- Company Name
- Refactor Talent
- Job Title
- Senior Security Architect
- Job Description
-
**Job Title:** Senior Security Architect
**Role Summary:**
Leads the design, implementation, and governance of enterprise security solutions with a focus on application security and DevSecOps. Partners with software development teams to embed security throughout the SDLC and ensures consistent security controls across on‑premises, disaster‑recovery, and cloud environments.
**Expectations:**
- Minimum 8 + years of experience in information security, including extensive work in application security and network security architecture.
- Proven track record of guiding development teams to deliver secure applications.
- Ability to translate business and technical requirements into robust security architectures.
- Strong communication and mentorship skills to serve as a trusted advisor to engineering stakeholders.
**Key Responsibilities:**
- Define and enforce enterprise security policies, standards, and procedures.
- Architect and evaluate security solutions for LAN/WAN, VPN, firewalls, routers, and related network technologies.
- Design, implement, and manage PKI infrastructures, digital signatures, and cryptographic controls.
- Lead application security and DevSecOps initiatives, integrating security tools and processes into CI/CD pipelines.
- Ensure security controls comply with industry standards across on‑prem, DR, and cloud platforms.
- Plan, deploy, test, and maintain security systems and architectures.
- Provide technical leadership, mentoring, and knowledge‑sharing to improve security practices.
- Advise engineering teams on secure design patterns and best practices.
**Required Skills:**
- Deep expertise in application security, threat modeling, secure coding, and vulnerability management.
- Extensive experience with DevSecOps tools (e.g., SAST, DAST, SCA, IaC security).
- Strong knowledge of network security concepts, protocols, and hardware configuration.
- Hands‑on experience designing and operating PKI and cryptographic solutions.
- Proficiency with cloud security frameworks (AWS, Azure, GCP) and hybrid environments.
- Ability to develop and enforce security policies and governance models.
- Excellent analytical, problem‑solving, and communication skills.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field (or equivalent experience).
- Professional security certifications preferred (e.g., CISSP, CISM, CEH, CCSP, OSCP).