Job responsibilities
- Evaluates current and future cyber architecture as it relates to infrastructure and applications, and leads the assessment of new technology using existing standards and frameworks
- Independently performs analysis and develops reports to identify security risks, impacts and mitigations to protect data, applications, and infrastructure using modern tools
- Conducts cybersecurity assessments and produces threat models
- Regularly provides technical guidance and direction to support the business to include engineering teams, product managers and vendors
- Works with stakeholders and senior leaders to recommend actions to mitigate vulnerabilities and uplift application and infrastructure security posture
- Serves as function-wide subject matter expert in one or more areas of application or infrastructure security
- Influences peers and project decision-makers to consider the use and secure deployment of leading-edge technologies and patterns
- Adds to team culture of diversity, equity, inclusion, and respect
Required qualifications, capabilities, and skills
- Formal training or certification in cybersecurity and 5+ years applied experience across one or more cybersecurity domain areas (e.g. threat modeling, vulnerability assessments, cyber operations, product security, cybersecurity strategy, infrastructure design, supply chain risk management)
- Familiarity across a range of security frameworks and guidelines (e.g. OWASP, NIST, ISO, MITRE) and experience reconciling design documentation and architecture with applicable industry standards and best practices
- Hands-on practical experience delivering enterprise level cybersecurity solutions and controls by leading or producing security assessments, architecture reviews or threat models
- Advanced knowledge of cybersecurity architecture, applications, and technical processes with considerable, in-depth knowledge in one or more technical disciplines (e.g., SaaS, public cloud, mobile security AI/ML)
- Ability to tackle design and functionality problems independently with little to no oversight
- Ability to evaluate current and emerging technologies to select or recommend the best solutions for future state architecture & enterprise integrations
- Proven experience leading projects from scoping to delivery
- Strong written and oral communication skills to effectively engage with stakeholders and convey findings
Preferred qualifications, capabilities, and skills
- Ability to tailor communication for audience needs and explain complex topics succinctly
- Demonstrated experience in mobile, cloud or AI/ML security
- Certifications applicable to this role: CISSP, CISM, CRISC and/or SANS (to include but not limited to GCIH, GCFA, GCEH, GPEN, GCED) and/or AWS/GCP/Azure Cloud Foundations or Solutions Architect
- Experience operating and collaborating in a highly regulated global enterprise environment.