Responsibilities
- Effectively communicate cybersecurity guidelines to engineering and business teams, fostering their adoption for enhanced security practices.
- Maintain close collaboration with engineering teams to guide architecture decisions and support the implementation of cybersecurity controls.
- Contribute to the identification and effective management of cybersecurity risks through thorough threat modeling of products and enterprise tools.
- Provide expert cybersecurity architecture consultation across major programs and solutions to elevate security posture.
- Engage actively with cybersecurity peers to build a unified cybersecurity department while keeping engineering and product teams informed on specific business activities.
- Collaborate with enterprise architecture and infrastructure teams to assess current architectures, identify potential gaps, and propose actionable security enhancements.
- Participate in security events and incident response efforts to pinpoint design flaws and suggest solutions to prevent future threats.
- Advocate for education on cybersecurity best practices and standards among product and enterprise architects and engineers.
- Partner with governance, risk, and compliance teams to ensure that cybersecurity architecture adheres to regulatory and contractual requirements.
Minimum Qualifications
Bachelor's degree in a related discipline with 6 years of experience; alternatively, a master’s degree with 4 years, or a Ph.D. with 1 year of experience, or a total of 10 years in a related field.Minimum of 4 years dedicated to cybersecurity roles.Hands-on experience in designing, securing, or operating AWS infrastructure and services.Ability to clearly explain cybersecurity policies and procedures to both technical and non-technical stakeholders.Excellent customer service, writing, and executive presentation skills.Build strong working relationships with key stakeholders and collaborate closely with other cybersecurity teams to implement best practices.Comfortable navigating complex topics through a consultative approach with employees and senior leadership.Assess risks, providing recommendations based on their impact and likelihood to the organization.Familiarity with modern cybersecurity architectures such as zero trust, IaaS, PaaS, SaaS, and DevSecOps practices.Proficient in creatively solving complex cybersecurity challenges while demonstrating sound business judgment.Experience applying Agile methodologies in a collaborative environment.Proven success in initiating change and deploying solutions in Fortune 1000 companies.Knowledge of key cybersecurity frameworks such as ISO 27000 and NIST, along with industry regulations like GDPR and GLBA.Preferred Qualifications
Experience in developing cybersecurity standards for hosting and application stacks in both cloud and on-premises environments.In-depth knowledge of Identity and Access Management (IAM), cryptographic controls, access policies, and security protocols.Familiar with applications security implementations and standard methodologies.Extensive technical knowledge in various programming languages and frameworks, including Python, .NET, and Java.Experience with firewall technologies and deep understanding of DMZ architectures.Familiar with AWS Well-Architected Framework.Experience in crafting strategies for cloud enterprise solutions in AWS, GCP, or Azure.Strong grasp of cloud containerization technologies and serverless platforms.Background in sectors involving national critical infrastructure.Experience with big four consulting firms or Fortune 500 companies.Relevant industry certifications such as CISSP, CEH, OSCP, Azure, AWS, CISM, or CISA.Compensation : The base salary for this position ranges from $119,600.00 to $199,400.00, varied by location and candidate qualifications. Additional compensation may include incentive programs.
Benefits : The company offers flexible vacation policies, seven paid holidays, and up to 160 hours of paid wellness time per year. Employees may also enjoy additional paid time off for bereavement, jury duty, and parental leave.
Applicants must have authorization to work in the United States for any employer without current or future sponsorship.