02 oct
|
Unosquare
|
Colombia
02 oct
Unosquare
Colombia
Our team is dedicated to delivering digital learning experiences that transform education for learners and educators. Our focus is on creating seamless, impactful products that truly benefit our users while supporting growth and collaboration across teams. We foster a culture that values innovation, teamwork, and a balance between career growth and personal well-being.
How Can You Make an Impact?
Our team is seeking a Cybersecurity Architect who can collaborate with development teams, business teams, and cross-functional technology. The role will lead efforts to secure cloud platforms, mitigate cyber risks, and ensure compliance with security policies and regulatory requirements. As a Cybersecurity Architect, you should have experience in developer security (DevSecOps), cloud network security, cloud infrastructure vulnerabilities, vulnerability scanning tools, SAST, and working with teams to remediate vulnerabilities. Our Cybersecurity Team is a highly technical, metrics driven team, with a consistent focus on process optimization and automation to improve effectiveness. You must be able to report, quantify stats, trends, and metrics to articulate risk and results. This is an individual contributor role that will report to the VP of Cybersecurity.
What You'll Do
- Lead security architecture reviews for new digital product offerings or major changes to existing products to uphold our digital product security standards
- Design and implement a Static Application Security Testing (SAST) strategy to protect our static code environment that will reduce vulnerabilities prior to production deployments
- Develop and maintain the strategy of the cloud security posture for all cloud accounts (AWS, Azure, OCI) belonging to the organization
- Collaborate with development teams, cloud operations, engineering, and IT teams to promote secure development practices and integrate security controls into CI/CD pipelines
- Present and articulate threats, vulnerabilities and risks to developers, stakeholders, and leadership
- Respond and triage security incidents related to digital products
- Provide support for web-app and cloud infrastructure vulnerabilities and findings discovered via tools, penetration testing, or by security researchers
- Conduct risk assessments on cloud systems and identify/remediate security gaps
- Maintain Identity and Access Management (IAM) policies, Role-based Access Control, and least-privileged access to our cloud environment
- Design and implement strategy to secure our SDLC workflows
- Oversee Web Application Firewall strategy for our customer-facing products
- Secure AI and MCP development workloads
Who You Are
- Bachelor's degree in related field or equivalent experience preferred
- 10+ years of applicable experience
- Must hold a CISSP or have equivalent cybersecurity-related experience
- Must hold certifications or have equivalent experience in Networking, Cloud Principles, and Incident Response
- Ability to present cybersecurity risks and remediation recommendations to senior leadership
- Ability to respond to security-related incidents and perform digital forensics
- Familiarity with IT Security Policies and Procedures
- Strong analytical and communication skills
- Thorough understanding of web-based applications, server and container instances, and middleware
- In-depth understanding of AWS architecture and accommodating security controls
- While minimal, ability to respond to night and/or weekend security incidents
- Experience working with Dynamic Application Security Testing (DAST) and Static Application Security Scanning (SAST)
- Experience using, maintaining, and reporting results of vulnerability scanning tools, such as Insight AppSec, Insight VM, Insight CloudSec, Burp Suite Pro
- Collaborate with developers and engineers to articulate vulnerabilities, risks, and remediations
- Foster cybersecurity culture throughout our software development community
Preferred
- Experience maintaining and maturing a Vulnerability Management Program
- Experience or familiarity with other cloud service providers, such as Azure, Google Cloud, Oracle Cloud
- Experience securing custom AI/MCP applications and integrations
#J-18808-Ljbffr
📌 8995 - Cybersecurity Cloud, Infrastructure and ITOps Senior, Lead Argentina, Colombia, Mexico, Paraguay, Bolivia, United Kingdom Published 7 days ago
🏢 Unosquare
📍 Colombia