Sr Application Security Architect

2 weeks ago


United States MA Norwell Clean Harbors Full time

The Senior Application Security Architect is responsible for validating that application services are designed and implemented with high security standards. The role is focused significantly on application program interfaces (APIs), and the architect spends a large percentage of time developing and supporting security controls for API services. Additionally, the architect establishes an application security vision with sustainable standards and processes. An influential member of the team, the architect is a primary liaison with the security, engineering and technology teams. 

  • Influence secure API development standards and implementations across multiple platforms 
  • Adopt security standards for the API lifecycle and disseminate them across development and security teams 
  • Enforce rigorous security controls with internal and external constituents, and follow through for verification and consistency 
  • Document and provide ongoing maintenance of materials to eliminate discrepancies in development and security best practices. 
  • Focus on automation to aid in efficiencies with both testing and production 
  • Develop authentication and authorization security requirements to adhere to credential storage, privilege management and authenticity standards; support role- and attribute-based access control 
  • Work in tandem with developers to provide repetitive validation testing prior to production that allows for a continuous cycle of development followed by application security assessments 
  • Regularly monitor the security community for public-facing security issues as well as to learn new tactics for securing data transmissions and reducing attack exposure 
  • Attend and participate in application projects and change management committee meetings. This includes interacting with business units and technical teams to understand what is coming and how projects can be more secure from the beginning 
  • Leverage security standards and implementation configurations, as well as common security frameworks 
  • Document secure delivery and implementation advancements that meet defined service-level agreements (SLAs) and business metrics 
  • Align with architects and development teams for a mission of secure design and data integrity preservation among users, apps and infrastructure 
  • Develop security test plans from architectural designs, identify deficiencies and make enhancements to ensure production is not impacted 
  • Actively participate in and lead security team meetings that facilitate secure design 
  • Be highly engaged in information security projects that evaluate existing security infrastructure and proposed changes as defined by security leadership and architects; deliver projects on time, within budget and in accordance with SLAs 
  • At least 5+ years’ experience in cybersecurity preferred, including compliance and risk management with system and application security engineering 
  • Highly technical and analytical with a proven deep background in application programming (5+ years above and beyond cybersecurity experience preferred) 
  • Established experience with Agile and software development lifecycle (SDLC) practices 
  • Experience in DevSecOps to integrate security principles into the development process, such as vulnerability code review, development security frameworks, testing, and integration of such processes within a CI/CD pipeline 
  • Assess and understand security requirements of the Clean Harbors network, including impacts on bandwidth, latency, availability, and confidentiality 
  • Proficient in Data security concepts pertaining to data with physical security, access controls, logical application security including visibility and data protection 
  • Experienced with REST and SOAP development and security controls. 
  • Experience with .NET Java, Python, C++, Angular, etc. and the ability to drive a security by design approach within the software development lifecycle 
  • Knowledge of security fundamentals for software-as-a-service (SaaS) application integrations and effective use and security configuration of Infrastructure as a Service (IaaS) and Platform as a Service (PaaS) within Azure and Oracle Cloud environments 
  • Solid understanding of network and web protocols 
  • Skillful in single sign-on (SSO), OAuth 2.0, OpenID Connect and SAML 
  • Proven excellence in communicating business risk from cybersecurity topics 
  • Knowledge of practices and guidance emerging from OWASP, NIST and SANS, among others 
  • Experienced working with API gateways such as Ws02, Oracle OIC and Azure Gateway 
  • Experienced with securing intra-company and third-party APIs 

 

Clean Harbors is an equal opportunity employer. We do not discriminate against applicants due to race, ancestry, color, sexual orientation, gender identity, national origin, religion, age, physical or mental disability, veteran status, or on the basis of any other federal, state/provincial or local protected class.  

Clean Harbors is a Military & Veteran friendly company.  
  
#LI-DF1  
*CH  



  • Norwell, United States Clean Harbors Full time

    The application security architect is responsible for validating that application services are designed and implemented with high security standards. The role is focused significantly on application program interfaces (APIs), and the architect spends a large percentage of time developing and supporting security controls for API services. Additionally, the...


  • Weymouth, MA, 02190, Norfolk County, MA, United States Clean Harbors Full time

    The Senior Application Security Architect is responsible for validating that application services are designed and implemented with high security standards. The role is focused significantly on application program interfaces (APIs), and the architect spends a large percentage of time developing and supporting security controls for API services. Additionally,...


  • Boston, MA, United States RICEFW Technologies Full time

    Please Note: As of July 22, 2021, our team will require that all candidate submissions include a LinkedIn profile. Please do not submit any candidates that do not have a LinkedIn.A NA client in Boston is seeking a Sr. Peoplesoft Application Architect to join the Enterprise Application Services Team. The successful candidate will have a strong background in...


  • Fort Meade, MD, United States Leidos Inc Full time

    Description The Leidos DES (Defense Enclave Services) team is supporting an extensive digital modernization program critical to DISA and Fourth Estate Agencies and is currently seeking a Sr. Solutions Architect at our customer at Ft. Meade, MD.POSITION SUMMARY:Leidos is seeking a Senior Solution Architect to join our Defense Enclave Services (DES) team, who...

  • Security Architect

    2 weeks ago


    Dallas, TX, United States Sharp Decisions Full time

    Security Architect Hybrid - 2/3 on-sitePreferred locations : Dallas, Tampa and McLean, VABoston and Jersey City will be their last choice. 7 plus year experienced Security Architect.Must have PKI Architecture BackgroundMust Have Secrets to Management BackgroundMust have heavy infrastructure and application development architecture background.Must have great...

  • Sr IT Infrastructure

    4 weeks ago


    Scottsdale, AZ, United States The Computer Merchant, Ltd. Full time

    Job Title : Sr IT Infrastructure & DevOps Administrator Location: Scottsdale, AZ Wage Range: 60-64 depending on years of experience and qualifications Job Number: 24-00721 Job Description: Our client, a large defense contractor, has an immediate opening for a Sr IT Infrastructure & DevOps Administrator to work from their Scottsdale, AZ facilityAs a SrIT...


  • Boston, MA, United States RICEFW Technologies Full time

    Your Primary Responsibilities:Solutions Architecture Understand business needs and IT strategy and assets to identify optimal solution architecture appropriate to business needs and technology context. Understand implementation context and team capabilities to provide appropriate guidance for team to successfully implement solution architecture. Work with a...


  • Boston, MA, United States RICEFW Technologies Full time

    Please Note: As of July 22, 2021, our team will require that all candidate submissions include a LinkedIn profile. Please do not submit any candidates that do not have a LinkedIn.Job Responsibilities:Application Architecture Practice Research leading ideas, methodologies and technology to enable superior delivery capabilities. Assist compliance and...


  • Arlington, VA, United States Base One Technologies Full time

    Senior Security Architect Required Education/ExperienceRequires a Bachelor’s Degree and at least 12 years of prior relevant experience or Master’s Degree and 8 years of prior relevant experiencePrimary ResponsibilitiesOur Govt client has an immediate need for a Senior Security Architect for a new customer on a highly-visible and strategic Cybersecurity...


  • Washington, DC, United States ALTA IT Services Full time

    ALTA is supporting a direct hire opportunityThis position is 100% Onsite for initial 3-6 months and then remote 1-2 days/week and onsite 3-4 days/week after thatThe location is in the National Harbor area, south of Washington DC.Pay 200k + Clearance Level Must Currently Possess:Top Secret Clearance Level Must Be Able to Obtain:Top Secret Public Trust/Other...


  • Wayne, PA, United States Trinseo Full time

    OT Security Architect iCIMS Job ID 2024-3160 # of Openings 1 Job Family Information Security Overview Career at TrinseoTrinseo is a different kind of global materials company - at the intersection of people, technology, and customers. We are a world leader in the production of plastics and latex...


  • Augusta, GA, United States National Security Agency (NSA) Full time

    Employer: National Security AgencyJob Title: Computer Systems Architect - Entry to Expert Level (MD, TX, HI, GA, UT)Job ID: 1229114Close Date: 5/31/2024 ResponsibilitiesComputer Systems Architects at NSA use commercial and government developed hardware, software, networking, and security products to:- drive information technology projects- produce compliance...

  • IT Security Architect

    2 weeks ago


    Richmond, VA, United States Lucid Technologies Full time

    Role/Title: - IT Security ArchitectHybrid, Richmond, VirginiaAgency Interview Type: Web Cam Interview Only* REQUIRED ON SITE: 4 days/week - NO EXCEPTIONS!*Parking available for contractors on site* Does the candidate reside in the Greater Richmond area? If you answer "yes" to this question and the candidate's resume locations and /or phn# do not support...

  • Sr Analyst and Mobile

    2 weeks ago


    Dallas, TX, United States eRay Technologies LLC Full time

    MUST important skill: Integration architect with 10+ years of experience in Cloud/Mobile technologies . Hands on experience in Hybrid Mobile Application development (Angular, Ionic, and Capacitor/Cordova based mobile application development). Cloud based integration skills (AWS) : AWS Amplify, Lambda functions, Dynamo DB. Preferably with AWS Solution...


  • Huntsville, AL, United States Axient Full time

    Overview Axient has contingent career opportunities to support the AvMC Application Modernization and migration to Cloud effortsThese positions are contingent upon contract award and will be located in Huntsville, ALResponsibilities The AvMC is evaluating cloud based information technology infrastructure to host mission systems, applications, services, and...


  • Herndon, VA, United States IronBrick Full time

    Founded in 2006, IronBrick seeks to reduce the cost, risk, and effort of managing informationWe have deep expertise and specialized intellectual property to design, architect, implement, scale, and secure IT infrastructure solutionsJob Description: SrNetwork EngineerClearance Level: Active TS/SCI Fullscope PolygraphLocation: Herndon, VA We are looking...


  • Patuxent River, MD, United States Fortress Information Security Full time

    As a SrSRE/DevOps Engineer, you will be responsible for modernizing our deployment processes by transitioning our traditional Ansible deployments to containerized deployments in AWS and on-premises environmentsYou will also be responsible for improving our existing CI/CD efforts and infrastructure for developersIn this role, you will work closely with...


  • Washington, DC, United States NewGen Technologies, Inc. Full time

    NewGen Technologies is seeking a Cybersecurity Architect to join a program in Washington, D.CMust have eligibility to obtain a Public Trust clearance The cybersecurity architect is responsible for managing all aspects of the SIEM to include operations and maintenance for all lookup files, integrating security feeds, developing the alerting framework,...


  • Herndon, VA, United States Oracle Corporation Full time

    Cloud Security Architect Must currently hold and have the ability to maintain a DoD Secret security clearanceSenior position within Oracle’s Government Defense & Intelligence (GDI) organizationCandidate should have a history of implementing large, secure application environments within the Department of Defense (DoD)Must understand enterprise...


  • Boston, MA, United States RICEFW Technologies Full time

    Please Note: As of July 22, 2021, our team will require that all candidate submissions include a LinkedIn profile. Please do not submit any candidates that do not have a LinkedIn.Understand business needs and IT strategy and assets to identify optimal solution architecture appropriate to business needs and technology context Understand implementation...