Search by job, company or skills

Information Security Architect

Information Security Architect

Deloitte
6-8 Years
Not Disclosed
  • Posted 18 hours ago
  • Be among the first 10 applicants

Job Description


Required Qualifications

• Bachelor's degree in Computer Science, Information Technology, Engineering,

Information Security, Cybersecurity, or a related field is required.

• CISSP, CCSP, or CSSLP certification is mandatory.

Required Experience

• Minimum 6–8 years of relevant experience in cybersecurity architecture, security

engineering, application security, or a related field, including hands-on experience

in application threat modeling.

Key Responsibilities

• Conduct application threat modeling and architecture assessments across key

information security domains to ensure security-by-design.

• Document identified threats and recommend appropriate mitigation strategies.

• Evaluate technologies and solutions to strengthen security capabilities.

• Identify security gaps and clearly communicate related business risks to relevant

stakeholders.

• Provide security solutions aligned with business objectives, risk appetite, and

compliance requirements.

• Validate the effectiveness of security controls in mitigating identified risks.

• Support application teams in analyzing, prioritizing, and mitigating application-level

vulnerabilities identified through security assessments, code reviews, penetration

testing, and vulnerability scans.

• Provide implementation guidance for DevSecOps practices, including secure CI/CD

pipelines, automated security testing, vulnerability management, and security

control integration within development workflows.

• Track and report DevSecOps security metrics, including vulnerability remediation

SLA adherence, security scan coverage, open critical and high vulnerabilities, falsepositive rates, and recurring vulnerability trends.

• Partner with application and engineering teams to reduce critical and high-risk

application vulnerabilities within agreed remediation timelines and drive closure of

security findings through documented action plans.

• Increase adoption of automated security controls in CI/CD pipelines by integrating

SAST, DAST, SCA, container scanning, secrets detection, and policy-based build

gates across applicable application portfolios.

• Review DevSecOps performance dashboards with stakeholders on a regular basis

and recommend corrective actions to improve security testing effectiveness,

remediation velocity, and secure release readiness.

• Support engineering projects throughout the Secure Software Development Life

Cycle (SSDLC) and collaborate with teams to prioritize product security

requirements effectively.

More Info

Job Type:
Industry:
Function:
Employment Type:

Key Skills

application threat modeling

container scanning

DevSecOps practices

automated security testing

secrets detection

About Company