Security Architect
Senior Security Architect / Engineer
We are seeking a highly skilled Senior Security Architect/Engineer to design, implement, and maintain robust security solutions across our organization. The ideal candidate will possess a deep understanding of cloud security, threat detection, and response, as well as a strong foundation in offensive security and regulated Manufacturing Execution Systems. This role requires a combination of technical expertise and strategic thinking to protect our critical assets and ensure business continuity.
Responsibilities:
Must Have:
Architectural Design and Implementation:
- Design and implement robust Identity and Access Management (IAM) and Role-Based Access Control (RBAC) models in multi-cloud environment (CIEM)
- Implement threat detection and response capabilities using SIEM, SOAR, EDR, and XDR platforms.
- Ensure network security through the effective use of firewalls, IPS, VPNs, and network traffic analysis tools. Ability to Plan/Build/Run global projects.
- Lead/conduct vulnerability assessments, penetration testing, and red/purple teaming exercises.
- Proficient in Automating security tasks and incident response using scripting languages (Python, PowerShell).
- Experience in Implementing data security measures, including data loss prevention (DLP) and encryption.
Threat Detection and Response:
- SME in Deploying and managing SIEM and SOAR platforms (Sentinel, Falcon FDR, Demisto).
- SME Utilizing EDR and XDR solutions (CrowdStrike, Defender) for endpoint protection.
- Proficient Analyzing network traffic using tools like Wireshark and Tcpdump.
- Proficient Leveraging threat intelligence platforms (TIS) to stay informed of emerging threats.
Offensive Security:
- Experience in Conducting penetration testing using tools like Metasploit and Kali Linux.
- Experience Assessing system vulnerabilities using Nessus, Rapid 7 and/or other open source tools
- Experience in red and purple team exercises.
Blue Team Collaboration:
- Collaborate with the Security Operations Center (SOC) to enhance detection and response capabilities.
- Automate incident response tasks using Python and PowerShell and/or AI Agents.
Enterprise Security Solutions:
- Deep understanding on how to secure/ manage enterprise-grade hybrid infrastructure.
- Deep understanding on various load balancers stacks (ALB, ELB, Nginx) and Web Application Firewalls (WAFs).
- Proficient in Implementing data loss prevention (DLP) and encryption technologies.
Regulatory Compliance:
- Knowledgeable of security frameworks (NIST, ISO 27001, PCI DSS, HIPAA, GDPR).
- Preferred experience with FDA GxP regulations.
- Knowledgeable in Conducting gap assessments and develop remediation plans.
Project Management:
- Manage multiple security projects simultaneously.
- Effectively communicate with stakeholders and internal customers.
Qualifications:
- At least 7 years of experience in IT with a focus on Enterprise Cloud security services.
- CISSP certification is mandatory. Additional certifications ( AWS/Azure Certified Security Specialist) preferred.
- Strong understanding of cloud security, networking, cryptography, and security protocols.
- Exceptional analytical skills, problem-solving abilities, and attention to detail.