> Markdown version of [/jobs/ext/580241-cybersecurity-architect-threat-and-vulnerability-management](https://www.wearedevelopers.com/jobs/ext/580241-cybersecurity-architect-threat-and-vulnerability-management). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Architect - Threat and Vulnerability Management - **Company:** Creative Artists Agency - **Location:** Nashville, TN, United States - **Experience:** Experienced - **Salary:** $179,000.0 - $205,000.0 - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Application Programming Interfaces (APIs), Amazon Web Services, Architectural Patterns, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, Cloud Engineering, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Distributed Systems, Infrastructure as a Service (IaaS), Internet Security, Intrusion Detection and Prevention, Python (Programming Language), Network Security, OAuth, Open Web Application Security, Windows PowerShell, Red Team (Cyber Security), Zero Trust Network Access, Security Information and Event Management, Software Engineering, Data Logging, Mitre Att&ck, Cyber Threat Analysis, Information Technology, Integration Frameworks, Purple Team (Cyber Security), Network Server, Serverless Computing, Blue Team (Cyber Security), Security Orchestration, Automation & Response, Vulnerability Analysis, Microservices - **Published:** June 17, 2026 - **Apply:** https://caa.wd1.myworkdayjobs.com/Careers/job/Nashville-TN/Cybersecurity-Architect---Threat-and-Vulnerability-Management_JR8928 ## About the Role * Bachelor's degree in Cybersecurity, Computer Science, or related experience * 7+ years of experience in cybersecurity, with at least 2-3 years in architecture or senior engineering roles * Hands on experience in Cyber Threat and Offensive Security operations to test and validate the effective operation of security controls, measuring the ability to stop threats and attacks at the earliest point in the kill chain * Strong knowledge of network security, cloud security (AWS/Azure/GCP), and enterprise architectures * Strong understanding of the fundamental operations of servers, operating systems, networks, cloud applications and infrastructure along with an advanced understanding of the key controls required for secure operation of these systems * Experience scripting in at least one of the following languages: PowerShell, Python, JavaScript * Experience in aligning threat and vulnerability management efforts to frameworks and control objectives - MITRE ATT&CK, NIST CSF, ISO27001, Center for Internet Security, OWASP, * Experience integrating the following tools and capabilities into a successful threat and vulnerability program - Security Orchestration Automation and Response, Security Information and Event Management, Vulnerability Scanning, Security Threat Feeds, Red Team Tooling * Knowledge of Zero Trust architecture and modern identity security practices ## Description * We are seeking a strategic and hands-on Cybersecurity Architect to join our Purple Team, responsible for designing, validating, and continuously evolving enterprise security architecture in alignment with real-world adversarial threats. This role operates at the intersection of offensive and defensive security, leveraging Red Team insights and Blue Team capabilities to ensure systems are secure by design, resilient by default, and continuously tested against emerging attack techniques. * As a key leader in our security organization, the Cybersecurity Architect will drive the development of secure design principles, reference architectures, and security standards across a modern, SaaS-enabled and cloud-first ecosystem. This includes securing complex identity flows, third-party integrations, APIs, and distributed systems while addressing the shared responsibility model inherent in SaaS platforms. * The ideal candidate brings a deep understanding of attacker methodologies and defensive controls, applying that knowledge to proactively identify architectural weaknesses, reduce attack surface, and enhance detection and response capabilities. This individual will work closely with engineering, cloud, and product teams to embed security into the software development lifecycle, ensuring that security is not an afterthought but a foundational component of system design. * This role requires a balance of technical depth and strategic influence, with responsibility for translating complex threats into actionable architectural improvements and guiding the organization toward Zero Trust and secure-by-design maturity. Success in this position will be measured by the organization's ability to prevent, detect, and respond to sophisticated threats, as well as by the strength and scalability of its security architecture across both enterprise and SaaS environments. Responsibilities * Design and evolve enterprise security architecture with a strong emphasis on secure-by-design principles, ensuring security is embedded early in system and application lifecycles * Lead the development and adoption of secure design patterns and reference architectures, particularly for cloud-native and SaaS-based environments * Act as a key liaison between Red Team and Blue Team, translating adversarial findings into architectural improvements, detection use cases, and resilient system designs * Plan and execute Purple Team exercises to validate security controls across infrastructure, applications, and SaaS platforms, ensuring visibility and response capabilities are effective * Develop and maintain threat models for critical systems, including SaaS integrations, APIs, and identity flows, identifying attack paths and prioritizing mitigations * Define and enforce security architecture standards for SaaS adoption * Assess and secure SaaS ecosystems, including third-party integrations, OAuth applications, and API exposure risks * Evaluate and recommend controls for modern architectures, including Zero Trust, microservices, containers, and serverless environments * Drive improvements in detection engineering by mapping adversary TTPs (e.g., via MITRE ATT&CK) to logging, alerting, and response capabilities * Collaborate with cloud and platform teams to ensure secure configuration and continuous compliance across SaaS and IaaS environments * Conduct architecture risk assessments and provide actionable remediation strategies aligned with business risk tolerance * Promote security observability across SaaS platforms by ensuring proper logging, telemetry, and integration with SIEM/SOAR solutions * Mentor engineers and architects on secure design principles, SaaS security risks, and adversarial thinking ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Build Delightful Mobile Experiences with Kotlin, Realm, and Atlas Device Sync](https://www.wearedevelopers.com/videos/694-build-delightful-mobile-experiences-with-kotlin-realm-and-atlas-device-sync) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)