Cyber Security Architect (CISSP and AZ 104)
Dice is the leading career destination for tech experts at every stage of their careers. Our client, Atinfo Technology Inc, is seeking the following. Apply via Dice today!CTH role. Only for Permanent resident or citizen. F2F interview. CCISP and AZ 104 both certifications required.This role is responsible for deploying, operationalizing, and maturing application level security capabilities in alignment with global Architecture & Engineering (AE) strategy.The ideal candidate is a deep technical expert who can identify, assess, and remediate application security risks, while partnering closely with development teams, cloud engineers, and business stakeholders to ensure secure, scalable, and compliant solutions.Job Description:Application SecurityDeploy and operate application security capabilities, tools, and standardized requirements across the region.Identify, analyze, and document application level vulnerabilities in a systematic and repeatable manner.Communicate identified risks and mitigation strategies to technical and non technical stakeholders.Collaborate with development teams and market units to coordinate and track remediation activities.Provide hands-on support for secure design, remediation efforts, and secure SDLC practices.Report on remediation progress, risk posture, and compliance readiness.Deliver targeted application security training and awareness sessions.Support deployment and monitoring of applications hosted in Microsoft Azure.Explain and support application authentication and authorization concepts.Secure Profiling & Threat ModelingIdentify and document application threats using STRIDE, C4 modeling, and MITRE methodologies.Build data flow diagrams and comprehensive threat models for critical applications.Provide actionable security recommendations based on threat modeling outputs.Maintain tracking and coordination of remediation activities resulting from secure profiling engagements.Identity & Access ArchitectureDesign secure authentication and authorization models using:OAuth 2.0OpenID Connect (OIDC)SAML 2.0Implement secure integrations with Microsoft Entra ID (Azure AD).Guide teams on:JWT token validationManaged identitiesService-to-service authenticationRBAC and Conditional AccessSecure API authorizationAzure Cloud SecuritySecure Azure-native workloads, including App Services, Azure Functions, AKS, and Virtual Machines.Architect secure network configurations: NSGs, private endpoints, firewalls.Implement secrets management with Azure Key Vault.Use Defender for Cloud and Azure Policy for governance and continuous security improvement.Ensure observability and monitoring via Log Analytics and Sentinel.EducationBachelor s or Master s in Computer Science, Information Security, Cybersecurity, Engineering, or related discipline (Required).CISSP RequiredCCSP RecommendedAzure Certifications:AZ 104 (Required)AZ 500, AZ 700, AZ 140 (Recommended)ExperienceMinimum 10 years of experience in cybersecurity architecture and engineering.Strong background in threat modeling and application security tools, such as:Microsoft Threat Modeling ToolThreatModelerIriusRisksecuriCADProven experience designing and implementing countermeasures for application risks.Demonstrated experience collaborating with development teams during architecture, design, implementation, testing, and UAT phases.Experience identifying, analyzing, and managing risk in complex enterprise environments.Hands-on experience with security tools including:RedSealFortifyBurp SuiteQualysWizCrowdStrikeDefect DojoSkills Description:Deep knowledge of architectural blueprints for data center and cloud environments, with emphasis on Azure (IaaS, PaaS, SaaS).Strong ability to detect vulnerabilities through code review, application testing, and infrastructure assessments.High proficiency deploying and configuring applications in large-scale enterprise environments.Working knowledge of:NIST frameworksOWASP Top 10Enterprise grade security design patterns