Sr Security Architect Vulnerability Management

Oec
Oec

IT

United States

Posted on Aug 11, 2026
Job Summary/ObjectiveServes as a hands-on Security Engineer to help shape and execute the company’s modern security vision. Designs, builds, and scales a holistic, end-to-end Vulnerability Management and Application Security program. Establishes clear risk metrics, embedding security into software development workflows, and partners closely with Engineering and IT to ensure pragmatic, timely remediation. Delivers steady, incremental security improvements without stalling engineering velocity. Key Responsibilities & Duties (essential to the job) Builds and oversees a unified Vulnerability Management Life Cycle spanning AWS cloud environments, legacy co-located infrastructure, containers, and application code.Defines, tracks, and reports on core program metrics (e.g., MTTR by severity, SLA compliance, SLA breach rates, patch coverage) to demonstrate risk reduction to executive leadership.Establishes clear, risk-based Remediation SLAs in collaboration with Engineering, DevOps, and IT Operations.Shifts security "left" by embedding automated SAST, DAST, SCA, and secret-scanning tools into modern developer pipelines (e.g., CI/CD workflows, Terraform checks).Expands application security controls beyond basic infrastructure/log monitoring to cover open-source dependency risk, code composition, and secure development practices.Designs and maintains security standards and architectures within AWS.Secures cloud configurations and Infrastructure as Code (IaC) templates in AWS using automated security scanning and continuous compliance rules.Partners with IT Infrastructure and Systems teams to streamline patch management practices across hybrid datacenter and cloud workloads.Monitors emerging threat vectors, zero-day vulnerabilities, and active exploits (EPSS/KEV catalogs) to dynamically adapt remediation priorities.Coordinates targeted vulnerability assessments, third-party penetration testing, and post-remediation verification. EducationA bachelor’s degree from an accredited college or university is required, with a focus in Cybersecurity, Computer Science, Information Technology, or related discipline. In the absence of a degree, equivalent work experience directly related to the key responsibilities of the role will be considered as a substitute for the degree. Experience, Skills and Key CompetenciesAt least 6 years of experience in hand-on cybersecurity, with significant experience operating as a Senior/Lead Security Engineer or Security Architect in growing engineering organizations, demonstrated experience navigating hybrid environments, and deep practical experience writing and deploying Terraform. Experience, Skills and Key Competencies (continued)Must also be able to demonstrate the following knowledge, skills and abilities: Strong working knowledge of native AWS security services (GuardDuty, Security Hub, IAM, KMS, Org-level controls).Versatile, generalist knowledge across Security Operations (SecOps), SIEM architecture, Detection & Response, and Vulnerability Management life cycles.Ability to build strong relationships with DevOps, IT, and software development teams through collaborative problem-solving rather than rigid auditing.Understanding of AWS architecture and Terraform configuration scanning to identify cloud-native misconfigurations and drift.Demonstrated ability to define program SLAs, build executive dashboards, and drive culture change around patch compliance and code hygiene.Flexible and adaptable approach to work and can easily adjust to shifts in priorities as the needs of the business change.Able to effectively work and thrive in a remote work environment that has limited opportunities for in-person interactions.Excellent communication skills and can tailor messaging to a specific audience/situation. Special Position Requirements Willing and able to attend virtual meetings with the laptop camera on.