Product Security Architect
Mexico
Encora
Encora provides its clients with tailored innovation software engineering solutions across a wide range of leading-edge technologies.Important Information
Experience: +7 years
Job Mode: Full-time
Work Mode: Work from home
Job Summary
As a Security Architect, you will be responsible for contributing to the success of the Product Security team in several key areas. You’ll work to reduce security friction across engineering by fostering partnership and collaboration to enhance our security posture. Security enablement will be a crucial aspect of your responsibilities involving research, secure architecture, and design. You’ll play a vital role to ensure solutions are secure by default. You will facilitate continuous security testing, measurability, and reporting on the impact of security initiatives.
Responsibilities and Duties
- Partner with engineering and platform teams to identify and solve complex security problems.
- Contribute to the vision and roadmap to increase the security posture of our code and products.
- Conduct security reviews of product designs, code, and configurations to minimize software risk.
- Conduct comprehensive threat modeling exercises and testing to identify security risks and vulnerabilities while collaborating with product teams.
- Identify security gaps and provide strategic recommendations for remediation.
- Address security issues identified throughout the secure software development lifecycle.
- Conduct security testing beginning from the product planning phase continuing through production deployment.
- Lead in the research, development, and implementation of new product security capabilities.
- Develop and implement quantifiable application risk assessments of our client products and infrastructure.
- Scale the impact of Cyber Security by contributing and leading various Security Champion Initiatives.
- Define and implement security requirements ensuring alignment with industry standards and best practices.
- Ability to work independently, and lead both cyber security and cross functional security initiatives.
- Stay abreast of emerging security threats, vulnerabilities and controls.
Qualifications and Skills
- 7+ year experience across multiple security domains with an emphasis on product security and cloud-native security.
- 4+ year security architecture experience executing product security initiatives (i.e. secure architecture, SSDLC, threat models, and risk assessments).
- Expert knowledge of modern web application components, development, architecture, and design principles.
- Hands-on experience with design, code review, and securing products and solutions for public cloud-based applications and infrastructure.
- Experience architecting and developing product-centric security solutions.
- Expert knowledge securing internal microservices and public API’s.
- Experience securing applications deployed using Docker, Kubernetes, and public cloud environments.
- Product Security experience working for a SaaS-based organization.
- Excellent leadership and project management skills, with a track record of driving security initiatives within software development teams.
- Excellent communication skills (both written and verbal).
- Self-motivated, self-directed, and self-organized.
Nice to have experience
- SAST, SCA, DAST, WAF, and CNAPP solutions.
- Offensive testing tools like Burp Suite and Kali Linux.
- Penetration testing.
About Encora
Encora is a global company that offers Software and Digital Engineering solutions. Our practices include Cloud Services, Product Engineering & Application Modernization, Data & Analytics, Digital Experience & Design Services, DevSecOps, Cybersecurity, Quality Engineering, AI & LLM Engineering, among others.
At Encora, we hire professionals based solely on their skills and do not discriminate based on age, disability, religion, gender, sexual orientation, socioeconomic status, or nationality.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Analytics APIs Burp Suite Cloud CNAPP DAST DevSecOps Docker Kali Kubernetes Linux LLMs Microservices Pentesting Product security Risk assessment SaaS SAST SDLC SSDLC Vulnerabilities
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.