Opportunity DetailsQRR-4734
Senior Director, Security Architect (USA - Remote)US - Remote
Senior Director, Security Architect Location: Houston, Texas (preferred) or United States - Remote Model of Work: Hybrid if located in Houston, TX or Remote with Travel if the work location is United States - Remote Overview The Security Architect is the senior technical authority for security across the software products, cloud platforms, data, and AI systems built and operated by Quorum's Product, Innovation & Engineering (PIE) function. As a global software company serving the energy industry, the products we ship help operate and optimize critical infrastructure worldwide - which makes security a foundational requirement, a recurring subject of rigorous customer assurance, and a competitive differentiator rather than an afterthought.
Operating at the intersection of engineering and security, the Security Architect defines and drives the "build-side" security mandate: secure software development, cloud infrastructure hardening on Azure, product data protection, customer-facing identity and tenant isolation, and the fast-emerging discipline of securing AI and agentic systems. The role owns architecture and implementation for everything PIE is accountable for, implements enterprise standards set by the CISO where the two intersect, and advises on adjacent corporate-security decisions - while deliberately staying out of the corporate IT security domains owned elsewhere.
This is a hands-on architecture role. The Security Architect sets technical direction, produces reference architectures, threat models, and guardrails, and works shoulder-to-shoulder with engineering teams to make the secure path the default path.
Responsibilities Application & Software Security - Own the secure SDLC: define and evolve security gates across design, build, and release - threat modeling, secure-by-design patterns, and paved-road guardrails that engineering teams adopt by default.
- Drive SAST, DAST, and SCA: select, integrate, and tune application- and dependency-scanning tooling in CI/CD, keeping signal high and friction low, and set the standards for triage and remediation SLAs.
- Govern AI-generated code: establish review, provenance, and scanning controls specifically for code produced with AI assistants, treating it as a first-class supply-chain and quality risk.
- Secrets management: architect enterprise-grade secret storage, rotation, and detection so credentials never live in source or pipelines.
- Partner on offensive testing: act as the technical counterpart for CISO-commissioned application pentests and red-team exercises, and own remediation of the findings within PIE.
Cloud Infrastructure Security (Azure) - Secure the Azure landing zone: own the security architecture of subscriptions, network topology, private endpoints, and in-cloud segmentation for product and platform workloads.
- Policy-as-code & CSPM: codify guardrails (e.g., Azure Policy, Bicep/Terraform, Defender for Cloud) so misconfiguration is prevented at deploy time and continuously detected at runtime.
- Implement cloud IAM/PAM: operationalize the enterprise standard for MFA, just-in-time access, and service-account hygiene across cloud workloads, in line with CISO-set requirements.
Product & Customer Data Security - Protect product and customer data: architect encryption (at rest and in transit), key management, and DLP controls across the product estate.
- Data classification & governance: embed classification within DaWinci and the Data-as-a-Product model so sensitivity is known, enforced, and auditable across data products.
- Align to enterprise policy: implement product data protection consistent with CISO enterprise data policy, and engage Legal where privacy and contractual obligations apply.
AI / ML Security & Governance - Secure the AI platform: own security architecture for AI Foundry workloads and the agentic layer, including MCP/A2A agent access, scoping, and authorization.
- Defend against AI-specific threats: design controls for data leakage, prompt injection, insecure tool/agent use, and model supply-chain and vendor risk.
- Advise enterprise AI policy: as a consulted expert, inform the CISO/Legal-owned policy on what data may reach any LLM and how AI tools are used across the company.
Product Identity & Tenant Isolation - Own customer-facing identity: architect authentication and authorization for the products (OAuth2/OIDC, token and session design, least-privilege authorization models).
- Guarantee tenant isolation: ensure robust multi-tenant separation so one customer can never reach another's data or compute - a non-negotiable for energy-sector clients.
Incident Response, Compliance & Assurance - Detect and contain product/cloud incidents: build detection, containment, and forensics capability for product and cloud security events, operating within the CISO-owned enterprise IR program.
- Provide audit evidence: generate and maintain product- and cloud-side evidence for SOC 2, ISO 27001, and other frameworks, and respond authoritatively to customer security questionnaires.
- Advise on vendor risk: support security review of product-embedded vendors and LLM providers as a consulted party to the CISO-owned vendor-risk process.
And other duties as assigned. Requirements - Substantial experience (typically 8+ years) in security engineering or architecture, with a strong software-product and cloud-native focus.
- Demonstrated ownership of security architecture for production SaaS/cloud products, ideally in a regulated or high-assurance context.
- Deep hands-on Azure security expertise - landing zones, CSPM/Defender for Cloud, Azure Policy, private networking, and infrastructure-as-code (Bicep or Terraform).
- Proven secure-SDLC / DevSecOps practice - threat modeling and SAST/DAST/SCA and secrets management embedded in CI/CD.
- Strong grasp of cloud-native identity - OAuth2/OIDC, authorization models, and multi-tenant isolation.
- Working command of compliance frameworks relevant to product assurance - SOC 2, ISO 27001, and customer security questionnaires.
- Excellent communication and influence - able to align engineers, product leaders, and the CISO organization around a shared security direction.
Strongly Preferred Skills - Practical experience securing AI/ML and agentic systems - LLM application security, prompt-injection and data-leakage defenses, MCP/A2A or comparable agent frameworks, and model/vendor risk.
- Background serving the energy sector or other critical-infrastructure industries, with an appreciation of their heightened assurance and resilience expectations.
- Data-security depth - encryption and key management, DLP, and data classification within data-mesh / Data-as-a-Product architectures.
- Relevant certifications such as CISSP, CCSP, Azure Security Engineer / Cybersecurity Architect Expert, or SABSA/TOGAF.
Additional Details - Background Check : The successful candidate will need to successfully complete the following clearances: Criminal History Check, Education Verification, Employment Verification, Driver's License Verification and passport/ID validation.
- Visa Sponsorship : Employment eligibility to work with Quorum Software in the United States is required as the company will not pursue visa sponsorship for this position. The successful candidate will be required to ensure they maintain and renew any visas or permits that grant employment eligibility where applicable.