Principal Product Security Architect
Company
Early Warning
Location
Phoenix – Mesa – Scottsdale, AZ
Type
Full Time
Job Description
From fast money movement for over 100 million people who can access Zelle® directly through their banking app to new account opening and beyond - we make a difference in the lives of consumers and businesses every day and enable them to live their best financial lives. And we're only getting started.
With new state-of the-art offices in Scottsdale, AZ (Headquarters) and Chicago, IL - plus a growing presence in San Francisco - we're entering our next big chapter. We focus all hiring efforts in a few states and within driving distance of an office location to enable in-person collaboration when and where possible. Priority hiring locations are Scottsdale, AZ, Illinois, NY tri-state metro area (New Jersey, New York and Connecticut) and San Francisco, CA. On exception we will hire in secondary locations such as District of Columbia, Florida, Georgia, Maryland, Nevada, North Carolina, South Carolina, Texas and Virginia. We are not actively recruiting in Colorado, Rhode Island or Washington.
People matter to us, so we think our best work is done when we're together, in-person. From informal interactions, to sharing ideas, to mentoring and beyond. We also believe in workplace flexibility and empowering teams to determine the rhythm of work to create an inclusive culture. Through the power of innovative collaboration, we offer hybrid and (when necessary) virtual ("remote") workplace models.
Join us and make your mark on what's next in fintech.
*Applicants must be authorized to work for any employer in the United States. We are unable to sponsor an employment Visa for this position.
Overall Purpose
This position leads the Product Security Architecture consultation with Project Management, Product Management, Software Development and Engineering teams to enable them to build and enhance security in EWS products and Services in line with EWS and Industry standards. This position is a technical lead role and will drive the Product Security roadmap, assist with maturing the Product security program, mentor others and be hands-on partner to our product teams to deliver innovative and secure products to our customers.
Essential Functions
• Leads the Identification, measurement, control and minimization of security risks to information systems across a broad range of disciplines including application and host security. • Develops repeatable application security patterns by working with internal and external partners to ensure that systems are placed within the relevant security zones based on the data they house and their purpose. • Serves as the subject matter expert point of contact for all product security issues in assigned areas and contributes to the development of Early Warning security policy and procedures. • Drives Strategic Product security efforts with architecture teams to ensure that all newly developed and legacy applications and infrastructure implementations are in line with security policy and are compliance to the required frameworks (ISO, PCI, OWASP, NIST 800-53, etc.). • Advises and approves of changes and architectures for assigned areas from a security perspective. • Evaluates and drives decisions on product business cases including functional and detailed design specs to ensure security standards are met. • Consults and leads the security incident response process as assigned. • Develop Threat Models, design and develop Security architectures and publish reference architecture/patterns for Products and drive companywide adoptions • Leads efforts that document and present risks and security issues that could impact the confidentiality, integrity and/or availability of the business (both internally and externally) by assisting in documentation, tracking and creating solutions for mitigation. • Leads and consults on efforts to work with internal and external penetration testing organizations to effectively scope and drive Product Pentests that help identify and mitigate gaps in security controls. • Leads security efforts with Product Development and Engineering teams to perform security analysis on all internally developed products and services. • Interfaces with customer banks to gather yearly testing and security requirements, review penetration testing findings, mitigating controls and/or projects to rectify security vulnerabilities. • Mentors new Product security team members.
• Leads and Implements Product and Stakeholder teams efforts in building Cloud Native applications by incorporating Cloud Security and Microservices Security best practices and industry standards
• Leads and Evaluates Product Security efforts in evaluating new technology stacks and frameworks that helps stakeholder and business teams deliver innovative and secure solutions • Support the company's commitment to risk management and protecting the integrity and confidentiality of systems and data.
Minimum Qualifications
• Education and experience typically obtained through completion of a Bachelor's degree in Computer Science, Engineering, Math or Physical Science.
• 8 or more years of progressive related experience in Information Security roles.
• Combined 8 years of direct or related experience in application security or Security Architecture or Consulting or related IT or Information Security experience.
• Demonstrated subject matter expert in Product and Application Security
• Expert knowledge of relational databases, Windows, and Linux operating systems.
• Ability to work independently and within a team environment.
• Ability to lead efforts that develop and deliver complex and enterprise-wide risk mitigation solutions.
• Effective interpersonal skills, with ability to present to peers, coworkers and customers.
• Expert knowledge of operating system, application, network, and database security architectures.
• Proficiency in AppSec and Web services security
• Exposure to the Agile SDLC process.
• Expert vulnerability remediation experience.
• Experience with threat modeling and control design.
• Experience architecting and leading security for Cloud hosted products
• Expert knowledge with Security integration into CI/CD and experience in driving CI/CD adaptation for security controls
• Expert experience in analyzing technical issues and making recommendations for corrective action.
• Demonstrate expert understanding in the field of Information Security in terms of both concepts and technology.
• Advanced understanding of vulnerability exploitation chaining
• Background and drug screen.
Preferred Qualifications
• CEH/CPT, or CISSP or CSSLP Certification and one of GWEB, or Secure Development Cert, or PHD or MBA in InfoSec or equivalent certification.
• MCSE, SCSA, CCNA or CISA certification
• In depth knowledge with public cloud architecture, such as GCP, AWS and Azure, and virtualization technologies, such as Kubernetes, VMware and OpenStack
• In depth knowledge of threat model, network security, cryptography, authentication and authorization
• Experience performing threat modeling and design reviews to assess security implications and requirements
• Expert level experience in defining and documenting security reference architectures and standards
• Experience with automation tools and methodologies associated with DevOps and CI/CD pipelines
• Experience with enterprise architecture and partnering cross functionally
• Ability to establish priorities, work independently and proceed with objectives
• Experience with implementing common security frameworks and controls in highly automated environments, especially in CI/CD environments
• Familiarity with SAST like Veracode, Fortify and Composition analysis tools
• Experience supporting a Product through various Product Lifecycle stages as a Product Security SME • Familiarity with BSIMM framework
The above job description is not intended to be an all-inclusive list of duties and standards of the position. Incumbents will follow instructions and perform other related duties as assigned by their supervisor.
Physical Requirements
Working conditions consist of a normal office environment. Work is primarily sedentary and requires extensive use of a computer and involves sitting for periods of approximately four hours. Work may require occasional standing, walking, kneeling, and reaching. Must be able to lift 10 pounds occasionally and/or negligible amount of force frequently. Requires visual acuity and dexterity to view, prepare, and manipulate documents and office equipment including personal computers. Requires the ability to communicate with internal and/or external customers.
Employee must be able to perform essential functions and physical requirements of position with or without reasonable accommodation.
Some of the Ways We Prioritize Your Health and Happiness
• Healthcare Coverage - Competitive medical (PPO/HDHP), dental, and vision plans as well as company contributions to your Health Savings Account (HSA) or pre-tax savings through flexible spending accounts (FSA) for commuting, health & dependent care expenses.
• 401(k) Retirement Plan - Featuring a 100% Company Safe Harbor Match on your first 6% deferral immediately upon eligibility.
• Paid Time Off - Unlimited Time Off for Exempt (salaried) employees, as well as generous PTO for Non-Exempt (hourly) employees, plus 11 paid company holidays and a paid volunteer day.
• 12 weeks of Paid Parental Leave
• Maven Family Planning - provides support through your Parenting journey including egg freezing, fertility, adoption, surrogacy, pregnancy, postpartum, early pediatrics, and returning to work.
And SO much more! We continue to enhance our program, so be sure to check our Benefits page here for the latest. Our team can share more during the interview process!
Early Warning Services, LLC ("Early Warning") considers for employment, hires, retains and promotes qualified candidates on the basis of ability, potential, and valid qualifications without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote equal employment opportunity and affirmative action, in accordance with all applicable federal, state, and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our employees.
Date Posted
06/18/2023
Views
5
Similar Jobs
Manager, IT Support - California Closets BC
Views in the last 30 days - 0
California Closets founded in 1978 is a leading custom storage solutions provider offering premium space management and exceptional service The compan...
View DetailsBIM Coordinator - Larson Design Group
Views in the last 30 days - 0
Larson Design Group LDG is an awardwinning employeeowned Architecture Engineering and Consulting Firm They are expanding their team opening new office...
View DetailsLottery Fulfillment Associate, Retail - DraftKings
Views in the last 30 days - 0
The text describes an exciting job opportunity as an Operations Associate at a technology company DKNG specializing in sports and entertainment experi...
View DetailsHuman Resources Advisor - Banner Health
Views in the last 30 days - 0
Banner Health is offering a Human Resources position at University Medical Center Phoenix a nationally recognized academic medical center The role inv...
View DetailsSr. Specialist, Payroll - Achieve
Views in the last 30 days - 0
Achieve is seeking a Senior Specialist Payroll with at least 5 years of experience in multistate multicompany payroll processing The role involves pay...
View DetailsFront End Engineer - Swarmbotics AI
Views in the last 30 days - 0
Swarmbotics AI a company specializing in lowcost swarm robotics for defense and industry is seeking a FrontEnd Engineer The role involves designing an...
View Details