Sr Security Architect Vulnerability Management

Francisco Partners

United States

On-site

USD 140,000 - 190,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Francisco Partners seeks an hands‑on Security Engineer to shape and execute a modern security vision. You will design, build, and scale a holistic vulnerability management and application security program, embedding security into software development workflows and partnering with Engineering and IT for timely remediation.

You will drive risk metrics, implement left‑shifted security controls (SAST/DAST/SCA), and maintain secure AWS architectures across hybrid environments.

Qualifications

  • At least 6 years of hands-on cybersecurity experience in senior roles.
  • Strong knowledge of AWS security services and cloud security best practices.
  • Experience with vulnerability management life cycle and secure software development.
  • Ability to define SLAs, dashboards, and drive patch compliance.
  • Comfort working with DevOps, IT, and engineering teams.
  • Experience with Terraform and cloud infrastructure security.
  • Excellent communication tailored to technical and non-technical audiences.
  • Remote work capable with strong self‑direction.

Responsibilities

  • Builds and oversees a unified vulnerability management life cycle across AWS, on‑prem, containers, and code.
  • Defines metrics and reports to leadership showing risk reduction and remediation progress.
  • Sets remediation SLAs with engineering and IT operations.
  • Integrates SAST, DAST, SCA, and secret scanning into CI/CD pipelines.
  • Expands app security controls to cover open‑source risk and secure development.
  • Maintains security standards and architectures in AWS.
  • Secures IaC and cloud configurations with automated scanning and comliance rules.
  • Collaborates with infrastructure teams to streamline patch management.
  • Monitors threat vectors and prioritizes remediation accordingly.
  • Coordinates third‑party pentests and post‑remediation verification.

Skills

Security leadership
Executive communication
Remote work adaptability
Cross-functional collaboration
Risk-based decision making

Education

Bachelor’s degree in Cybersecurity or related field

Tools

Terraform
AWS GuardDuty
AWS Security Hub
IAM
KMS
OCI?

Job description

Job Summary/Objective

Serves as a hands‑on Security Engineer to help shape and execute the company’s modern security vision. Designs, builds, and scales a holistic, end‑to‑end Vulnerability Management and Application Security program. Establishes clear risk metrics, embedding security into software development workflows, and partners closely with Engineering and IT to ensure pragmatic, timely remediation. Delivers steady, incremental security improvements without stalling engineering velocity.

Key Responsibilities & Duties (essential to the job)
  • Builds and oversees a unified Vulnerability Management Life Cycle spanning AWS cloud environments, legacy co‑located infrastructure, containers, and application code.
  • Defines, tracks, and reports on core program metrics (e.g., MTTR by severity, SLA compliance, SLA breach rates, patch coverage) to demonstrate risk reduction to executive leadership.
  • Establishes clear, risk‑based Remediation SLAs in collaboration with Engineering, DevOps, and IT Operations.
  • Shifts security "left" by embedding automated SAST, DAST, SCA, and secret‑scanning tools into modern developer pipelines (e.g., CI/CD workflows, Terraform checks).
  • Expands application security controls beyond basic infrastructure/log monitoring to cover open‑source dependency risk, code composition, and secure development practices.
  • Designs and maintains security standards and architectures within AWS.
  • Secures cloud configurations and Infrastructure as Code (IaC) templates in AWS using automated security scanning and continuous compliance rules.
  • Partners with IT Infrastructure and Systems teams to streamline patch management practices across hybrid datacenter and cloud workloads.
  • Monitors emerging threat vectors, zero‑day vulnerabilities, and active exploits (EPSS/KEV catalogs) to dynamically adapt remediation priorities.
  • Coordinates targeted vulnerability assessments, third‑party penetration testing, and post‑remediation verification.
Education

A bachelor’s degree from an accredited college or university is required, with a focus in Cybersecurity, Computer Science, Information Technology, or related discipline. In the absence of a degree, equivalent work experience directly related to the key responsibilities of the role will be considered as a substitute for the degree.

Experience, Skills and Key Competencies

At least 6 years of experience in hand‑on cybersecurity, with significant experience operating as a Senior/Lead Security Engineer or Security Architect in growing engineering organizations, demonstrated experience navigating hybrid environments, and deep practical experience writing and deploying Terraform.

Must also be able to demonstrate the following knowledge, skills and abilities:

  • Strong working knowledge of native AWS security services (GuardDuty, Security Hub, IAM, KMS, Org‑level controls).
  • Versatile, generalist knowledge across Security Operations (SecOps), SIEM architecture, Detection & Response, and Vulnerability Management life cycles.
  • Ability to build strong relationships with DevOps, IT, and software development teams through collaborative problem‑solving rather than rigid auditing.
  • Understanding of AWS architecture and Terraform configuration scanning to identify cloud‑native misconfigurations and drift.
  • Demonstrated ability to define program SLAs, build executive dashboards, and drive culture change around patch compliance and code hygiene.
  • Flexible and adaptable approach to work and can easily adjust to shifts in priorities as the needs of the business change.
  • Able to effectively work and thrive in a remote work environment that has limited opportunities for in‑person interactions.
  • Excellent communication skills and can tailor messaging to a specific audience/situation.
Special Position Requirements

Willign and able to attend virtual meetings with the laptop camera on.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Security Architect
Principal Security Architect

Francisco Partners • United States

On-site
USD 130,000 - 165,000
Senior Security Engineer
Senior Security Engineer

Novacoast • Salt Lake City (UT)

On-site
USD 100,000 - 130,000
Senior Security Engineer
Senior Security Engineer

Spinwheel Solutions, Inc. • United States

On-site
USD 140,000 - 190,000
Cybersecurity Engineer
Cybersecurity Engineer

OneImaging • Bellevue (WA)

On-site
USD 100,000 - 130,000
Health Care Plan
Retirement Plan
Paid Time Off
+2
Cybersecurity Engineer - Cloud, Ops (human)
Cybersecurity Engineer - Cloud, Ops (human)

NEURA Robotics • Germany (OH)

On-site
USD 120,000 - 160,000
Security Engineer
Security Engineer

Semaphore Technologies doo • United States

Remote
USD 120,000 - 180,000
Principal Security Engineer
Principal Security Engineer

Jobtailor • Town of Texas (WI)

On-site
USD 140,000 - 190,000
Sr. Security Engineer
Sr. Security Engineer

California Water Service • San Jose (CA)

On-site
USD 180,000 - 240,000
Senior Security Engineer
Senior Security Engineer

Hiring Our Heroes • Arlington (VA)

On-site
USD 120,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Zermount, Inc. • United States Virgin Islands

On-site
USD 100,000 - 150,000