Description
Summary:
Seeking a Security Architect to assess and elevate security across applications, infrastructure, cloud, and data platforms, embedding secure-by-design practices from early design to release.
Highlights:
1. Collaborate with engineering, infrastructure, and business teams
2. Serve as a trusted advisor on security architecture
3. Opportunity to work on international projects with top brands
We are looking for a **Security Architect** to assess and elevate security across applications, infrastructure, cloud environments, and data platforms. You will collaborate with engineering, infrastructure, and business teams to embed secure\-by\-design practices from early design through release. Apply now to help keep systems resilient, compliant, and aligned with best practices.
**Responsibilities**
* Conduct end\-to\-end security architecture reviews for applications, SaaS platforms, and infrastructure initiatives
* Assess proposed designs against established security standards, surface gaps and risks, and recommend practical mitigations
* Partner with project teams early in the design lifecycle to ensure secure\-by\-design principles are implemented
* Perform data risk assessments by mapping data flows across systems, storage locations, and access paths
* Provide architectural guidance on data security tooling such as Databricks security configurations and Varonis for data classification, access auditing, and insider threat monitoring
* Lead security assessments of cloud environments and workloads, reviewing configurations, network segmentation, identity boundaries, logging, and workload protections
* Provide architectural oversight for application security activities including penetration testing, SAST, and DAST
* Review API security designs covering authentication, authorization, rate limiting, and correct handling of API keys, secrets, and tokens via approved secrets management solutions
* Apply IAM and PAM principles to architectural decisions, ensuring least privilege, separation of duties, and strong authentication patterns
* Champion phishing\-resistant MFA approaches across critical systems and advise on MDM and MAM strategies for mobile and endpoint devices
* Evaluate network architectures, segmentation strategies, and perimeter and zero\-trust controls, and collaborate on vulnerability remediation
* Serve as a trusted advisor on security architecture, document architectural decisions, and maintain reference architectures and security patterns
**Requirements**
* 3\+ years of experience conducting security architecture reviews for applications, SaaS solutions, and infrastructure
* Strong background in data security, including data flow analysis, data risk assessments, and tooling such as Databricks and Varonis
* Hands\-on experience with cloud security assessments and cloud\-native security controls
* Solid understanding of API security patterns and handling of keys, secrets, and tokens
* Working knowledge of IAM and PAM concepts, including authentication, authorization, privilege management, and identity governance
* Familiarity with phishing\-resistant MFA technologies and modern authentication standards
* Knowledge of MDM and MAM platforms and mobile/endpoint security approaches
* Understanding of networking fundamentals (TCP/IP, segmentation, firewalls) and vulnerability remediation practices
* Application security experience, including familiarity with penetration testing, SAST, and DAST tools and processes
* Experience with Cyber Resilience capabilities and Disaster Recovery technologies
* Ability to translate complex security concepts into clear, actionable recommendations for technical and non\-technical audiences
* Excellent written and verbal communication skills, with experience producing architecture documents, assessment reports, and design diagrams
* English proficiency at B2 level or higher
**Nice to have**
* Certifications such as CISSP, CCSP, SABSA, or AWS/Azure/GCP security certifications
* Experience aligning security architecture work to frameworks such as NIST CSF, ISO 27001, CIS, or zero\-trust reference models
* Prior experience in regulated environments (e.g., HIPAA, PCI, SOX, GDPR)
**We offer**
* International projects with top brands
* Work with global teams of highly skilled, diverse peers
* Healthcare benefits
* Employee financial programs
* Paid time off and sick leave
* Upskilling, reskilling and certification courses
* Unlimited access to the LinkedIn Learning library and 22,000\+ courses
* Global career opportunities
* Volunteer and community involvement opportunities
* EPAM Employee Groups
* Award\-winning culture recognized by Glassdoor, Newsweek and LinkedIn