Job Description
The Role
Reporting to theĀ CAA Deputy CISOĀ this is a hands-onĀ solutionsĀ architectĀ roleĀ with aĀ focus onĀ cyber/information security,Ā working within the InformationĀ Risk ManagementĀ (IRM)Ā group and deliveringĀ secureĀ technologyĀ solutions to the company at large.Ā The role is critical in embedding security into CAA technology solutions thatĀ are developed in-house or SaaS based.Ā The candidate willĀ collaborate across business,Ā technology,Ā andĀ otherĀ functionalĀ businessĀ areas toĀ understandĀ requirements and workflows to develop and guide implementation of secure solutions to protect CAAĀ assets.Ā Ā
Ā
We are looking for candidates whoĀ are self-driven andĀ proficient inĀ cybersecurity,Ā third-partyĀ risk/security management, dataĀ securityĀ and general IT risk managementĀ processes. The candidate will have experience as aĀ solutionsĀ architect with a strong focus on integrating security throughĀ the product/solution lifecycle.Ā Ā
Ā
The candidate will play a key roleĀ inĀ ourĀ teamsāĀ efforts to build and support a defensible environment where we are able to detect, contain and respond quickly toĀ data securityĀ threats and compromise in ways that serve to enable the business needs of a highly collaborative organization. The environment is fast-paced and commonly on the leading edge of technology, including early adoption of various cloud services along with the challenges of integrating those services into our security practices.Ā
Ā Ā
ResponsibilitiesĀ
Lead the solutions architecture function to ensure security is integrated early in the development lifecycle for in-houseĀ applicationsĀ orĀ SaaS based solutions, infrastructureĀ projectsĀ and technology processes.Ā Ā
Partner with business and technology teams toĀ identifyĀ and document workflows, system architecture, dataĀ flowsĀ andĀ developĀ appropriate securityĀ considerations.Ā Ā
Leverage Threat ModelingĀ techniques toĀ identifyĀ security threats, vulnerabilities,Ā and attack vectors across theĀ solutionĀ (infrastructure, application, data).Ā
Ensure the security considerationsĀ identifiedĀ areĀ implementedĀ and the solutions are configuredĀ securely.Ā Ā
Develop secureĀ patternsĀ for foundational technology solutions based on CAAĀ security standardsĀ and continually educateĀ technology stakeholders onĀ the adoption of patterns.Ā
Key focus onĀ securityĀ integrationsĀ includesĀ secureĀ access and authorizations,Ā audit logging,Ā secretsĀ management, data protection, dataĀ securityĀ andĀ other functionalĀ third-partyĀ integrations.Ā Ā
Support the SaaS/Third Party security assessmentsĀ and collaborateĀ with service owners, businessĀ leadsĀ andĀ vendors to develop a managed solution aligned with CAA security policies.Ā Ā
IdentifyĀ risks and provide mitigating controls or risk treatment options for a given solution.Ā Ā
Develop training forĀ technology team members to increaseĀ awarenessĀ on securityĀ practices for onboardingĀ new technologyĀ solutions.Ā Ā
Ā Ā
RequiredĀ CapabilitiesĀ
MinimumĀ 8Ā years of Information Security experience with aĀ BachelorāsĀ Degree.Ā
Minimum 3Ā years experienceĀ in a SecurityĀ ArchitectureĀ function.Ā
Create and reviewĀ system architecture diagrams inĀ LucidchartĀ or equivalent tool.Ā
ExperienceĀ in SaaS and Cloud architecturesĀ āĀ Azure,Ā AWS,Ā M365,Ā and exposure toĀ SAP 4/HANA, Workday,Ā Salesforce,Ā and otherĀ SaaSĀ solutions.Ā Cloud architectureĀ certifications preferred.Ā Ā
Experience with Cybersecurity frameworks ā NIST CSF,Ā CSA Cloud Controls.Ā
Cybersecurity certificationsĀ CISM, CISSPĀ or equivalent work backgroundĀ preferred.Ā Ā
Familiarity withĀ operationalĀ tools such as JIRA,Ā ServiceNow,Ā OneTrust.Ā
Experience with contractual and regulatory standards such as GDPR, CCPA, FINRA, TISAX,Ā SOX.Ā
Experience with third partyĀ securityĀ assessmentsĀ and standards ā SOC, ISO27001, SIG.Ā
Ability to communicate complex messages in a clear and concise mannerĀ with stakeholders at all levels.Ā
Excellent organizational skills and ability to communicate with internal/external entities and executives.Ā
Effective leadership skills withĀ demonstratedĀ ability to coordinate people and teams to project/activity completion.Ā
Ability to work inĀ teamĀ environment sharing responsibilities.Ā
Ability to work in a flexible environment where requirements and procedures continuously evolve.
Learn more about this Employer on their Career Site
