Apply

Security Application Solution Architect (Remote)

Posted 1 day agoViewed

View full description

💎 Seniority level: Senior, 9 years

📍 Location: United States

🔍 Industry: Software Development

⏳ Experience: 9 years

🪄 Skills: AWSCloud ComputingCybersecurityKubernetesSoftware ArchitectureAzureCommunication SkillsCI/CDRESTful APIsDevOpsJSONStrong communication skillsRisk Management

Requirements:
  • Experience with Secrets Management in a corporate environment, large enterprise strongly preferred.
  • Knowledge of Secrets Management tools such as HashiCorp Vault, AWS KMS, Azure Key Vault, Beyond Trust.
  • Demonstrated experience architecting and guiding the deployment of enterprise-scale secrets management solutions, with hands-on familiarity a plus.
  • During recent history, candidate must have demonstrated exceptional ability to assess and communicate information security concepts and practices, with both business and IT stakeholders.
  • Requires in-depth knowledge of the systems development life cycle, client area’s functions and systems, and systems applications programs development technological alternatives.
  • Proven implementation of creative technology solutions that advance the business.
  • Relevant work experience is important for successful performance of this role due to the complexity of our global IT Security environment.
  • Information security qualification such as CISSP is preferred but not required.
  • Strong understanding of application security principles, including OWASP Top 10, SANS/CWE Top 25, and secure coding practices.
  • Expertise in secure session management, token handling, and authentication mechanisms (OAuth, SAML, OpenID Connect).
  • Knowledge of cryptographic practices, encryption protocols, and PKI management.
  • Experience with containerization (Docker, Kubernetes) and cloud platforms (AWS, Azure, GCP).
  • Familiarity with tools for code analysis (e.g., SonarQube, Veracode) and vulnerability scanning (e.g., Burp Suite, Nessus).
  • Understanding of DevSecOps practices, including securing CI/CD pipelines
  • Self-starter with the ability to work independently and manage multiple projects simultaneously.
  • Strong problem-solving and analytical skills with the ability to identify security risks and propose effective solutions.
  • Ability to work collaboratively in cross-functional teams and influence technical teams towards secure implementations.
Responsibilities:
  • Design and architect enterprise-grade secrets management solutions leveraging technologies such as HashiCorp Vault, AWS KMS, Azure Key Vault, or BeyondTrust.
  • Define reusable security architecture patterns and guardrails to enable consistent, secure implementation across high-risk business applications.
  • Drive secure-by-design initiatives by integrating security considerations early in the software architecture lifecycle and influencing enterprise architecture direction.
  • Represent security architecture in design authority boards and technical review councils, advocating for risk-based security controls.
  • Work with in-business IT customers, including application architects and engineers to evaluate application software and infrastructure designs, for the purpose of defining/designing application controls aligned with enterprise standards.
  • Define and drive the architecture and roadmap for enterprise-grade secrets management capabilities, including reference architectures, integration blueprints, and scalable deployment models.
  • Define application-specific security control architectures and produce design artifacts to guide secure implementation of business-critical systems.
  • Develop re-usable implementation guidance and design patterns based on previous engagements to scale the service
  • Work with information security leadership to develop strategies and plans to enforce security requirements and address identified risks in the infrastructure and applications.
  • Act as a security architecture liaison to IT delivery and engineering teams, embedding security principles into technical delivery and architecture review forums.
  • Support security aspects of business & IT initiatives by assisting in architecture, design, implementation, deployment, and operational transition of innovative & secure technology solutions.
  • Work with information security leadership to develop strategies and plans to enforce security requirements and address identified risks in the infrastructure.
  • Research, evaluate, design, test, recommend and plan the implementation of new or updated information security technologies.
  • Establish collaborative working relations with the Information Technology functions to ensure that solutions align with security architecture and business strategy.
  • Play an advisory role in application development or acquisition projects to assess security requirements and controls and to ensure that security controls are implemented as planned.
  • Complete remediation activities and initiate actions to ensure that compliance and security gaps are successfully addressed.
  • Research and assess new information security threats and recommend remedial actions.
  • Foster an information security culture through education, skill development, and implementation of effective information security processes and practices.
  • Understand and adhere to corporate standards regarding applicable Corporate and Divisional Policies, including code of conduct, safety, GxP compliance, data security, and the software development lifecycle
  • Matures and leverages relationships with affiliates, subsidiaries, vendors, and industry peers in accordance with Abbvie Values, Vendor Management Office, and Purchasing to further the mission, vision and goals of the organization.
Apply