Security architect
Position : Security Architect
Location : Washington, DC
Hybrid : 2-days onsite / week
The role's primary purpose is to design, engineer, influence and embed security controls in the early phases of the IMF's System Development Lifecycle process (Shift Left Mindset).
The selected candidate is expected to influence, drive, and collaborate with business and technical stakeholders to achieve practical architecture solutions that meet the secure by design and privacy by design principles.
Minimum Qualifications :
1. Degree from an accredited university plus a minimum of 7 years of progressive work experience in either security architecture or red teaming.
2. Deep and hands-on understanding and expertise in at least 4 of the following 6 areas - Infrastructure, Application, Network, Cloud Security, Identity & Access Management and Security Automation.
3. An understanding of Azure Cloud and Microsoft 365 security controls, solutions, and future roadmaps.
4. Advanced knowledge Azure Key Vault, Azure Kubernetes Service, Azure Active Directory, Defender for Cloud, Azure monitor, Azure API Management, Application gateway.
5. Understanding of application security assessment methods : OWASP Top 10, OWASP Application Security Verification Standard (ASVS), OWASP Mobile Application Security Verification Standard (MASVS), Attack and Defense techniques.
6. Understanding and ability to perform threat modeling on a diverse category of architecture (Referencing STRIDE, DREAD, MITRE ATT&CK Frameworks).
7. Experience implementing and designing DEVSECOPS and Security Automation delivery pipelines with automation tools like SAST, DAST, SCA, Container Security tooling.
8. Familiarity with cloud security concepts like Landing Zones, Isolation concepts, NSGs / VCNs, Conditional Access, CI / CD pipelines.
9. Familiarity with Datacentric Architectural concepts (Data storage, data lakes, raw and transformational data vaults, data isolation, ETL / ELT ingestion pipelines).
10. Ability to operate with a limited level of direct supervision.
11. Exercise independence of judgement and autonomy.
12. Familiarity with Zachman's abstract architectural concepts.
13. Strong critical thinking and problem-solving skills.
14. Strong written, verbal communication, and interpersonal skills.
15. Ability to translate business requirements into technical and security control requirements.
Major Duties and Responsibilities :
1. Drive and support the solution architecture development process from context to physical architecture and ensure that all relevant security controls are embedded early in the SDLC phase.
2. Work with technical and business stakeholders to identity architectural attributes that may influence threat and attack vectors.
3. Collaborate with business and technical stakeholders to develop data flows, user profiles, data dictionaries, release notes, technical specification and process flows as input for threat modeling activities.
4. Review high level conceptual and logical architectural artifacts and present findings to the IMF's Enterprise Architecture Review Board.
5. Perform threat modeling activities and communicate outcomes to platform engineers, Information Security Risk Management and Application Security team.
6. Develop technical road maps towards achieving mid to long term enterprise security architecture goals like zero trust architecture, automated threat modeling, secure by default, policy as code and pattern as code.
7. Attend project and enhancement meetings to advise and provide input on security architecture related issues.
8. Collaborate with Information security risk managers as part of security accreditation process by providing inputs from a security architectural perspective.
9. Research new information security capabilities and technology for continuous improvement self and the organization.
10. Develop security patterns and security reference architecture documents based on organizational technology demand and knowledge gaps.
11. Collaborate with information security assurance team on developing practical and applicable information security baselines and referencing those baselines in Enterprise Security Architecture documentation.
12. Drive and document security architecture artifacts for protecting the IMF's crown jewels and strictly confidential assets.
13. Collaborate with IMF's DevOps team to define guardrails and process flows for configuration, development, delivery, and deployment pipelines.
14. Collaborate with IMF Enterprise Architecture division on Enterprise Architecture in a bilateral manner and create visibility of activities between ISG and EA division to ensure continuous synchronization.
Related Jobs
Security architect
Security
Admin Security
Security Service Technician