Job Summary
We are seeking a Senior DevSecOps Architect to serve as a strategic and technical leader responsible for advancing enterprise DevSecOps maturity and Secure Application Development Lifecycle (Secure SDLC) initiatives. This role will drive secure-by-design practices, provide architectural leadership, and collaborate across technology teams to embed security throughout application development, deployment, and operations. The ideal candidate will have deep expertise in application security, enterprise architecture, DevSecOps automation, cloud security, and security governance.
Key Responsibilities
• Define and establish secure-by-design target architectures for application security testing platforms.
• Serve as a senior technical advisor and Subject Matter Expert (SME) for enterprise security and DevSecOps initiatives.
• Provide architectural guidance for Secure SDLC implementation and DevSecOps automation.
• Evaluate emerging technologies and recommend security solutions aligned with enterprise architecture standards.
• Collaborate with Enterprise Architecture teams on technology validation and governance processes.
• Promote cybersecurity best practices, DevSecOps automation, security tooling, and enterprise security standards.
• Develop security requirements, architecture specifications, and technical documentation supporting secure solution design.
• Create and maintain architecture artifacts, including functional, system, and security architecture documentation, whitepapers, implementation guidance, and best practices.
• Conduct security architecture reviews for applications, platforms, integrations, and cloud or on-premises environments.
• Define and validate security and assurance requirements across applications, platforms, and infrastructure.
• Identify architectural risks, gaps, and areas requiring further technical definition.
• Participate in project planning, estimation, solution design, and delivery activities as the security architecture representative.
• Provide architectural guidance and implementation estimates for enterprise security initiatives.
• Develop scalable enterprise security architecture patterns, frameworks, and standards.
• Ensure alignment with enterprise governance methodologies and architectural frameworks.
• Support implementation and maintenance of security controls based on industry standards such as NIST 800 and CIS Controls.
• Integrate secure database architecture and data protection practices, including encryption, data classification, secure query design, and automated compliance controls.
• Provide architectural oversight for network security, firewall governance, segmentation strategies, and Zero Trust security models.
• Guide the secure implementation and governance of Microsoft Power Platform solutions, including connector governance, Data Loss Prevention (DLP) policies, environment strategy, and enterprise governance models.
Required Qualifications
• Extensive experience in DevSecOps, application security, and enterprise security architecture.
• Strong expertise in Secure Software Development Lifecycle (Secure SDLC) and secure-by-design principles.
• Experience designing and implementing enterprise application security testing platforms.
• Deep understanding of DevSecOps automation, CI/CD security, and application security tooling.
• Experience conducting security architecture reviews for enterprise applications, cloud platforms, and infrastructure.
• Strong knowledge of enterprise architecture frameworks and security governance practices.
• Experience with cloud security, application security, infrastructure security, and platform security.
• Knowledge of Zero Trust architecture, network segmentation, firewall governance, and access control strategies.
• Experience implementing security controls based on NIST 800, CIS Controls, and industry security standards.
• Experience with secure database architecture, encryption, data classification, and compliance controls.
• Knowledge of Microsoft Power Platform governance, including connectors, Data Loss Prevention (DLP) policies, and environment management.
• Strong documentation skills with experience producing architecture diagrams, technical specifications, and design documentation.
• Excellent analytical, communication, stakeholder management, and leadership skills.
• Experience collaborating with enterprise architects, engineering teams, and executive stakeholders.
Preferred Qualifications
• Experience working with enterprise architecture frameworks such as TOGAF.
• Experience supporting large-scale enterprise modernization and digital transformation initiatives.
• Experience implementing enterprise-wide security architecture standards and governance.
• Knowledge of modern cloud platforms, infrastructure automation, and container security.
• Experience with enterprise risk management and security compliance programs.