See all roles

DevSecOps Security Architect (Remote)

Work from home Full-time role Hiring

DevSecOps Security Architect (Remote) 130k-160k, target bonus of 12.5%

  • * can be based anywhere in the US EXCEPT California and be 100% remote, we will also consider candidates who need to be sponsored. If the candidates are based in Chicago, they will need to adhere to our hybrid environment.

For our bonuses, the percentage I provided is a target range and based on performance. If a candidate is performing well in the role, they can expect their bonus to be higher than that target range.

  • Medical, dental and vision insurance
  • Retirement program (401k and Pension)
  • Generous PTO plan
  • 11 paid holidays per year
  • Hybrid working model (effective February 22, 2022)
  • Casual dress code

Duties:

  • Serve as security authority for IT on the Modern Engineering solutions; responsible for developing "security first" strategy and evangelizing cloud and application security best practices
  • Serve as subject matter expert for security and tooling landscape; stay current on market trends and research
  • Design and implement architecture of security solutions in accordance with IT strategy and leading practices from industry including AWS Well-Architected Framework
  • Work directly with business and IT technology owners to understand security requirements, complexities, and implementation strategies
  • Define, develop, and validate RBAC security configurations when applicable to Modern Engineering platforms and environments
  • Consult with all levels of the organization, including executive leadership, to provide direction for security practices and controls; this includes areas of application security, cloud security, DevOps, compliance, and organizational strategy
  • Engage and consult with other Security leadership including Information Security, Security Advisory & Analytics, and IT Risk & Compliance to define Security Standards and Procedures and integrate security considerations within the software development lifecycle
  • Define, review, and implement Modern Engineering cloud-specific Security Standards, Procedures, and Guidelines
  • Engage and consult with the CoE and IT Delivery Teams to review their architecture and security checkpoints, perform gap analyses, implement proof-of-concepts, present findings and recommendations, and automate implementation
  • Consult on application development projects to assess security requirements and controls, and to ensure that security controls are implemented as planned
  • Evaluate the benefits and risks of a solution's security posture and identify implementation strategies to enhance security posture
  • Review and approve Modern Engineering architecture and designs for security posture; to enforce security requirements and address identified risks
  • Provide oversight and management of audit finding remediation, including generating requirements for full remediation, providing feedback and suggestions on managerial responses to findings, tracking progress, and providing status and updates to the enterprise Risk team for reporting purposes
  • Participate in evaluating security requirements of third-party tools or SaaS Solutions
  • Consult on and evangelize the behavior change and mindset shifts required of people resources to implement new architecture and processes
  • Partner with other CoE members and HR to account for effort associated with culture change as part of implementation strategies
  • Model desired culture including open knowledge sharing, proactive cross-functional collaboration, and adaptive learning via continuous improvement
  • Educate stakeholders from the business and IT on security solutions and how to best leverage the Modern Engineering solutions and processes to enhance the security posture
  • Develop project case studies, training materials and technical guidance on how to "shift left" on security implementation for teams within the company
  • Assist with estimating work efforts required for each phase of a project
  • Lead and coordinate technical reviews (architectural, security, compliance, etc.)
  • Implement key performance indicators (KPI) to monitor process health and service metrics

Requirements:

  • Bachelor's Degree or equivalent experience required. Computer Science, Computer Information Systems or related field preferred
  • Certification from leading vulnerability management frameworks (e.g., SANS, CISSP, OSCP) preferred
  • 10+ years of security experience including implementation of security controls for applications, cloud, and/or DevOps
  • 5+ years of software engineering experience required
  • Audit, compliance, and governance experience preferred
  • Knowledge of and experience in developing and documenting security architecture and plans, including strategic, tactical and project plans
  • Knowledge of common information security management frameworks, such as ITIL and COBIT frameworks
  • In-depth knowledge of risk assessment methods and technologies
  • In-depth knowledge and understanding of information risk concepts and principles, as a means of relating business needs to security controls
  • Skilled in performing risk, business impact, control, and vulnerability assessments

Knowledge, Skills, Abilities and Behaviors:

  • Proven experience with AWS cloud security best practices (e.g., IAM, WAF, KMS)
  • Subject matter expertise in security domains, with knowledge pertaining to the majority of these topics: AppSec (OWASP Top10, SANS Top 25), Defense-in-depth, Risk assessment and management, Network topology and security, Network Infrastructure - securing network devices, Network protocols, Virtualization, Intrusion Detection, Intrusion Prevention, Logging, SIEM, Social Engineering, Security policy related to business continuity planning and contingency planning, Incident handling process, Opsec, Data classification, DRM, Pentesting, Vulnerability Analysis, Secure communications including encryption and cipher suites, Linux and Windows security
  • Strong analytical skills to analyze security requirements and relate them to appropriate security controls
  • Experience in performing web application and infrastructure penetration security test and threat modeling
  • Experience collaborating across multiple functional/technical teams to deliver a project
  • Ability to communicate with customers on a business level and translate their needs into a technical solution
  • Ability to adapt to organizational change and advocate for the required culture change within the organization
  • Strong emotional intelligence to identify the behavioral and cultural indicators to team effectiveness
  • Consultative, collaborative approach to solving complex problems, with customer service skills
  • Passionate about developing the skills of team members through technical and professional mentoring
  • Capable of leading by role or influence, as well as working independently
  • Strong communications skills, both oral and written, appropriate for a broad range including business stakeholders and end users, executive leadership, and third-party vendors
  • Demonstrated growth mindset, enthusiastic about learning new technologies quickly and applying the gained knowledge to address business problems
  • Self-starter; ability to proactively define work and deliver results

Company requires all employees, except those who may require accommodations under federal or state civil rights laws, to be fully vaccinated. ABBTECH is an EOE/Minorities/Women/Disabled Individuals/Veterans Apply tot his job Apply To this Job

You might like

Experienced Associate Merchant for Walmart Seasonal Jobs 2023 – Full-Time Opportunity with Competitive Salary and Benefits

Work from home Full-time role

Radio Promotions Assistant (Part-Time/Seasonal)

Work from home Full-time role

Retail Stocking Associate; Seasonal

Work from home Full-time role

Software Engineer, Security Assurance | US | Remote

Work from home Full-time role

Seasonal Sales Associate-8067 Lawrenceville, NJ 08648

Work from home Full-time role

Professional Services Security Architect

Work from home Full-time role

Lead Security Architect (Director level, individual contributor)

Work from home Full-time role

Senior Product Security Architect - Remote

Work from home Full-time role

GRC Consultant

Work from home Full-time role

Lead IT Compliance Analyst (remote)

Work from home Full-time role

Experienced Junior Data Entry Operator – Entry-Level Position for 17-Year-Olds with Strong Typing Skills and Attention to Detail

Work from home Full-time role

Outreach Representative

Work from home Full-time role

Remote Medical Transcriptionist / Medical Scribe

Work from home Full-time role

Manager, Training and Education Operations

Work from home Full-time role

Remote Data Entry Clerk – High‑Accuracy Typing Specialist for arenaflex Logistics Operations (Work‑From‑Home)

Work from home Full-time role

Experienced Data Entry Specialist – Entry-Level Opportunity for Career Growth at blithequark

Work from home Full-time role

Clinical Registrar - Tumor Registry - Remote

Work from home Full-time role

Teacher, Virtual Launchpad Biology

Work from home Full-time role

Chat Support Agent - Entry Level, No Degree Required - 15

Work from home Full-time role

Junior Underwriter

Work from home Full-time role