Quick Overview
Seniority
Mid Senior
Work mode
Hybrid
Location
Princeton, NJ, United States
Posted
18 hours ago
MicroservicesAWSEncryptionMFAOAuthOWASPPCI DSSSAMLSOC 2SSOAzureGDPRGoogle CloudHIPAAJWTKubernetesLLMPenetration TestingPowerShellPythonTerraformWAFZero Trust
Job Description
Job Title: Cyber Security Architect
Location: Princeton, NJ & NYC, NY (Hybrid)
Location: Princeton, NJ & NYC, NY (Hybrid)
Key responsibilities:
- Define and maintain the organization's cybersecurity strategy, principles, standards, and reference architectures.
- Design secure architectures for enterprise applications, networks, cloud platforms, APIs, data platforms, and infrastructure.
- Translate business, regulatory, and technical requirements into security controls and architecture patterns.
- Conduct threat modelling, attack-surface analysis, security risk assessments, and architecture reviews.
- Identify vulnerabilities, design gaps, single points of failure, and risks introduced by new technologies or system integrations.
- Define security controls for confidentiality, integrity, availability, authentication, authorization, monitoring, and data protection.
- Establish defense-in-depth strategies covering identity, network, endpoint, application, data, and cloud security.
- Review solution designs, technical specifications, infrastructure-as-code, and implementation plans for security compliance.
- Guide development and engineering teams in secure design, secure coding, DevSecOps, and security testing practices.
- Design and govern identity and access management solutions, including SSO, MFA, RBAC, ABAC, PAM, and zero-trust controls.
- Define security requirements for firewalls, WAF, VPN, IDS/IPS, SIEM, EDR, DLP, secrets management, and endpoint protection.
- Develop cloud-security architectures for AWS, Azure, or Google Cloud environments.
- Establish security logging, monitoring, alerting, detection, and incident-response requirements.
- Support vulnerability assessments, penetration testing, configuration reviews, and remediation planning.
- Assist incident-response and business-continuity teams during major security events.
- Evaluate security products, technologies, vendors, and managed security services.
- Maintain security architecture documentation, standards, diagrams, risk registers, and control mappings.
- Support audits and compliance initiatives involving ISO 27001, SOC 2, PCI DSS, GDPR, HIPAA, or applicable regulatory frameworks.
- Track changes in the threat landscape and update security controls and architecture accordingly.coursera+2
Required qualifications:
- 8 12 years of experience in cybersecurity, information security, infrastructure security, cloud security, or security architecture.
- 3+ years of experience designing and reviewing enterprise security architectures.
- Strong knowledge of network security, application security, cloud security, IAM, cryptography, and security operations.
- Experience with threat modelling frameworks such as STRIDE, MITRE ATT&CK, or equivalent methodologies.
- Strong understanding of security principles including least privilege, zero trust, defense in depth, secure-by-design, and separation of duties.
- Experience conducting security risk assessments and developing risk-treatment plans.
- Hands-on knowledge of security controls, vulnerabilities, penetration testing, incident response, and disaster recovery.
- Experience working with architecture frameworks, security policies, control standards, and governance processes.
- Strong communication skills, with the ability to explain complex security risks to technical and business stakeholders.
- Demonstrated ability to influence engineering teams and drive security improvements across projects.
Preferred qualifications:
- Experience securing AWS, Azure, or Google Cloud environments.
- Knowledge of Kubernetes, containers, service meshes, serverless systems, and cloud-native architectures.
- Experience with DevSecOps tools, CI/CD security, SAST, DAST, SCA, IaC scanning, secrets scanning, and container security.
- Familiarity with SIEM, SOAR, EDR, XDR, WAF, CSPM, CNAPP, DLP, and vulnerability-management platforms.
- Experience with API security, microservices security, OAuth 2.0, OpenID Connect, SAML, and JWT.
- Knowledge of data classification, encryption, tokenization, key management, and privacy engineering.
- Experience with security automation using Python, PowerShell, Terraform, or similar tools.
- Familiarity with AI/ML security, LLM application security, prompt injection, data leakage, and model governance.
- Experience with regulatory and security frameworks such as NIST CSF, NIST SP 800-53, CIS Controls, ISO 27001, SABSA, COBIT, and OWASP.
- Professional certifications such as CISSP, CCSP, SABSA, CISM, GIAC, AWS Security Specialty, or Azure Security Engineer.
Similar jobs
- XP
Senior Cybersecurity Engineer | Cyber Threat Intelligence & Response
NewXplor
Atlanta, GA🇺🇸Remote8 hours agoAWSPCI DSSActive Directory+6Technology - TC
Cyber Security Architect
NewTECHNEPTUNE CONSULTING INC
Princeton, NJ🇺🇸Hybrid18 hours agoMicroservicesAWSEncryption+14Technology - SI
Senior Application Security Engineer
NewSource Infotech
New York, NY🇺🇸Hybrid18 hours agoOWASPLLMPythonTechnology - IN
Product Sales Security Specialist - Enterprise - New York
NewInfoblox
United States🇺🇸$145k - $165k/yrRemote7 hours agoBusiness DevelopmentMEDDICSales - RI
IAM Engineer
NewRIIM
North Kansas City, MO🇺🇸Hybrid18 hours agoMFASSOAzure+2Technology - TE
Cyber Security Engineer - Wilmington, DE, Fairfax, VA, Washington, DC, Silver Spring, MD, Philadelphia, PA
NewTechniPros, LLC
Wilmington, DE🇺🇸Hybrid18 hours agoSpringAWSMFA+7Technology