The Security Architect will partner with Enterprise Architects, Infrastructure and Development Teams to develop a deep technical understanding of the client's technology ecosystem. Incumbent will conduct architecture reviews, threat modeling, identify risks and advise IT, business owners and technical teams on options to mitigate the risk.
The candidate must have excellent verbal and written communication skills. 
This position reports to the Manager of Security Architecture.
Major Responsibilities
• Review enterprise architecture diagrams and recommend security related enhancements.
• Model attack vectors and design security controls to mitigate risk
• Strong knowledge of cloud security concepts with SaaS, PaaS and IaaS platforms and architectural knowledge of Amazon Web Services (AWS) and Microsoft Azure cloud services.
• Plan, design, develop and maintain security technologies, diagrams, processes and procedures.
• Develop and implement enterprise-wide and cross-functional integration solutions
• Research and recommend new industry IT cyber security models, management strategies and effective resource utilization models that can be presented to Senior Leadership (i.e. Directors and above)
• Conduct technology reviews and audits that ensure computer systems are built to reference security architecture principles
• Help build security into infrastructure and architecture designs and guide implementation with the operations team
• Create and deliver knowledge sharing presentations and documentation to security, developers and operations teams
Learn on the job and explore new technologies with little supervision to identify new and emerging security threats
• Education/Experience:
? Requires bachelor's degree in computer science or information security
? Requires a minimum of 6 years of professional IT work experience or a master's degree and 4 years of professional work experience
? Requires a minimum of 2 years of experience in technology such as enterprise security architecture design and developing threat models as well as architecture risk analysis.

• Additional licensing, certifications, registrations:
? One of the following certifications are desired.
§ SANS/GIAC Certifications
§ AWS Certifications

• Knowledge of:
? Application security tools such as:  HTTP and TCP proxies, fuzzers, scanners, debuggers, simulators, etc.
? Common vulnerabilities in the OWASP top 10 list
? Protocols/technologies like SOA, HTTP, SSL/TLS, LDAP, JDBC, Servlet/JSP, SQL, HTML, XML
? Java Application and Java Application Server administration/tuning
? Amazon Web Services (AWS) and/or Microsoft Azure and/or VMware vCloud and/or Docker
? Encryption standards
? Authentication and Authorization standards such as Oauth 2.0, OpenID Connect (OIDC), and SAML 2.0

• Skills and Abilities:
? Ability to understand software design algorithms
Ability to write scripts in languages such as Python, BASH, or PowerShell for automation preferred


