Security Architecture Engineer, STORM

United States Digital Space LLC

Warsaw (IN)

Hybrid

USD 90,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

United States Digital Space LLC is seeking a collaborative Security Architecture Engineer to join their Warsaw office. This role will lead security design reviews and contribute to building robust security frameworks to protect users and ensure compliance with industry standards.

With responsibilities spanning threat modelling, code reviews, and AI governance, candidates must possess over 7 years of relevant experience. This position operates on a hybrid schedule, primarily in office on key days.

Qualifications

  • 7+ years of experience in security roles with a focus on security architecture.
  • Hands-on proficiency with threat modelling methodologies.
  • Competency in conducting security-focused code reviews.

Responsibilities

  • Lead architecture reviews and structured threat modelling for projects.
  • Conduct security-focused code reviews and analyze data flows.
  • Develop governance practices for AI-augmented development workflows.

Skills

Security architecture
Application security
Threat modelling
Code reviews
Compliance frameworks
Authentication mechanisms

Job description

STORM (Security Threat Operations & Response Management) is the company's security operations organization, made up of red and blue team specialists focused on protecting the company's employees, users, and customers. We proactively address threats, embed security across the product lifecycle, and partner closely with the company's broader R&D and engineering teams to make security-by-design the norm. We are looking for a collaborative, analytical Security Architecture Engineer to join our team in Warsaw to solve complex design challenges and scale our architectural security defenses.

This role is based in our Warsaw office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do and the teams with which you partner. If you're interview ing for this role, your recruiter will share more about the in-office requirements.

We offer a Contract of Employment (UoP) for our employees in Poland.

What you’ll achieve
  • Security Design Review & Threat Modelling: Lead architecture reviews and structured threat modelling (such as STRIDE, OWASP Threat Dragon, and MITRE ATT&CK) for new and in-flight projects to identify risk early and produce actionable guidance before code is written.

  • Code & Data Flow Analysis: Conduct security-focused code reviews and analyze data flows across services, APIs, and integrations to identify trust boundaries and attack surface reduction opportunities.

  • Defensive Engineering Recommendations: Translate threat model findings into concrete engineering recommendations and feed architectural weaknesses to STORM’s red team for proactive adversary emulation planning.

  • Architecture Standards & Frameworks: Build and mature the company’s security architecture review process and define standards aligned to industry best practices like NIST 800-53, FedRAMP, ISO 27001, and OWASP ASVS.

  • Security Pattern Library: Develop and maintain a reusable security pattern library for authentication, authorization, encryption, API security, and data handling that engineering teams can adopt directly.

  • AI Security Architecture: Evaluate AI tooling and integrations using industry standards (such as OWASP Maestro and OWASP Top 10 for LLMs), assessing risks including prompt injection, model misuse, data leakage, and supply chain exposure.

  • AI Governance: Develop governance practices for AI-augmented development workflows and stay current with the evolving AI security landscape.

  • Security Artifact Advocacy: Champion security-by-design by driving organizational adoption of architecture diagrams, data flow diagrams, and threat models as first-class engineering artefacts.

  • Training & Culture: Deliver highly technical training and workshops to engineering and product teams, making the secure choice the path of least resistance across the organization.

About you
  • 7+ years of progressive experience in security roles, with a focus on security architecture, application security, or high-scale design reviews.

  • Hands‑on proficiency with threat modelling methodologies (STRIDE/PASTA, OWASP Threat Dragon) and the MITRE ATT&CK framework at the TTP level.

  • Competency conducting security-focused code reviews across modern languages, including Python, Go, Java, or TypeScript.

  • Deep functional knowledge of compliance frameworks and baselines, including NIST 800-53, FedRAMP, ISO 27001, OWASP ASVS, and the AWS Well-Architected Security pillar.

  • Strong understanding of authentication/authorisation mechanisms (OAuth 2.0, OIDC, SAML, SSO) and container infrastructure security (Kubernetes RBAC, pod security, network policies, and secrets management).

  • Familiarity with emerging AI security standards, specifically the OWASP Top 10 for LLMs, OWASP Maestro, or securing multi-tenant SaaS platforms.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, Offensive Security
Manager, Offensive Security

United States Digital Space LLC • Warsaw (IN)

Hybrid
USD 80,000 - 113,000
Senior Security Architect for Threat Modeling & AI Security
Senior Security Architect for Threat Modeling & AI Security

United States Digital Space LLC • Warsaw (IN)

Hybrid
USD 90,000 - 120,000
Security Architect (AI Specialist)
Security Architect (AI Specialist)

smithnephew • Town of Poland (NY)

Hybrid
USD 150,000 - 190,000
Generous annual bonus
Life insurance and health plans
Share options / equity
+1
Staff Security Engineer (Product Security and Architecture)
Staff Security Engineer (Product Security and Architecture)

Compass • Ventura (CA)

On-site
USD 150,000 - 230,000
Platform & Security Engineer (m/f/d)
Platform & Security Engineer (m/f/d)

SportAlliance • Town of Poland (NY)

Hybrid
USD 21,000 - 26,000
Private medical care
Sports card
Access to Udemy Business courses
+3
Senior Application Security Architect
Senior Application Security Architect

Jobtailor • Cary (NC)

On-site
USD 120,000 - 180,000
Product Security Architect (m/k) – Kraków (Małopolskie), Polska Astek
Product Security Architect (m/k) – Kraków (Małopolskie), Polska Astek

ASTEK Polska Sp. z o.o. • Town of Poland (NY)

Hybrid
USD 47,000 - 69,000
Long-term collaboration
Technical training and certification
Mentoring via Competence Center
+3
Security Architect
Security Architect

SQA Solution • United States

On-site
USD 140,000 - 200,000
Application Security Architect
Application Security Architect

Alarm.com • Tysons (VA)

On-site
USD 140,000 - 210,000
Enterprise Security Architect (ID: 3650)
Enterprise Security Architect (ID: 3650)

Stafide • Netherlands (MO)

On-site
USD 140,000 - 190,000