ForgeApply
Try it free

ForgeApply · Job listing

Senior Product Security Architect

Earlywarning

Scottsdale | Chicago | San Francisco, US$160k – $200khybrid

See all 87 open roles at Earlywarning

Tailor your resume for this Earlywarning job in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Earlywarning's site. Free trial, no card required.

About this role

At Early Warning, we’ve powered and protected the U.S. financial system for over thirty years with cutting-edge solutions like Zelle®, Paze℠, and so much more. As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses.

Positions located in Scottsdale, San Francisco, Chicago, or New York follow a hybrid work model to allow for a more collaborative working environment.

Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship.

Overall Purpose  

This position consults with Project Management, Product Management, Product Development and Engineering teams to enable them to build and enhance security in EWS products and Services in line with EWS and Industry standards.   This position is highly technical and will lead Product Security efforts in maturing our product security program, mentor others and be a hands -on partner to our product teams to deliver innovative and secure products to our customers .  

Essential Functions   

• Complete s the Identification, measurement, control and minimization of security risks to information systems across a broad range of disciplines including application and host security.  

• Develops repeatable application security architectures working with internal and external partners to ensure that systems are placed within the relevant security zones based on the data they house and their purpose.  

• Serves as the point of contact for all Product security issues in assigned areas.  

• Works with architecture teams to ensure that all newly developed and legacy applications and infrastructure implementations are in line with security policy and are compliance to the required frameworks (ISO, PCI, OWASP, NIST 800-53, etc.)  

• Advises and approves of changes and architectures for assigned areas from a security perspective.  

• Evaluates all product business cases including functional and detailed design specs to ensure security standards are met.  

• Assists in the security incident response process as assigned.  

• Contributes to the development of Early Warning security policy and procedures.  

• Develop Threat Models, design and develop Security architectures and publish reference architecture/patterns for Products and drive companywide adoptions  

• Document and evaluate the present risks and security issues that could impact the confidentiality, integrity and/or availability of the business (both internally and externally) by assisting in documentation, tracking and creating solutions for mitigation.  

• Lead efforts to w ork with internal and external penetration testing organizations to effectively scope Product Pentests that help identify and mitigate gaps in security controls  

• Manages efforts with Product Development and Engineering teams to perform s ecurity analysis on all internally developed products and services .  

• Interacts with customer banks to gather yearly testing and security requirements, review penetration testing findings, mitigating controls and/or projects to rectify security vulnerabilities.  

• Drives Product and Stakeholder teams efforts in building Cloud Native applications by incorporating Cloud Security and Microservices Security best practices and industry standards  

• Drives Product Security efforts in evaluating new technology stacks and frameworks that helps stakeholder and business teams deliver innovative and secure solutions  

• Support the company's commitment to risk management and protect ing the integrity and confidentiality of systems and data.  

Minimum Qualifications  

• Education and experience typically obtained through completion of a Bachelor’s degree in Computer Science, Engineering, Math or Physical Science  

• Typically 10 or more years of engineering, IT, or Information Security experience with a c ombined 6 years of application security or Security Architecture or Consulting or related IT or Information Security experience .  

• Advanced knowledge of relational databases, Windows, and Linux operating systems.  

• Effective interpersonal skills, with ability to present to peers and coworkers.  

• Advanced knowledge of operating system , application , network , and database security architectures.  

• Application development and/ or Software Security background.  

• Exposure to the Agile SDLC process.  

• Experience in Threat Modeling and control design.  

• Experience in designing security for Cloud hosted products .    

• Knowledge of Security Integration into CI/CD and experience in driving CI/CD adaptation for Security controls   

• Advanced experience in analyzing technical issues and making recommendations for corrective action.  

• Demonstrate advanced understanding in the field of Information Security in terms of both concepts and technology.  

• Ability to manage information security related efforts.  

• Advanced understanding of vulnerability exploitation chaining .  

• Background and drug screen.      

Preferred Qualifications  

• CEH/CPT, or CISSP or CSSLP Certification and one of GWEB, or Secure Development Cert, or PHD or MBA in InfoSec or equivalent certification.  

• MCSE, SCSA, CCNA or CISA certification  

• In depth knowledge with public cloud architecture, such as GCP, AWS and Azure, and virtualization technologies, such as Kubernetes, VMware and OpenStack  

• In depth knowledge of threat model, network security, cryptography, authentication and authorization  

• Experience performing threat modeling and design reviews to assess security implications and requirements  

• Expert level experience in defining and documenting security reference architectures and standards  

• Experience with automation tools and methodologies associated with DevOps an

Salary insight

The midpoint of this range ($180k) is about 10% below the median disclosed salary for San Francisco roles listed on ForgeApply ($200k across 8,548 jobs).

Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.

Tailor your resume for this Earlywarning role before you apply.

Tailor my resume for this job

Similar jobs

Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)