02 Jan
Information Security Architect
job summary:Randstad Technologies is in search of an Information Security Architect for an exciting opportunity in the Kansas City area. In this role the Security Architect will be designing and implementing security architecture designs that meet regulatory obligations and data protection requirements as well as alignment with the business and company security strategy. This position will work collaboratively with Information Security Teams in each of the divisions to develop centralized security design reference architecture and drive cross divisional assessments of security. location: SHAWNEE MISSION, Kansasjob type: Permanentsalary: $100,000 - 150,000 per yearwork hours: 8am to 4pmeducation: Bachelors responsibilities:
- Develop centralized security design reference architecture (design patterns) based on an aligned common set of security standards
- Drive cross divisional security assessments
- Design resource to work with other divisions, as necessary
- Lead risk assessments for new technologies and projects
- Drive and perform complex security assessments, identify gaps in existing security architecture, and recommend changes or improvements; govern the implementation of identified solutions
- Proactively identify security architecture controls to mitigate identified threats that align with company security strategy, internal security standards, and industry security and architecture frameworks
- Document and design enterprise security requirements and controls for both on-premises and cloud-based environments based on security best practices of zero trust and defense in depth and alignment with company Information Security Standards
- Define and document how the implementation of a new technology impacts the security posture of the current environment
- Represents the Information Security Team on projects as the subject matter expert to ensure security standards are addressed as part of requirements phase on projects and provides the project team members with guidance on how to meet the identified security requirements
- Provides advanced guidance and direction on new security technologies to ensure architectural fit
- Owns and drives the process to gather and provide security requirements on request for proposals (RFPs), statements of work (SOWs), and other procurement documents
- Proactively identifies, evaluates, and communicates current and emerging security threats to project team members
- Manage and maintain the Information Security Incident Response Plan
- Leads efforts to periodically test the Information Security Incident Response Plan
- Responds quickly and effectively to all security incidents and provides post-event analyses
- University degree in IT, Computer Science, Engineering, or related field
- Minimum five years of experience in Information Security Architecture
- Security+, CEH, CISSP, CISA, or other relevant security related designation(s) required
- Architecture certifications in TOGAF or SABSA considered an asset
- 5+ years of experience in identifying security gaps in existing architectures
- 5+ years of experience in designing security architectures to mitigate threats
- Advanced knowledge of computer networking concepts and protocols (e.g. TCP/IP, DNS) and network security methodologies
- Advanced knowledge of wireless security, routers, switches, VLANs, intrusion detection and prevention
- Advanced knowledge of network access, identity, and access management (e.g. public key infrastructure, Oath, OpenID, SAML, etc.)
- Advanced knowledge of capabilities and applications of network equipment including routers, switches, servers, transmission media, and related hardware
- Advanced knowledge of remote access technology concepts
- Advanced knowledge of application firewall concepts and functions
- 5+ years of experience in cybersecurity designs for systems, networks, and multi-level security requirements or requirements for processing multiple classification levels of data
- Advanced knowledge of risk management processes and experience in conducting risk assessments
- Familiarity with the application of privacy principles to organizational requirements
- Advanced knowledge of identity and access management methods
- 5+ years of experience working with and understanding of Windows, Unix, and Linux operating systems
- Advanced knowledge of concepts for performing network segmentation
- Advanced knowledge of business continuity and disaster recovery operation plans
- Advanced knowledge of security architecture principles and concepts within the AWS cloud environment and prior experience with controls implementation in the AWS cloud environment
- Analytical and problem solving skills
- Exceptional written, oral, and interpersonal communication skills
- Ability to work in team environments and to negotiate with multiple stakeholders
- Ability to meet tight deadlines and to prioritize tasks
- Innovative thinker who is self-directed and resourceful
- Experience level: Experienced
- Minimum 5 years of experience
- Education: Bachelors