Job Description
We are seeking a skilled and motivated Security Architecture Analyst to join our team. This role is critical in performing security architecture assessments, developing remediation strategies, and helping to ensure our systems and applications meet global security standards. The ideal candidate will have a solid technical background, excellent communication skills, and the ability to assess both application and infrastructure security in an enterprise environment.
Key Responsibilities:
- Initiate communication with system owners/vendors to collect background information and schedule interviews for security assessments.
- Conduct thorough remote and/or in-person interviews with system owners and vendors to identify security gaps and gather detailed system data.
- Review technical documentation such as system specifications, architecture diagrams, requirements, and test plans to evaluate adherence to security standards.
- Collaborate with Senior Security Architecture Analysts and other stakeholders to review findings and address concerns.
- Conduct comprehensive security assessments based on documentation and interviews.
- Develop clear, detailed security architecture assessment reports identifying root causes and providing actionable remediation strategies.
- Contribute to the development of global security standards, guidelines, and processes.
- Evaluate and make recommendations for the adoption of new and emerging security technologies.
Basic Qualifications:
- 3+ years of experience in Security Architecture Assessment.
- Bachelor's degree in information systems security, Computer Science, or a related field.
Preferred Skills & Certifications:
- One or more professional certifications such as CISSP, SSCP, or CISM (in good standing) strongly preferred.
- Strong verbal and written communication skills, with the ability to present to both technical and non-technical stakeholders.
- Experience in application and/or infrastructure security in enterprise environments.
- Ability to explain and guide developers on common vulnerabilities (e.g., XSS, CSRF, Injection attacks) and remediation methods.
- Proficiency in articulating technology risks to business stakeholders.
- Ability to work under pressure and meet tight deadlines.
- Strong knowledge of access control technologies including SSO, SAML 2.0, and Kerberos.
- Familiarity with OWASP Top 10 vulnerabilities and best practices.
- Excellent analytical, research, and problem-solving skills.
- Knowledge of security incident response procedures, threat modeling, and various attack vectors.
- Solid understanding of network and system infrastructure and security best practices.
#J-18808-Ljbffr