Security Architect
Summary
The Security Architect will assess and elevate security across applications, infrastructure, and cloud environments by implementing secure-by-design practices. The role involves conducting security reviews, performing data risk assessments, and providing architectural guidance on tools like Databricks and Varonis.
We are looking for a Security Architect to assess and elevate security across applications, infrastructure, cloud environments, and data platforms. You will collaborate with engineering, infrastructure, and business teams to embed secure-by-design practices from early design through release. Apply now to help keep systems resilient, compliant, and aligned with best practices.
Responsibilities
- Conduct end-to-end security architecture reviews for applications, SaaS platforms, and infrastructure initiatives
- Assess proposed designs against established security standards, surface gaps and risks, and recommend practical mitigations
- Partner with project teams early in the design lifecycle to ensure secure-by-design principles are implemented
- Perform data risk assessments by mapping data flows across systems, storage locations, and access paths
- Provide architectural guidance on data security tooling such as Databricks security configurations and Varonis for data classification, access auditing, and insider threat monitoring
- Lead security assessments of cloud environments and workloads, reviewing configurations, network segmentation, identity boundaries, logging, and workload protections
- Provide architectural oversight for application security activities including penetration testing, SAST, and DAST
- Review API security designs covering authentication, authorization, rate limiting, and correct handling of API keys, secrets, and tokens via approved secrets management solutions
- Apply IAM and PAM principles to architectural decisions, ensuring least privilege, separation of duties, and strong authentication patterns
- Champion phishing-resistant MFA approaches across critical systems and advise on MDM and MAM strategies for mobile and endpoint devices
- Evaluate network architectures, segmentation strategies, and perimeter and zero-trust controls, and collaborate on vulnerability remediation
- Serve as a trusted advisor on security architecture, document architectural decisions, and maintain reference architectures and security patterns
Requirements
- 3+ years of experience conducting security architecture reviews for applications, SaaS solutions, and infrastructure
- Strong background in data security, including data flow analysis, data risk assessments, and tooling such as Databricks and Varonis
- Hands-on experience with cloud security assessments and cloud-native security controls
- Solid understanding of API security patterns and handling of keys, secrets, and tokens
- Working knowledge of IAM and PAM concepts, including authentication, authorization, privilege management, and identity governance
- Familiarity with phishing-resistant MFA technologies and modern authentication standards
- Knowledge of MDM and MAM platforms and mobile/endpoint security approaches
- Understanding of networking fundamentals (TCP/IP, segmentation, firewalls) and vulnerability remediation practices
- Application security experience, including familiarity with penetration testing, SAST, and DAST tools and processes
- Experience with Cyber Resilience capabilities and Disaster Recovery technologies
- Ability to translate complex security concepts into clear, actionable recommendations for technical and non-technical audiences
- Excellent written and verbal communication skills, with experience producing architecture documents, assessment reports, and design diagrams
- English proficiency at B2 level or higher
Nice to have
- Certifications such as CISSP, CCSP, SABSA, or AWS/Azure/GCP security certifications
- Experience aligning security architecture work to frameworks such as NIST CSF, ISO 27001, CIS, or zero-trust reference models
- Prior experience in regulated environments (e.g., HIPAA, PCI, SOX, GDPR)
Benefits
- International projects with top brands
- Work with global teams of highly skilled, diverse peers
- Healthcare benefits
- Employee financial programs
- Paid time off and sick leave
- Upskilling, reskilling and certification courses
- Unlimited access to the LinkedIn Learning library and 22,000+ courses
- Global career opportunities
- Volunteer and community involvement opportunities
- EPAM Employee Groups
- Award-winning culture recognized by Glassdoor, Newsweek and LinkedIn