Application Security Architect


Job Details

Application Security Architect

Direct Hire

Remote - EST Hours

MUST be in GA, MS, or AL


Summary:


This role will have responsibility for setting the strategic direction for the Enterprise Security Architecture teams in the areas of Application and Cloud Security and then execute projects against the strategic roadmap. This position is primarily focused on Application and Code Security but does touch other security domains as well. Interested applicants should be well rounded in their understanding and application of different security and technology platforms; in areas such as identity, networking, endpoint, data, monitoring, cloud, and/or application security. Qualified candidates need to be able to align strategy and execution to increase cybersecurity maturity, anticipate future requirements for complex traditional, hybrid, and multi-cloud environments, drive initiatives via influence and relationships into business processes, keep up with current security trends, be focused on results, and be a self-starter.


This position is responsible for ensuring the confidentiality, integrity, and availability of the company s information assets. This will be accomplished by:


Establishing and implementing an information security framework and technical architecture.

Designing, developing, and implementing information security products.

Providing information security expertise and consulting.



Job Responsibilities:


  • Align forward thinking strategy with business goals to integrate and raise the bar on security practices and solutions.
  • Assist in the ongoing development of the client's security architecture identify areas of opportunity, research alternatives and recommend solutions.
  • Develop creative solutions to meet business needs while ensuring appropriate security controls and best practices are implemented.
  • Partner with others to identify and resolve information security issues.
  • Plan, coordinate, and lead information security projects.
  • Help customers understand and apply information security concepts, processes, and technologies.
  • Maintain current knowledge of information security concepts, technologies, and practices.
  • Mentor others to strengthen cybersecurity principles and best practices to outside operational areas.
  • Establish and maintain excellent working relationships and partnerships across the Technology Organization functions, business partners, and external vendors and suppliers.
  • Create an environment that fosters accountability, innovation, and engagement at all levels.
  • Streamline the software development lifecycle to reduce application vulnerabilities, improve developer productivity, and code quality.


Education/Experience:


  • Experience with software development and programing, code reviews, and application vulnerability remediation.
  • Experience with network infrastructure, modern operating systems, database applications, web applications and other computing technologies
  • Hands-on experience designing, architecting, and implementing various information security tools/products such as PKI, Static or Dynamic Code Analysis, Next-Generation Firewalls, HSM s, SIEM, Multi-Factor Authentication, IPS, NetFlow Monitoring, Full Packet Capture, Database Encryption, Privileged Identity Management, Cloud Posture Management, etc.
  • Ability to lead a project from concept through implementation and anticipate potential problems.
  • Comprehensive knowledge and understanding of information security concepts and best practices (NIST, COBIT, ISO, PCI, OWASP, etc)
  • Ability to perform detailed information security risk assessments and recommend mitigating controls.
  • Experience promoting security as a business enablement function through the use of documentation, metrics, and strong verbal communication.
  • Industry certification preferred (CISSP, CCSP, CISA, GIAC, etc)


Requirements and qualifications:


Minimum


  • Experience with software development and programing, code reviews, and application vulnerability remediation.
  • Strong technical knowledge of application development practices, CI/CD pipelines, various cloud platforms including Azure, AWS, or GCP, modern operating systems, networking protocols and designs, and identity management.
  • Experience with development platforms and CI/CD tools, such as TFS/ADO/Git or Jenkins.
  • Proficiency in one or more coding languages, such as C#, Python, Java, or Java Script
  • Experience promoting security as a business enablement function using influence, metrics, documentation, strong verbal communication, and presentation skills.
  • At least 5 years of work experience playing a key role in building technical programs.
  • Ability to lead a project from concept through implementation and anticipate potential problems.
  • Experience prioritizing and executing with minimal direction or oversight.
  • Must pass NERC CIP & Insider Threat Protection background checks.


Preferred Qualifications


  • Development or Programming background.
  • Azure, AWS, and GCP certifications preferred.
  • Competency in APIs (Rest, Graph) and/or JavaScript/JSON/Kubernetes/SQL.
  • Industry certifications such as: CISSP, CCSP, CISA, GIAC, OSCP, CRISC, CCNP, etc.
  • Experience with information security frameworks such as: COBIT, NIST, OWASP, etc.
  • Familiarity with nation state, sophisticated criminal, and supply chain threats.
  • Up-to-date knowledge of current hacking techniques, vulnerability disclosures, and data breach incidents.
  • Working knowledge of cloud and traditional security network architectures.
  • Experience with cybersecurity analysis and analytic tradecraft.


The annual pay range for this position is $120,000 to $137,000 (dependent on factors including but not limited to client requirements, experience, statutory considerations, and location). Benefits available to full-time employees: medical, dental, vision, disability, life insurance, 401k and commuter benefits. Note: Disclosure as required by the Equal Pay for Equal Work Act (CO), NYC Pay Transparency Law, and sb5761 (WA).


About Synergis

Synergis serves a myriad of clients across nearly all industries, from start-ups to Fortune 100 companies. The outcomes of these relationships are demonstrated in a growing list of more than 300 clients and industry recognition by Inc. magazine and the Atlanta Business Chronicle. From its foundation in 1997, Synergis has been successfully recruiting and placing IT professionals in all areas of information technology. For more information about Synergis, please visit the company website at www.synergishr.com.


Synergis is proud to be an Equal Opportunity Employer. We value diversity and do not discriminate on the basis of race, color, ethnicity, national origin, religion, age, gender, gender identity, political affiliation, sexual orientation, marital status, disability, military/veteran status, or any other status protected by applicable law.


For immediate consideration, please forward your resume to Sumner Pirkle at ...@synergishr.com. If you require assistance or an accommodation in the application or employment process, please contact us at ...@synergishr.com.





 Synergis

 05/26/2024

 All cities,GA