- Company Name
- United Software Group Inc
- Job Title
- Security Architect
- Job Description
-
**Job Title:** Security Architect
**Role Summary:**
Lead end-to-end application security testing, ensuring comprehensive coverage of SAST, DAST, API security, container and cloud security, and penetration testing. Drive vulnerability remediation, compliance integration, and a security-first culture across development and DevOps teams.
**Expectations:**
* Deliver rigorous security assessments on enterprise applications, AI/ML platforms, and APIs.
* Own the security lifecycle from code analysis to deployment, embedding security tools and compliance checks into CI/CD pipelines.
* Advise and mentor teams on secure coding, architecture, and infrastructure practices.
**Key Responsibilities:**
* Conduct SAST, DAST, API testing, container security (Trivy), and penetration testing to identify and remediate vulnerabilities.
* Build, maintain, and secure CI/CD pipelines using Jenkins, GitLab CI, or GitHub Actions, integrating security scans at every commit.
* Deploy and manage security tooling (SAST, DAST, dependency scanning) and IaC security with Terraform or Ansible.
* Implement compliance-as-code for standards such as PCI‑DSS, GDPR, OWASP Top10, CWE, CVE, and NIST frameworks.
* Collaborate with DevOps, development, and product stakeholders to establish secure design, code, and deployment practices.
* Communicate findings, risks, and remediation plans to technical and non‑technical audiences.
**Required Skills:**
* Deep expertise in SAST, DAST, API security, penetration testing, and container security (Docker, Kubernetes).
* Strong programming knowledge in Java, .NET, Python, JavaScript for code‑level analysis.
* Experience with CI/CD platforms (Jenkins, GitLab CI, GitHub Actions) and security tooling integration.
* Proficiency in IaC tools (Terraform, Ansible) for secure infrastructure provisioning.
* Familiarity with cloud security testing (AWS, Azure, GCP).
* Excellent stakeholder communication and risk‑management skills.
**Required Education & Certifications:**
* Bachelor’s degree in Computer Science, Information Security, or related field.
* 6–8 years of IT experience, with ≥5 years in application security testing.
* Preferred certifications: OSCP, CEH, GWAPT, CISSP.