Responsibilities:
- Provides technical and architectural oversight for systems and projects to ensure compliance with security policies, customer contracts, along with State and federal regulations.
- Facilitates communication with cross-functional groups and works with our product management and other IT departments to develop secure business requirements and develops the security architecture and integrate into our long-term platform strategy.
- Consults and researches with vendor product specialists/sales, independent research organizations, on-site support engineers, and fellow architects and administrators on best-fit technologies and ensures compliance with department policies, standards, and technology roadmap.
- Coordinates with Enterprise Architecture team for technology validation or suggestions for alternative solutions.
- Produces architectural framework documents i.e., white papers, guidance documents, best practices, technical reports, etc.
- Provides project estimates based on past experience with security implementation projects/programs.
- Provides support and subject matter expertise with respect to adherence to security controls (e.g. NIST 800-53 and CIS).
- Provides support and subject matter expertise with respect to adherence to Enterprise Architecture Frameworks (e.g. TOGAF and SABSA)
- Leads and mentors other team members in achieving goals and objectives.
Experience:
- 10+ years of experience in information security or system administration with 3 years experience leading, architecting, designing and developing large-scale security solutions utilizing a mixture of hardware and software technologies
- Bachelor’s degree in computer science, information systems or related field and a CISSP certification is required. Will accept any suitable combination of education, training, or experience
- Position requires experience building security architectures for applications deployed on or with the following technologies: IBM Mainframe, HP NonStop/Tandem, Java, .Net, Linux, Microsoft Windows, SQL Server, Mongo DB, Big Data Ecosystem (Hadoop)
- Demonstrated relevant security expertise in designing security solutions for a mix of technology areas, with focus on network and cloud security. Areas may include: Advanced Identity & Access Management, Application Security include S-SDLC, DevSecOps, and Automation, Security Operations and Incident Response, Cyber Threat Hunting, Intelligence, and Analytics, Data Classification, Encryption, and Protection
- Experience as technical lead organizing and mentoring junior- and intermediate-level engineers/architects
- Ability to build risk models and analyze security weaknesses in complex technology deployments
- Experience working with product teams on specifying secure application requirements
- Experience with payment processing or Financial Services systems is considered a plus
- Ability to solve complex technical problems using independent judgement.