Sr Security Architect Vulnerability Management

OEConnection LLC

Northern (KY)

Hybrid

USD 120,000 - 180,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

OEConnection LLC is seeking a hands-on Security Engineer to shape and execute a modern security vision. You will design, build, and scale a holistic vulnerability management and application security program across AWS, hybrid infrastructure, and modern developer pipelines.

Collaborate with Engineering and IT to embed security into software development, establish risk metrics, and deliver steady improvements without slowing velocity.

Qualifications

  • Bachelor-level degree required or equivalent work experience in Cybersecurity/CS/IT.
  • At least 6 years of hands-on cybersecurity experience with Senior/Lead Security Engineer or Security Architect roles.
  • Experience operating in hybrid environments and deploying Terraform in production.

Responsibilities

  • Build and manage a unified Vulnerability Management Lifecycle across AWS, on-premises, containers, and code.
  • Define and report program metrics (MTTR, SLA, patch coverage) to leadership.
  • Set remediation SLAs with Engineering, DevOps, and IT Operations.
  • Embed SAST/DAST/SCA and secret-scanning into CI/CD pipelines and Terraform checks.
  • Expand controls to cover open-source dependencies, code hygiene, and secure development.
  • Design and maintain security architectures within AWS and IaC templates.
  • Coordinate patch management across hybrid workloads.
  • Track emerging threats and adjust remediation priorities accordingly.
  • Coordinate external security assessments and post-remediation verification.

Skills

Cloud security
Terraform
SAST/DAST/ SCA
SIEM & SecOps
Threat monitoring
AWS security services
Security governance
Remediation leadership

Education

Bachelor's degree in Cybersecurity/CS/IT

Tools

Terraform
Cloud security tooling

Job description

United States

Posted Tuesday, August 11, 2026 at 4:00 AM

OEC provides software solutions to those who work in the automotive parts and repair industry. Our solutions make it easier for automotive industry professionals to buy and sell parts, conduct repair research & planning, optimize estimates, improve the parts supply chain, and more. OEC partners with many of the world’s largest manufacturers, dealers and suppliers, shops and repairers, and service providers, giving our customers access to a comprehensive network and a streamlined workflow.

Job Summary/Objective

Serves as a hands-on Security Engineer to help shape and execute the company’s modern security vision. Designs, builds, and scales a holistic, end-to-end Vulnerability Management and Application Security program. Establishes clear risk metrics, embedding security into software development workflows, and partners closely with Engineering and IT to ensure pragmatic, timely remediation. Delivers steady, incremental security improvements without stalling engineering velocity.

Key Responsibilities & Duties (essential to the job)

  • Builds and oversees a unified Vulnerability Management Life Cycle spanning AWS cloud environments, legacy co-located infrastructure, containers, and application code.
  • Defines, tracks, and reports on core program metrics (e.g., MTTR by severity, SLA compliance, SLA breach rates, patch coverage) to demonstrate risk reduction to executive leadership.
  • Establishes clear, risk-based Remediation SLAs in collaboration with Engineering, DevOps, and IT Operations.
  • Shifts security "left" by embedding automated SAST, DAST, SCA, and secret-scanning tools into modern developer pipelines (e.g., CI/CD workflows, Terraform checks).
  • Expands application security controls beyond basic infrastructure/log monitoring to cover open-source dependency risk, code composition, and secure development practices.
  • Designs and maintains security standards and architectures within AWS.
  • Secures cloud configurations and Infrastructure as Code (IaC) templates in AWS using automated security scanning and continuous compliance rules.
  • Partners with IT Infrastructure and Systems teams to streamline patch management practices across hybrid datacenter and cloud workloads.
  • Monitors emerging threat vectors, zero-day vulnerabilities, and active exploits (EPSS/KEV catalogs) to dynamically adapt remediation priorities.
  • Coordinates targeted vulnerability assessments, third-party penetration testing, and post-remediation verification.

Education

A bachelor's degree from an accredited college or university is required, with a focus in Cybersecurity, Computer Science, Information Technology, or related discipline. In the absence of a degree, equivalent work experience directly related to the key responsibilities of the role will be considered as a substitute for the degree.

Experience, Skills and Key Competencies

At least 6 years of experience in hand-on cybersecurity, with significant experience operating as a Senior/Lead Security Engineer or Security Architect in growing engineering organizations, demonstrated experience navigating hybrid environments, and deep practical experience writing and deploying Terraform.

Experience, Skills and Key Competencies (continued)

Must also be able to demonstrate the following knowledge, skills and abilities:

  • Strong working knowledge of native AWS security services (GuardDuty, Security Hub, IAM, KMS, Org-level controls).
  • Versatile, generalist knowledge across Security Operations (SecOps), SIEM architecture, Detection & Response, and Vulnerability Management life cycles.
  • Ability to build strong relationships with DevOps, IT, and software development teams through collaborative problem-solving rather than rigid auditing.
  • Understanding of AWS architecture and Terraform configuration scanning to identify cloud-native misconfigurations and drift.
  • Demonstrated ability to define program SLAs, build executive dashboards, and drive culture change around patch compliance and code hygiene.
  • Flexible and adaptable approach to work and can easily adjust to shifts in priorities as the needs of the business change.
  • Able to effectively work and thrive in a remote work environment that has limited opportunities for in-person interactions.
  • Excellent communication skills and can tailor messaging to a specific audience/situation.

Special Position Requirements

  • Willing and able to attend virtual meetings with the laptop camera on.

What makes working at OEC awesome? It varies from employee to employee. For some, it's the flexibility - whether it's remote work or a hybrid or in-person role, OEC takes our teams across multiple time zones and international communities. For others, it's the strong sense of camaraderie and community that celebrates both individuals and team-driven contributions. Or it could be the empowerment and how the team is encouraged to take risks, learn, and grow within a dynamic and supportive environment. But no matter what gets us out of bed in the morning, our whole global community is inspired to be forward thinking and drive innovative solutions for the automotive parts and repair industry.

OEConnection is subject to certain governmental recordkeeping and reporting requirements for the administration of civil rights laws and regulations. In order to comply with these laws, we invite applicants and employees to voluntarily self-identify their gender, race and ethnicity. Submission of this information is strictly voluntary and refusal to provide it will not subject you to any adverse treatment. The information obtained will be kept confidential and may only be used in accordance with the provision of applicable laws, executive orders, and regulations, including those that require the information to be summarized and reported to the federal government for civil rights enforcement. When reported, data will not identify any specific individual. This information will be maintained separately from your application for employment. If you do not wish to self-identify at this time, you may do so in the future by submitting this form. Failure to provide the following information will not subject you to any adverse action or treatment. OEConnection is an Equal Opportunity/ Affirmative Action employer. We provide equal employment opportunities to all qualified employees and applicants for employment without regard to race, religion, sex, age, marital status, national origin, sexual orientation, citizenship status, veteran status, disability or any other legally protected status. We prohibit discrimination in decisions concerning recruitment, hiring, compensation, benefits, training, termination, promotions, or any other condition of employment or career development.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Security Architect
Principal Security Architect

OEConnection LLC • Northern (KY)

Hybrid
USD 120,000 - 180,000
Remote work options
Application Development Architect
Application Development Architect

OEC • Atlanta (GA)

Remote
USD 110,000 - 130,000
Full benefits starting Day 1: Medical, Dental, and Vision
401(k) with company match
Unlimited Flex Time Off plus 10 company-paid holidays
+4
Application Development Architect
Application Development Architect

OEConnection LLC • Austin (TX)

Remote
USD 100,000 - 130,000
Medical, Dental, and Vision benefits
401(k) with company match
Remote-first role
+3
Senior Platform Engineer (Cloud & AI Platform)- Remote within US
Senior Platform Engineer (Cloud & AI Platform)- Remote within US

OEC • United States

Hybrid
USD 130,000 - 190,000
Senior Software Engineer, Platform (Full Stack)
Senior Software Engineer, Platform (Full Stack)

name • United States

Remote
USD 140,000 - 180,000
Medical, dental, vision
401(k) with match
Remote-friendly with stipend
Sr DBA- Remote within the US
Sr DBA- Remote within the US

OEC • United States

Hybrid
USD 150,000 - 210,000
Sr DBA- Remote within the US
Sr DBA- Remote within the US

OEConnection LLC • United States

Hybrid
USD 120,000 - 180,000
Senior Identity & Access Architect- Atlanta, GA, Austin, TX or Cleveland, OH
Senior Identity & Access Architect- Atlanta, GA, Austin, TX or Cleveland, OH

OEC • Atlanta (GA)

Hybrid
USD 100,000 - 130,000
Medical, Dental, and Vision Benefits
401(k) with company match
Unlimited Flex Time Off
+2
Remote Security Architect — Vulnerability & AppSec Leader
Remote Security Architect — Vulnerability & AppSec Leader

OEConnection LLC • Northern (KY)

Hybrid
USD 120,000 - 180,000
IT Principal Premium Support Specialist- Hybrid in Austin, TX
IT Principal Premium Support Specialist- Hybrid in Austin, TX

OEC • Austin (TX)

On-site
USD 120,000 - 180,000
Medical, Dental, Vision benefits
401(k) with company match
Unlimited vacation/personal time off