Information Security Architect


Job Details

Work Location: - McLean, VA

Job Title: IT - Information Security Architect

Duration: Long Term

Job Description: Position Statement:

As Senior Lead Engineer for Application Security Architecture team, you will work closely with application team to help implement security solutions that are tailored to the specific risks facing the organization. You will be an influential technical lead, who will be work across a heavily matrixed global organization to aggressively drive secure discipline for customer and enterprise applications, as well as lead cybersecurity function for critical Hilton platforms. You will play an important role to help manage the compliance of policies and standards as a function of an end-to-end SDLC project lifecycle.

Qualifications

Please list specific qualifications/experience, knowledge, skills and abilities needed for this position.

Working knowledge of one or more following technologies: Atlassian Stack, Node.js, react, relay, Graphql and NOSQL database such Couchbase.

Experience with AWS Cloud environment and cloud security concepts and architecture.

Experience reviewing application design, software framework, and infrastructure to identify issues. Capable of assessing underlying components (e.g., databases, servers), configuration, and security access controls.

Experience with static code scan tools (e.g., Fortify, Checkmarx) and dynamic scanning tools (e.g., Burp, Qualys).

Experience with development CI/CD tools such as Git, Jira, GitLab, or Jenkins.

Familiarity with container orchestration services, especially Kubernetes.

At least three years experience and proficient in a one of the public clouds such as AWS, Azure, GCP or Alicloud.

Experience developing and authoring application security architectures, standards, and guidelines.

Experience communicating application security requirements and risk to IT teams and business partners.

Experience reviewing application design, software framework, and infrastructure to identify risks. Capable of assessing underlying components (e.g., databases, servers), configuration, and security access controls.

Experience with DevSecOps and integrating security tools into a secure CI/CD pipeline.

Required Qualifications

Minimum Education: BA/BS in Information Technology, Computer Science, Computer Engineering, or equivalent work experience.

Minimum Years of Experience: 5+ years of experience combined with exposure to product development and web development on J2EE platforms or alternate technology stacks.

Minimum 3 years of experience working with AWS Cloud technologies or alternate public cloud providers.

Minimum Years of Experience: 3+ year of product development and web development on J2EE platforms or alternate technology stacks.





 Rockwoods

 06/01/2024

 Mc Lean,VA