks, security policies, control standards, and governance processes. * Strong communication skills, with the ability to explain complex security risks to technical and business stakeholders. * Demonstrated ability to influence engineering teams and drive security improvements across projects. Preferred qualifications * Experience securing AWS, Azure, or Google Cloud environments. * Knowledge of Kubernetes, containers, service meshes, serverless systems, and cloud-native architectures. * Experience with DevSecOps tools, CI/CD security, SAST, DAST, SCA, IaC scanning, secrets scanning, and container security. * Familiarity with SIEM, SOAR, EDR, XDR, WAF, CSPM, CNAPP, DLP, and vulnerability-management platforms. * Experience with API security, microservices security, OAuth 2.0, OpenID Connect, SAML, and JWT. * Knowledge of data classification, encryption, tokenization, key management, and privacy engineering. * Experience with security automation using Python, PowerShell, Terraform, or similar tools. * Familiarity with AI/ML security, LLM application security, prompt injection, data leakage, and model governance. * Experience with regulatory and security frameworks such as NIST CSF, NIST SP 800-53, CIS Controls, ISO 27001, SABSA, COBIT, and OWASP. * Professional certifications such as CISSP, CCSP, SABSA, CISM, GIAC, AWS Security Specialty, or Azure Security Engineer. Technical skills ## Description * Define and maintain the organization's cybersecurity strategy, principles, standards, and reference architectures. * Design secure architectures for enterprise applications, networks, cloud platforms, APIs, data platforms, and infrastructure. * Translate business, regulatory, and technical requirements into security controls and architecture patterns. * Conduct threat modelling, attack-surface analysis, security risk assessments, and architecture reviews. * Identify vulnerabilities, design gaps, single points of failure, and risks introduced by new technologies or system integrations. * Define security controls for confidentiality, integrity, availability, authentication, authorization, monitoring, and data protection. * Establish defense-in-depth strategies covering identity, network, endpoint, application, data, and cloud security. * Review solution designs, technical specifications, infrastructure-as-code, and implementation plans for security compliance. * Guide development and engineering teams in secure design, secure coding, DevSecOps, and security testing practices. * Design and govern identity and access management solutions, including SSO, MFA, RBAC, ABAC, PAM, and zero-trust controls. * Define security requirements for firewalls, WAF, VPN, IDS/IPS, SIEM, EDR, DLP, secrets management, and endpoint protection. * Develop cloud-security architectures for AWS, Azure, or Google Cloud environments. * Establish security logging, monitoring, alerting, detection, and incident-response requirements. * Support vulnerability assessments, penetration testing, configuration reviews, and remediation planning. * Assist incident-response and business-continuity teams during major security events. * Evaluate security products, technologies, vendors, and managed security services. * Maintain security architecture documentation, standards, diagrams, risk registers, and control mappings. * Support audits and compliance initiatives involving ISO 27001, SOC 2, PCI DSS, GDPR, HIPAA, or applicable regulatory frameworks. * Track changes in the threat landscape and update security controls and architecture accordingly.coursera+2, AWS, Azure, Google Cloud Platform, IAM, KMS, GuardDuty, Defender, Security Command Center Network security Firewalls, WAF, VPN, IDS/IPS, segmentation, NAC, zero trust Identity security SSO, MFA, RBAC, ABAC, PAM, OAuth 2.0, OIDC, SAML Security operations SIEM, SOAR, EDR, XDR, SOC processes, incident response Application security OWASP, API security, SAST, DAST, SCA, threat modelling DevSecOps Jenkins, GitHub Actions, GitLab CI, Terraform scanning, container security Infrastructure Kubernetes, Docker, Linux, Windows, virtualization, service meshes Data security Encryption, DLP, tokenization, secrets management, key management Governance ISO 27001, NIST, CIS Controls, SOC 2, PCI DSS, GDPR