This role sits at the intersection of software engineering, application security, and infrastructure architecture. The Security Architect will help define how systems are designed, reviewed, and protected across the organization, with particular emphasis on backend security, cloud environments, and secure development practices.
Responsibilities:
- Define and evolve security architecture across applications, services, and infrastructure.
- Partner with engineering teams to design secure software systems, with particular focus on backend and data security.
- Conduct threat modeling, risk assessments, architecture reviews, and security reviews for new and existing systems.
- Establish and improve secure coding standards, development practices, and review processes.
- Collaborate with DevOps on cloud security, container security, CI/CD hardening, and access controls.
- Evaluate and implement security tools supporting vulnerability management, code scanning, and incident response.
- Provide technical guidance and mentorship on secure application development.
- Monitor emerging threats, security practices, and relevant compliance standards.
Qualifications:
- 10+ years of experience in software engineering or security architecture roles.
- Strong full-stack engineering background with deep backend security expertise.
- Experience with languages such as Python, Go, C/C++, Rust, or similar.
- Demonstrated experience designing or securing systems in fintech, banking, digital assets, or other security-critical environments.
- Strong knowledge of cryptography, authentication, authorization, and key management.
- Hands-on experience with cloud security platforms such as AWS, GCP, or similar.
- Experience with threat modeling, secure SDLC practices, and application security frameworks such as OWASP, NIST, or ISO 27001.
- Strong communication skills with the ability to explain technical risks and security recommendations to both technical and non-technical stakeholders.
- Experience with blockchain or distributed ledger technologies (preferred).
- Contributions to open-source security projects or tooling (preferred).
- Security certifications such as CISSP, OSCP, CEH, or equivalent (preferred).