Sorry, this listing is no longer accepting applications. Don’t worry, we have more awesome opportunities and internships for you.

Sr Security Architect

matchpoint solutions

Sr Security Architect

San Antonio, TX
Full Time
Paid
  • Responsibilities

    Job Description

    SECURITY ARCHITECT - SENIOR -AUSTIN-TX /FOSTER CITY, CA - 6-MONTH CONTRACT 

    Looking for a Sr Security Architect to come in and hit the ground running. The day to day will be conducting assessments, review application design, threat modeling, making recommendations for security requirements

    Must have skills

    7+ YOE WITH THREAT MODELING, APPLICATION SECURITY(OWASP, NIST SPECIFICATIONS, PCI), AND DATA PROTECTION(CRYPTOGRAPHY)

    Nice to have skills

    INFRASTRUCTURE / NETWORK SECURITY APPLICATION DEVELOPMENT EXPERIENCE KNOWLEDGE OF ONE OF JAVA/ C/C+/ .NET

    DESCRIPTION:

    • 7+ years of work experience with a Bachelor’s Degree
    • You will have significant progressive experience in building secure applications preferably payment platforms, systems that can withstand all types of threats from various threat agents.
    • You would have conducted threat modeling exercises on networks and systems to identify all the threats the systems are exposed to and recommended mitigations controls to address those threats.
    • You will have a deep understanding of current compliance, regulatory and legal requirements relevant to the transaction processing industry such as PCI, HIPPA, SOX, and GLB.
    • Knowledge of administrative, physical and technical controls that could be built around networks, systems, and applications to secure them.
    • A proven record of accomplishment in designing security controls for complex web applications with backend services expertise such as API Gateway, Identity, and Access Management Services, Data Protection technologies, Security Information Event Management, etc.
    • Strong knowledge of deep design review and Secure Development Lifecycle methodologies, Agile-based methodologies, middleware platforms, development platforms (Java, C, C++, .NET, etc.)
    • An individual with experience of working on large scale cloud-based services (including SaaS, PaaS, IaaS) and very understanding of security challenges involved in deploying Cloud Applications
    • Experienced hands-on SW development in C/Objective-C/C++/Swift/Java
    • Technical experience with security technologies including, but not limited to, intrusion detection/prevention, event correlation, firewall, antivirus, anti-spam, policy enforcement, patch/configuration management, usage monitoring, audit, secure application development, etc.

    ESSENTIAL FUNCTIONS

    • Be a product security champion by driving Security Architecture and Design/implementation/optimization for Web, API and Mobile backend applications across Client.
    • Engage in the initial requirements definition (including analysis of threats and risks and alignment with Client security, Engineering, IT and Architecture standards.
    • Conduct and facilitate security reviews, threat modeling including deep design reviews throughout the development lifecycle.
    • Facilitate "table-top"/red-team/scenario analysis exercises in conjunction with other SME's; and plan the resolution of any identified vulnerabilities/issues.

    You’ll be working on enabling/building security on various platforms and technologies which protect the applications from attacks like:

    o Payment processing platforms, Payment Wallet solutions, Consumer-facing applications, COTS products deployed in house, public clouds, Issuer/Acquirer facing platforms and applications, white-labeled solutions for partners.

    o zTPF, zOS, MVS, Linux, Windows, VMWare, Openstack, SDN, Public cloud like AWS, Google

    o Cybersecurity tools like IDS, SIEM, Tripwire, Tanium, Netwitness, Netflow, WAF

    o HSMs, Tokenization systems, data encryption solutions from Safenet, Vormetric etc

    o Web technologies like HTTP, SOAP, REST services, AJAX

    o Databases like Oracle, MS SQL, Couchbase, Cassandra, Riak, Aerospike

    o Programming languages like Java, C, C++, .Net, Javascript, GoLang, ErLang, Cobol etc

    o Caching services like Kafka, Coherence, MQ

    o Big-data like Hadoop

    o Web Access Management solutions like Forgerock, Siteminder, Custom/in-house Security Frameworks

    • Automate security tools and processes ensuring innovation and advancement strategies that keep pace in the areas of access control, security-in-depth, secure transaction processing, secure coding practices for web and mobile applications.
    • Help business and product team to achieve various compliance certifications like PCI, FFIEC, etc.
    • Be responsible for the overall planning, direction, and oversight of multiple projects, products, services or functions.
    • Identify and analyze a system and application-level vulnerabilities to provide recommended counter measures or mitigating controls that reduce risk to an acceptable and manageable level.
    • Independently formulate direction, design or oversight for the development of major Enterprise-wide programs or plans that have a significant impact on the success of the organization.
  • Qualifications

    Qualifications

    Must have skills

    7+ YOE WITH THREAT MODELING, APPLICATION SECURITY(OWASP, NIST SPECIFICATIONS, PCI), AND DATA PROTECTION(CRYPTOGRAPHY)

    Nice to have skills

    INFRASTRUCTURE / NETWORK SECURITY APPLICATION DEVELOPMENT EXPERIENCE KNOWLEDGE OF ONE OF JAVA/ C/C+/ .NET

    Additional Information

    All your information will be kept confidential according to EEO guidelines.