Description

As part of a team, ensure the adoption of security architecture and engineering initiatives in order to effectively and securely support the organization in meeting specific business technology needs.
• Review solutions to be deployed in cloud and on premise environments
•Assist with Architectural design documentation and System Security Plan documentation
•Monitor and guide systems to ensure Authority to Operate is achieved in a timely manner
• Understand technical security issues and the implications to the Platform and be able to communicate them to management and other business leaders.
• Responsible for guiding the design and implementation of secure solutions and services across the Platform.
• Maintain in-depth knowledge of IT industry best practices, technologies, architectures, and emerging technologies.
• Must have knowledge and understanding to be able to configure and implement security solutions to reduce risk to an acceptable level.
• Understand emerging security technologies and determine the appropriate use within business applications.
• Must be able to provide technical guidance and foster a collective understanding of data flows and security issues encountered in both premise based and cloud applications and services.
• Communicate architectural decisions, plans, goals, and strategies
• Must be able to incorporate business drivers, needs and strategies to address future business / technology needs.
• Work in teams for secure application and/or infrastructure solution architecture.
• Collaborate with our Governance organization and functions including Internal Audit, Legal and Compliance, Privacy, and Sourcing to ensure that the Platform maintains a strong cybersecurity posture.

Required/Desired Skills

 

SkillRequired /DesiredAmountof Experience
Experience providing high-level design and architecture diagramsRequired8Years
technically validating solutions and connecting business, data, security, systems, and other technical and non-technical architecturesRequired8Years
Familiarity with open architecture and cybersecurity architecture principles that achieve cybersecurity framework goals.Required8Years
Familiar with encryption technologies used in commercial operating systems, including Public Key Infrastructures-continuedRequired8Years
symmetric and asymmetric cryptography, certificate trust stores and the use of key escrow for discovery and legal purposesRequired8Years
At least 8 years of experience in network and endpoint security architectureRequired8Years
Familiarity with protocols commonly used in commercial networks, such as SMB, RPC, HTTP, SQLRequired8Years
Familiar with multi-tiered network applications, common ports and protocols used in those communicationsRequired8Years
Familiar with Vulnerability Scoring (CVSS) and exploitation mechanisms of common vulnerability types (overflows, cross-site-scripting, SQL injection)Required8Years
Experience working with Cloud Native architecture paradigms, patterns and security methodologies.Required6Years
Familiarity with NIST, IRS 1075, HIPAA, FedRAMP and other cybersecurity framworksRequired8Years
Familiar with methodologies for scalable, automated creation of System Security Plan, and Authority To Operate, Attestation & ValidationRequired4Years
Candidate should have a background in general security practices such as identity and access management (IAM)-continuedRequired8Years
Experience leading the alignment of on-going activities in support of critical State & Federal mandates such as -continuedRequired8Years
Continuous Diagnostics and Monitoring (CDM), Executive Orders related to cybersecurity, and guidance from OMB and NISTRequired8Years
Familiarity with open architecture and cybersecurity architecture principles that achieve cybersecurity framework goalsRequired8Years
Desired Skills / Certification: • AWS Certified Security • Azure Architect Certification • Google Architect CertificationDesired0 
Desired Skills/Certs (continued)- Certified Information Systems Security Professional (CISSP) • Certified Cloud Security Professional (CCSP)