Job Details

Senior Application/Product Security Architectvirtual remote

Location
Portland, ME, United States

Posted on
Apr 11, 2023

Apply for this job






Profile

Description

We are searching for an experienced Application Security Architect who can utilize solid business knowledge and expert technical experience in security to help develop strategy, roadmap and execution for our Application Security program. In this role you will work to discover security issues proactively during solution design and prevent vulnerabilities during development. You will support the development of design patterns and development standards to help developers and architects build secure solutions. You will support the development of assessment frameworks to evaluate designs then be responsible for their execution. These processes will become especially pertinent in support of current technology modernization efforts with a big emphasis on cloud adoption.

Responsibilities


Support the design of proactive application security frameworks to ensure the secure architecture and development of business solutions. This includes frameworks for performing consistent application security assessments and threat models as well as the development of secure design patterns and development standards.
Implementation of the above controls into a modern SDLC.
Conduct application security assessments, threat modeling and architecture reviews
Proactively communicate design and development principles to appropriate stakeholders
Proactively improve security designs to reduce vulnerabilities found after development of code
Influence stakeholders to correct security deficiencies in the solution design as well as developed code
Provide solutions to security deficiencies while allowing for necessary business and technical functionality
Automation and standardization of all applicable processes


Required Qualifications:

Technical Competencies


In depth comprehension of the OWASP Top 10 and an ability to communicate with developers and application architects. Development or software architecture background is preferred.
Experience working with application security frameworks such as BSIMM and SAMM
Expertise in performing cloud architecture reviews, application risk assessments and threat modeling
Experience in integrating security controls into all forms of SDLC including automation into a CI/CD pipeline
Analyzes business impact and exposure based on emerging security threats, vulnerabilities and risks, and recommends technologies and solutions to mitigate them.
Implement security considerations for in house developed, COTS and SaaS solutions
Translates technical concepts into plain language to show business risk
Collaborates with developers and software architects to adjust designs to securely meet business and technical requirements


Cultural Competencies


Comfortable operating in an environment with constant change and ambiguity
Demonstrated experience mentoring others by providing technical guidance to project teams
Build relationships with development, software architecture and product management stakeholders
Experience working in highly regulated environments subject to HIPAA, HITrust, PCI or other related


Preferred Qualifications:


Bachelor's degree in an IT-related field strongly preferred; post-graduate degree is a bonus, but not required
Knowledge and experience with the configuration of security controls and secure migration of enterprise applications to one of the major cloud providers such as Azure (preferred), Amazon Web Services, or Google Cloud.
Experience with CI/CD pipelines
Automation and standardization of software security controls, particularly into a CI/CD pipeline
Communicate the need for security controls to a business audience, including justification of spend and effort
CISSP, CISM or equivalent
GIAC or Offensive Security certifications
Cloud Architecture and/or Cloud Security Certifications (AWS, Azure, GCP)
Cloud Security Alliance (CCSP, CCSK) (ISC)2


Additional Information

Humana and its subsidiaries require vaccinated associates who work outside of their home to submit proof of vaccination, including COVID-19 boosters. Associates who remain unvaccinated must either undergo weekly negative COVID testing OR wear a mask at all times while in a Humana facility or while working in the field.

Remote/WAH requirements:


WAH requirements: Must have the ability to provide a high speed DSL or cable modem for a home office. Associates or contractors who live and work from home in the state of California will be provided payment for their internet expense.
A minimum standard speed for optimal performance of 25x10 (25mpbs download x 10mpbs upload) is required.
Satellite and Wireless Internet service is NOT allowed for this role.
A dedicated space lacking ongoing interruptions to protect member PHI / HIPAA information


Scheduled Weekly Hours

40

Humana complies with all applicable federal civil rights laws and does not discriminate on the basis of race, color, national origin, age, disability, sex, sexual orientation, gender identity or religion. We also provide free language interpreter services. See our ****

Company info

Sign Up Now - EmploymentCrossing.com

Similar Jobs:
Description The Software Engineer 2 codes software applications based on business requirements. The Software Engineer 2 work assignments are varied and frequently require interpretation and independent determination of the approp...
Description Join us and be a part of the unique opportunity to transform Humana into a consumer focused healthcare leader backed by digital platforms. We're looking for someone who craves new challenges and solves hard customer p...
Description Join us and be a part of the unique opportunity to transform Humana into a consumer focused healthcare leader backed by digital platforms. We're looking for someone who craves new challenges and solves hard customer p...
I found a new job! Thanks for your help.
Thomas B - ,
  • All we do is research jobs.
  • Our team of researchers, programmers, and analysts find you jobs from over 1,000 career pages and other sources
  • Our members get more interviews and jobs than people who use "public job boards"
Shoot for the moon. Even if you miss it, you will land among the stars.
EmploymentCrossing - #1 Job Aggregation and Private Job-Opening Research Service — The Most Quality Jobs Anywhere
EmploymentCrossing is the first job consolidation service in the employment industry to seek to include every job that exists in the world.
Copyright © 2025 EmploymentCrossing - All rights reserved. 169 192