Dover Environmental Solutions Group

Sr Staff Engineer, Security Architect

Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Information Security, Engineering, or related field; 10 years relevant experience.
  • At least 5 years in security architecture or related security discipline.
  • Experience influencing cross-functional teams without direct authority.
  • Proven ability to engage with customers on security architecture discussions.
  • Practical experience with cloud/on-premises security architecture and PCI DSS requirements.
  • In-depth knowledge of DevSecOps processes and vulnerability management.
  • Strong communication skills for both technical and non-technical audiences.

Responsibilities

  • Define and maintain security architecture roadmap across multiple platforms.
  • Partner with teams to identify security gaps and remediation priorities.
  • Engage with customers to communicate security risks and proposed solutions.
  • Define guidelines for secure cloud and on-premises architectures.
  • Embed secure-by-design principles into the delivery lifecycle.
  • Establish and improve DevSecOps processes for security controls.
  • Collaborate with teams to assess CVEs and drive timely remediation.

Benefits

  • 401(k) savings plan with employer contributions.
  • Medical, dental, and vision insurance.
  • Wellness programs and health savings account.
  • Company paid short and long-term disability insurance.
  • Paid time off and various leave options, including parental and military leaves.
  • Employee assistance program including counseling and legal services.
Full Job Description
Position Summary:

The Security Architect partners with solution teams to define and drive the security architecture strategy across cloud platform and SaaS Solutions, Fueling dispensers, POS Platforms, Edge gateways, platforms, and delivery processes. This role defines security architecture, roadmaps, standards, and practical guidance; embeds secure-by-design and DevSecOps practices into delivery pipelines; and serves as the liaison between engineering teams and security specialists to prioritize and address CVEs. The successful candidate brings strong knowledge of fueling-industry security requirements, PCI and PCI DSS, PCI Software Security Framework (SSF), and cloud, on-premises, and network architectures.

Key Responsibilities:
• Define and maintain the security architecture roadmap across cloud, edge, applications, APIs, network, connected devices, third party integrations.
• Partner with solution, product, infrastructure, and engineering teams to assess architecture and identify security gaps, risks, and remediation priorities.
• Engage directly with customers to discuss solution security and network security architecture, clearly communicate risks and controls, and build confidence in proposed approaches.
• Define target-state security architecture, roadmaps, reference patterns, and implementation guidelines for cloud and on-premises environments.
• Embed secure-by-design principles, threat modeling, security requirements, and design reviews throughout the delivery lifecycle.
• Establish and continuously improve DevSecOps processes, including security controls and quality gates in CI/CD pipelines.
• Work with security specialists, application teams, and platform owners to triage CVEs, assess risk and exploitability, and drive timely remediation or risk acceptance.
• Define vulnerability-management expectations for software, containers, infrastructure as code, third-party components, and build artifacts.
• Guide teams on secure network architecture, including segmentation, identity and access controls, encryption, firewalling, remote connectivity, and monitoring.
• Ensure architectures and controls align with PCI, PCI DSS, PCI Software Security Framework (SSF), applicable fueling-industry security standards, and internal policies.
• Translate regulatory, customer, and security requirements into actionable engineering standards, patterns, and backlog items.
• Support security assessments, audits, customer due diligence, and evidence collection through clear architecture and control documentation.
• Develop security metrics and report that communicate risk posture, remediation progress, and roadmap outcomes.
• Provide security guidance and technical mentorship to architects, developers, and engineering leaders.
• Engage on special projects as required.

Candidate Experience and Qualification:
• Bachelor's degree in computer science, Information Security, Engineering, or a related field with a minimum of 10 years of relevant experience, or an equivalent combination of education and experience.
• Minimum of 5 years of experience in security architecture, application security, infrastructure security, or closely related security discipline.
• Experience partnering with cross-functional solution and engineering teams to influence technical decisions without direct reporting authority.
• Comfortable leading customer discussions on solution security and network security architecture, including security risks, controls, and trade-offs.
• Practical experience in the following:
• Security architecture for cloud and on-premises applications, platforms, and infrastructure.
• PCI, PCI DSS, PCI Software Security Framework (SSF), and security standards or practices relevant to the fueling industry.
• DevSecOps practices, CI/CD security controls, software composition analysis, static and dynamic testing, container security, and infrastructure-as-code security.
• Vulnerability and CVE management, including triage, prioritization, remediation planning, and risk acceptance.
• Network architecture and security, including segmentation, routing, firewalls, identity, encryption, and secure remote connectivity.
• Threat modeling, security design reviews, secure coding practices, and security requirements definition.
• Security frameworks and standards such as NIST, ISO 27001, CIS Controls, and OWASP.
• Excellent written and verbal communication skills, including the ability to explain security risks and solutions to technical and non-technical audiences.
• Demonstrated leadership, strong analytical and problem-solving skills, and a results-oriented work ethic.
• Relevant certifications such as CISSP, CCSP, or PCI ISA are a plus.
• Experience in a global environment is a plus.

Essential Functions:
• International and domestic travel may be required.
• Ability to sit for extended periods of time, including during long international flights.
• Ability to work in excess of 8 hours per day as business needs require.
• Ability to effectively and clearly communicate.
• Customer-centric mindset.
• Technology leadership mindset.
• Ability to work both independently and in a team.
• Ability to work with limited direction to attain project goals according to set timelines.

Work Arrangement: Hybrid

We consider several job-related, non-discriminatory factors when determining the pay rate for a position, including, but not limited to, the position's responsibilities, a candidate's work experience, a candidate's education/training, the position's location, and the key skills needed for the position. Pay is one of the Total Rewards that we provide to compensate and recognize employees for their work.

Benefits: Benefits for this position include: a 401(k) savings plan with employer contributions; medical, dental and vision insurance; wellness programs; health savings account, health care and dependent care flexible spending accounts; company paid short-term disability and long-term disability; company paid employee basic life and AD&D insurance; supplemental employee and dependent life insurance; optional accident, hospital indemnity and critical illness insurance; adoption, surrogacy, and fertility benefits and assistance; commuter benefits; parental, military, jury duty, and bereavement leaves of absence; paid time off, business travel services; employee discounts; and an employee assistance program that includes company paid counseling sessions and legal services. Eligibility for benefits is governed by applicable plan documents and policies.

Location:
Job Function:

#LI-TE1

About Dover Environmental Solutions Group

Dover Environmental Solutions Group is a provider of environmental solutions and services. The company offers a range of products and services, including waste management, recycling, and environmental consulting. Dover Environmental Solutions Group is a subsidiary of Dover Corporation, a diversified global manufacturer with annual revenues of over $7 billion. Dover Environmental Solutions Group is headquartered in Downers Grove, Illinois.
Learn more about Dover Environmental Solutions Group
Size
25,000 employees
Market Cap
$19.3 billion
Industry
Net Income
$683.4 million
5 Year Trend
+5.5%
Revenue
$6.6 billion
NASDAQ

Similar Jobs

More Jobs at Dover Environmental Solutions Group

More Information Technology Jobs

Find similar Sr Staff Engineer, Security Architect jobs: