Application Security Architect

Brookfield, Wisconsin, United States - Remote

Applications have closed

We are seeking to add an Application Security Architect to our growing managed security offering. This individual will utilize a combination of business process analysis, technical process analysis and technical expertise to develop enterprise architectural security deliverables. This analyzes the relationships of the various IT components and business processes to define approaches that provide significant value to our clients by driving appropriate security strategies across these disciplines.

This individual will be working closely with key client decision makers and business leaders as well as varying levels of technologists requiring this individual to have solid communication skills with all levels of an organization. Additionally, this individual would be responsible for developing advanced enterprise security ideas aligned with key industry standards that can guide our security offerings into the future. More about SysLogic


PRIMARY RESPONSIBILITIES:

  • Build strong client relationships and effectively influence staff at all levels of client organizations.
  • Advise senior client management on security risks.
  • Translate security risks to business impact.
  • Consult and facilitate delivery of Information Security strategic goals and initiatives for clients
  • Assists in the evaluation of overall risk for IT systems (including data), accounting for the people, processes, and technologies that provide security controls
  • Architects, prioritizes, coordinates and communicates the choice of security technologies necessary to ensure a highly secure yet usable computing environment
  • Provide security architecture and advice in support of application development, infrastructure, and enterprise technology projects.
  • Coordinate with various project teams to communicate the necessity of security requirements and design constraints.
  • Identify any gaps in existing application security infrastructure to meet project requirements, work with the Client Management to identify and roadmap solutions.
  • Perform code analysis, application security reviews, and develop an application security training program.
  • Stays current with security technologies and make recommendations for use based on business value.
  • Maintains an expert knowledge in the field of Information Security and the related issues, systems, processes, products, and services.
  • Provide training and mentoring to client and consulting resources.

DESIRED QUALIFICATIONS:

  • Solid history of designing, developing, or customizing application authentication and authorization systems.
  • Understanding of the OWASP Top 10 application security risks and how to address them.
  • Working knowledge of the Microsoft Security Development Lifecycle (SDL), OWASP Software Assurance Maturity Model (SAMM), or Building Security in Maturity Model (BSIMM).
  • Experience with Security Lifecyle Development Assurance (SDLA).
  • Strong working knowledge of enterprise software technologies, application security, and infrastructure.
  • Working knowledge of Microsoft Azure or other cloud computing platform offerings and security related services.
  • Hands on experience with encryption, hashing, secure random number generation, key derivation, key management, digital signatures, etc. in one or more major development languages.
  • Review technology solution designs to assist the business in meeting their cybersecurity objectives. Ensure solutions and new features are designed and implemented according to established design and cybersecurity standards and practices (and, where necessary, facilitate acceptable tradeoffs)
  • Document technical requirements and technical designs for new solutions and features.
  • Lead Developers in secure application design and patterns
  • Research new technologies and best practices for approaching and implementing emerging technologies
  • Advise senior client management on security risks
  • Translate security risks to business impact
  • Coordinate with various project teams to communicate the necessity of security requirements and design constraints.
  • Stays current with security technologies and make recommendations for use based on business value.
  • Core understanding of web application security scanning software and related penetration testing tools
  • General knowledge of core security networking concepts like TLS, SSH, DNS, Firewalls etc.
  • Solid understanding of cloud architecture as well as on premise IT landscape.
  • Exposure to security to the device level.
  • General understanding of regulatory compliance and how it relates to application security and privacy.
  • Ability to articulate technically advanced issues to all audiences.
  • Highly seasoned in organizational, time management, decision making and problem solving skills
  • Ability to mentor and train internal and client teams.
  • Bachelor's degree preferred.
  • 4+ years of advanced security experience.
  • Minimum of 10 years application development experience ideally within the Microsoft development stack.
  • Applicable certification strongly desired (CISSP, CISSP - ISSAP, CEH etc.) or obtained within 6 months of employment.

Most important criteria is a strong desire to be part of a high performing team, providing quality solutions and experiences for our clients.

#LI-HYRBID #LI-REMOTE

Benefits

  • Health Care Plan (Medical, Dental & Vision)
  • Retirement Plan (401k, IRA)
  • Life Insurance (Basic, Voluntary & AD&D)
  • Paid Time Off (Vacation, Sick & Public Holidays)
  • Family Leave (Maternity, Paternity)
  • Long Term Disability
  • Training & Development
  • Work From Home
  • Free Food & Snacks

Tags: Application security Azure BSIMM CEH CISSP Cloud Code analysis Compliance DNS Encryption Firewalls Hashing OWASP Pentesting Privacy SAMM SSH TLS

Perks/benefits: 401(k) matching Health care Insurance Medical leave Parental leave

Regions: Remote/Anywhere North America
Country: United States
Job stats:  15  1  0

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.