Security Architect
Overview
As Security Architect you will translate security requirements into enterprise architecture across cloud, apps, and blockchain domains. You will work with cross-functional teams, influence security maturity, and drive risk-aware design for both blockchain and non-blockchain systems. The role has high visibility, shaping security strategy, incident response, and secure SDLC across zerohash’s cloud environment. You’ll stay ahead of industry developments and advise stakeholders to balance security with business needs.
Compensation / BenefitsHealthcare Insurance including premiums coverageVision & Dental Insurance (US)EquityMaternity & Paternity leaveWeWork All Access MembershipWFH Yearly Stipend (US)
ResponsibilitiesImplement CISO-defined security strategy with input on executionInfluence technology functions to mature security-critical processesReview supplier security profiles and submissionsManage licenses and entitlements for tooling and relationshipsMap security initiatives to risk and maturity modelsSupport compliance initiatives and industry threat awarenessArchitect, design, and implement security solutions for cloud and product systemsDevelop requirements and standards for security operations, threat detection, and incident responseConduct regular system tests and continuous security monitoringEstablish disaster recovery procedures and breach drillsCollaborate with product and software teams to ensure secure SDLCLeverage threat models to identify gaps and address threatsPerform security reviews of infrastructure, products, and servicesTest web3 and web2 apps for vulnerabilities and manage remediationDevelop secure coding standards and training materialsResearch blockchain-specific vulnerabilities and integrate into security practicesProvide expertise on cloud security and blockchain trendsEnhance and configure scalable security technologies for detection and responseImplement and maintain strong access controls and IAM in the cloudSupport tooling evaluations and rollouts (e.g., SIEM)Support CISO and Security team on additional security projects as needed
Key requirements10+ years designing and implementing security infrastructure in AWS5+ years in blockchain securityAppSec experience including SAST, DAST, vulnerability management, and pen testingUnderstanding of security operations standardsExperience developing cybersecurity and IT architecturesStrong cross-functional ownership and project management under pressureAdvanced analytical and problem-solving skillsClear written and oral communication with technical and non-technical audiencesDeep experience with identity management and trendsHands-on experience with AWS services (CloudTrail, CloudWatch, SecurityHub, GuardDuty, Inspector, Shield, WAF, Secrets Manager, Lambda)Secrets management and confidential computing knowledgeFamiliar with serverless (Lambda) and containerization (EKS, Kubernetes)Experience leading cloud security design reviewsFamiliarity with AI/ML security concernsAbility to collaborate with software, SRE, and cloud engineersSecurity certifications a plus (CISSP, OSCP, GIAC, AWS Security Specialty)ownershipcross-functional collaborationclear communicationAWS security servicesIAM, EDR, MDM, SIEM, KMS, PAMblockchain security