Application Security Analyst / System Security Architect

Visionary Innovative Technology Solutions LLC
New York, NY, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Microsoft Azure Cloud Computing Cloud Computing Security Cyber Security Identity and Access Management Key Management Network Security Open Web Application Security Systems Development Life Cycle Sherwood Applied Business Security Architecture Software Engineering
+5 more
Software Vulnerability Management Google Cloud Software Security Togaf CIS Benchmarks

Job description

This role is ideal for a security professional who can represent Information Security during project planning and implementation, ensuring that security requirements are embedded into new initiatives from inception through deployment., We are seeking an experienced Application Security Analyst / System Security Architect to act as the Information Security representative (proxy) for new business and technology initiatives. The role will be responsible for evaluating security requirements, conducting architecture and risk reviews, ensuring compliance with enterprise security standards, and providing security guidance throughout the project lifecycle., * Serve as the Information Security (IS) representative/proxy for new initiatives, projects, and technology implementations.

  • Participate in project discussions, architecture reviews, and design workshops to identify security risks and required controls.
  • Perform security assessments, threat modeling, and risk analysis for new applications, systems, and infrastructure solutions.
  • Review application and system architectures to ensure alignment with security policies, regulatory requirements, and industry best practices.
  • Provide security recommendations related to authentication, authorization, encryption, network security, and data protection.
  • Partner with business, application development, infrastructure, cloud, and third-party vendors to integrate security requirements early in the project lifecycle.
  • Review security exceptions and recommend risk mitigation strategies.
  • Support governance, risk, and compliance activities, including audit and regulatory requirements.
  • Evaluate cloud and on-premises solutions for security risks and control effectiveness.
  • Track remediation of identified security gaps and vulnerabilities.

Requirements

  • Strong experience in Application Security, Security Architecture, or Information Security Consulting.
  • Experience conducting security architecture reviews, threat modeling, and risk assessments.
  • Knowledge of secure software development practices and application security controls.
  • Understanding of security frameworks such as NIST, ISO 27001, CIS Controls, and OWASP Top 10.
  • Experience with cloud security concepts across AWS, Azure, or Google Cloud Platform.
  • Strong understanding of:

  • Identity and Access Management (IAM)
  • Encryption and Key Management
  • Network Security
  • Secure SDLC
  • Vulnerability Management
  • Third-Party Risk Assessments

Ability to communicate security risks and recommendations to both technical and business stakeholders., * CISSP, CCSP, CISM, SABSA, TOGAF, or equivalent security certifications.

  • Experience in financial services, banking, or highly regulated environments.
  • Familiarity with security governance, regulatory compliance, and audit processes.

Key Competencies

  • Security Architecture Review
  • Application Security
  • Threat Modeling & Risk Assessment
  • Secure Design & Governance
  • Cloud Security
  • Stakeholder Management
  • Security Consulting
  • Compliance & Regulatory Support

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

6:10 min

Unlocking free learning credits via Google Cloud Innovators

Asrar Asrar · WWC 2024

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · WWC 2023

4:42 min

Container hosting options available on Google Cloud Platform

Federico Fregosi · WWC 2022

Videos

See all

Related articles

See all