Job Title: Security Architect with Java exp
Location: Austin`, TX
Duration: Contract
Rate : $65/Hr on C2C
Role Summary
We are looking for a Security Architect to own the security architecture and design assurance of enterprise web applications and services. You will review and define application security architecture, identify design-level weaknesses, specify the correct target-state design, and establish reusable secure-design patterns and assurance standards that engineering teams build to.
This is a design-authority role. The emphasis is on architectural judgement - trust boundaries, identity and authorization models, and data-protection design - rather than on tool operation or test execution.
Key Responsibilities
Security architecture and design review
- Review the security architecture of enterprise applications and services: trust boundaries, identity and tenancy models, authorization models, and sensitive-data flows
- Conduct threat modelling (STRIDE or equivalent) with engineering teams and derive prioritized, testable review plans from the model
- Identify design-level weaknesses that automated tooling does not surface - perimeter and gateway bypass, internal-trust assumptions that fail under external exposure, loss of end-user identity across service-to-service hops, and client-side-enforced tenant isolation
- Review authentication and authorization architecture: OAuth2/OIDC usage, token validation completeness, service-to-service authentication, and object- and function-level authorization across roles and tenants
- Review data-protection design: encryption in transit and at rest, key management, secrets handling, and logging hygiene for sensitive data
- Review platform architecture: container and Kubernetes security posture, infrastructure-as-code, and cloud IAM least privilege
Target-state design and patterns
- Specify target-state designs for architectural weaknesses, not problem statements alone
- Develop and publish reusable secure-design patterns and reference architectures for adoption across engineering teams
- Act as the design authority engineering teams consult before implementing security remediation
- Feed systemic recommendations into SDLC and CI/CD controls to prevent recurrence
Assurance and standards
- Define security review standards, assessment criteria and scoring or rating models, and defend them under challenge
- Assess applications against those standards and produce the resulting assurance findings and ratings
- Provide technical direction and quality assurance for a small security review team, including offshore members
- Mentor engineers in architecture-level security review
Stakeholder engagement
- Partner with central information security functions on assessment scope, coverage and findings
- Advise application owners and engineering leads on remediation design and prioritization
- Escalate risks and blockers clearly and early
Required Skills and Experience
- 10+ years in application or product security, including time in a named security architect or design authority role on enterprise systems
- Demonstrable track record of identifying design-level security weaknesses and specifying target-state designs that were adopted
- Experience authoring reference architectures or secure-design patterns used by multiple engineering teams
- Experience on, or running, an architecture or design review board or equivalent design gate
- Threat modelling at architecture level, including facilitating sessions with teams new to the practice
- Java and Spring Boot secure design and code review, including Spring Security and API gateway layers; awareness of reactive/non-blocking codebases
- Identity and access architecture - OAuth2/OIDC, JWT validation, federated enterprise identity providers, service-to-service authentication (HMAC-signed requests, app-to-app token exchange), session and token lifecycle
- Multi-tenant authorization architecture - broken object- and function-level authorization, tenant isolation design and verification
- Cloud and container security architecture - Kubernetes and Helm, container hardening, infrastructure-as-code review, cloud IAM across at least two major providers
- Working knowledge of OWASP ASVS, OWASP Top 10, OWASP API Security Top 10, and CVSS v4.0
- Experience handling confidential or regulated data under a formal classification scheme
- Ability to build the security model of a proprietary or undocumented internal framework from its source code
- Strong written communication - designs, findings and rationale must be actionable by engineers
- Ability to influence without direct authority, and to work credibly with both central security functions and delivery teams
Preferred
- AI / LLM application security architecture - retrieval-augmented generation design, tenant isolation on retrieval, prompt and template provenance, treating model output as untrusted, agent and tool credential scope, Model Context Protocol (MCP) exposure
- Hands-on security testing or penetration testing background, sufficient to validate and demonstrate a finding
- API security architecture and authorization-matrix testing
- Software supply chain, SBOM and dependency risk management
- Experience establishing a security assurance programme where no formal process previously existed
- Familiarity with enterprise CI/CD security gates (SAST, SCA, secrets scanning)
Certifications
Demonstrable architectural depth is weighted above certification. One or more of the following is expected:
- CISSP, CSSLP, CISSP-ISSAP, or SABSA
- Valuable additions: CCSP, CKS, OSCP, GWAPT, or a recognized threat-modelling credential