Job Closed
This listing is no longer active.
Oportun is an A.I.-powered digital banking platform that seeks to make financial health effortless for anyone.
Senior Manager, Information Security Architecture – Engineering
Location
United States
Posted
150 days ago
Salary
0
Seniority
Senior
Job Description
Senior Manager, Information Security Architecture – Engineering
Oportun
• Define and maintain secure application and infrastructure architecture frameworks, ensuring security is built-in from the outset • Partner with engineering, DevOps, and technology teams to integrate security into SDLC, CI/CD, and data pipelines • Own and oversee the vulnerability management program, ensuring risk-based remediation across all technology assets • Enhance and scale an existing security design review service, providing structured security assessments for new and evolving systems and data • Advocate for security as a service, building tools and processes that streamline secure development and system operations • Act as a security advisor to engineering and technology operations, ensuring security aligns with business goals • Collaborate with the Security Governance, Risk, and Compliance (GRC) team to align technical security requirements with regulatory and commercial requirements • Champion a security-first culture, ensuring technical execution teams understand security risks, standards, and best practices
Job Requirements
- 10+ years of experience in security architecture, application security, infrastructure security, or related domains
- Strong background in cloud security (AWS, Azure, GCP), DevSecOps, and/or data security
- Experience leading a globally distributed team across time zones which relies heavily on asynchronous working and collaboration methods
- Experience leading and developing globally distributed security teams with a focus on professional growth and collaboration
- Experience designing security controls for data flows and distributed computing environments
- Hands-on expertise of secure software development practices, security testing methodologies, and threat modeling
- Strong cross-functional leadership with the ability to communicate security risks effectively to engineering, IT, and business stakeholders
- Experience of security frameworks and regulations (e.g., NIST CSF, PCI-DSS, GLBA)
- Bachelor's degree in Computer Science, Information Security, or related field
Benefits
- Health insurance
- Flexible working hours
- Professional development opportunities
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Staff Security Engineer, Product Security
MozillaThe Mozilla Corporation was founded in 2005 as a taxable, wholly-owned subsidiary of the Mozilla Foundation, which launched in 2003. The corporation serves the
• Safeguard millions of users by embedding security into Firefox, Mozilla VPN, and other mission-critical products. • Ensure software products are secure by embedding security into the full Software Development Life Cycle (SDLC). • Anticipate, prioritize and mitigate risks through proactive threat modeling, security assessments, security testing, and automation. • Perform security code reviews • Lead penetration testing on web, mobile, and embedded applications, then guide remediation efforts. • Develop and maintain automated security tests within CI/CD pipelines to catch vulnerabilities early. • Partner with engineers to integrate security throughout the software development lifecycle—not as an afterthought, but as a core design principle. Provide security guidance, develop secure solutions, and facilitate secure releases. • Help define and enforce security policies and provide security guidance to development teams. • Help shape Mozilla's security culture through collaboration, guidance, and education.
• Conduct analysis and testing of generative AI systems • Conduct sophisticated and comprehensive simulated attacks on generative AI models and their operating environments to uncover vulnerabilities. • Evaluate the security posture of AI models and infrastructure, identifying weaknesses and potential threats. • Perform thorough risk analysis to determine the impact of identified vulnerabilities and prioritize mitigation efforts. • Collaborate with development and security teams to develop effective strategies to mitigate identified risks and enhance model resilience. • Stay abreast of the latest trends and developments in AI security, ethical hacking, and cyber threats. • Maintain detailed documentation of all red team activities, findings, and recommendations. • Prepare and present reports to senior management and relevant stakeholders.
• Assist in designing and implementing security solutions for client IACS environments, following standards such as ISA/IEC 62443. • Support security maturity assessments and help develop prioritized mitigation plans. • Help identify and remediate vulnerabilities in OT components (PLCs, HMIs, SCADA systems). • Assist in maintaining compliance with regulations (e.g., NERC CIP) and security documentation. • Participate in OT security incident response efforts alongside client engineering, operations, and IT teams. • Contribute to evaluating OT/ICS security technologies (e.g., Claroty, Dragos, Nozomi Networks). • Support pre-sales activities for OT security initiatives. • Stay informed on evolving OT threat landscapes.
Principal Cloud Security Architect
Caesars Entertainment CorporationCaesars Entertainment is a public gaming corporation previously known as Harrah’s Entertainment. Caesar’s Entertainment is the fourth largest gaming company
• Develop and enforce secure-by-design principles for cloud-native applications on AWS and GCP. • Embed security into DevSecOps pipelines, ensuring early detection of vulnerabilities (Shift Left). • Architect zero-trust security models for cloud services, APIs, and microservices. • Multi-Cloud Security Engineering & Automation • Lead the deployment of AWS and GCP security services, including GuardDuty, Security Hub, IAM, WAF, Shield, Macie (AWS) and Security Command Center, IAM, and others. • Implement automated security testing in CI/CD pipelines to ensure infrastructure-as-code (IaC) security compliance using Terraform, CloudFormation, and Kubernetes (EKS/GKE). • Drive container security best practices in Kubernetes (EKS/GKE) and serverless security for Lambda and Cloud Functions. • Architect API security frameworks for high-traffic sports betting and gaming applications. • Design and enforce strong authentication, tokenization, and API gateway security. • Deploy advanced AWS WAF, Google Cloud Armor, and API security solutions to detect and mitigate abuse, fraud, and bot traffic. • Enhance cloud-native detection and response capabilities for fraud, arbitrage betting, identity abuse, and payment security. • Implement behavioral analytics and ML-driven security detection to combat fraud, money laundering, and account takeovers. • Work closely with AWS and GCP security teams to enhance cloud-native incident response capabilities. • Ensure cloud security architecture aligns with PCI-DSS, ISO 27001, NIST, and gaming compliance regulations. • Partner with fraud, legal, and compliance teams to enforce AML (Anti-Money Laundering) and KYC (Know Your Customer) security measures. • Automate compliance monitoring across AWS and GCP environments.




