Job Closed

This listing is no longer active.

Senior Security Architect, Cloud Authentication and Authorization

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 10,001+Since 1993H1B SponsorCompany SiteLinkedIn

Location

California + 2 moreAll locations: California | North Carolina | Texas

Posted

69 days ago

Salary

$184K - $287.5K / year

Seniority

Senior

Bachelor Degree8 yrs expEnglishCloudCyber SecurityDistributed Systems

Job Description

Senior Security Architect, Cloud Authentication and Authorization

NVIDIA

• Outline the security architecture strategy for cloud authentication, authorization, workload identity, and agent identity across NVIDIA cloud platforms, AI-enabled systems, enterprise connectors, services, and automation. • Outline processes for establishing, linking, authorizing, delegating, auditing, and retiring human, workload, service, and autonomous agent identities, including attestation-supported identity issuance and certificate-based or temporary credentials. • Develop authorization and delegation frameworks for AI agents and enterprise connectors, encompassing consent, token exchange, prioritized authority, sensitive-action approval, revocation, and protections against confused-deputy behavior. • Lead architecture reviews and threat modeling for high-risk identity and access flows, turning ambiguous scenarios into practical controls that engineering teams can build and verify. • Establish identity lifecycle, telemetry, and emergency-disablement patterns for token issuance, policy decisions, privilege elevation, tool invocation, data access, credential rotation, grant revocation, and compromised or untrusted identities. • Convert emerging AI security risks into authentication, authorization, audit, and execution-boundary requirements. • Partner with identity, cloud, platform, application, AI security, governance, detection, and incident response teams to align architecture decisions with risk strategy and operational reality. • Build reusable architecture patterns, decision records, exception criteria, and implementation mentorship, staying engaged through adoption, validation, and residual-risk closure.

Job Requirements

  • 8+ years experience in cybersecurity, security architecture, cloud security, IAM, application security, product security, platform security, infrastructure security, or security engineering for distributed systems.
  • Extensive knowledge in cloud authentication, authorization, IAM, workload identity, agent identity, non-human identity, or identity architecture, combined with hands-on experience in developing, managing, deploying, or assuming direct responsibility for authentic security controls.
  • Bachelor’s degree in Engineering, Cybersecurity, Data Engineering, or a related technical field, or equivalent experience.
  • Proficiency in authentication and authorization protocols and frameworks, such as OIDC, OAuth 2.0, SAML, federation, delegation, token exchange, token scope, issuer and audience boundaries, consent, mTLS, certificate-backed identity, prioritized access, and associated technologies.
  • Direct involvement in handling workload and agent identities, covering attestation processes, Zero Trust Architecture concepts, short-lived credentials, and temporary identities.
  • Experience developing authorization boundaries for distributed systems, including fine-grained authorization patterns, control points, prioritized delegation, model/data/tool access controls, sensitive-action approval, and execution boundaries.
  • Proficiency with identity and certificate lifecycle management, including enrollment, provisioning, scope definition, prioritized issuance, renewal, rotation, revocation, expiration, auditability, deprovisioning, lifecycle automation, and awareness of crypto-agility and post-quantum cryptography implications.
  • Hands-on understanding of AI security risks combined with adequate proficiency in AI-enabled systems to assess timely injection, data exfiltration, unsafe tool use, overbroad authorization, and loss of human accountability.
  • Strong foundational cybersecurity judgment, including threat modeling, architecture review, risk analysis, practical mitigation development, clear communication of assumptions, partner-team alignment, and follow-through through implementation, verification, documentation, and closure.

Benefits

  • equity
  • benefits

Related Categories

Related Job Pages

More Security Engineer Jobs

World Wide Technology Healthcare Solutions logo

Security Solutions Lead Consultant

World Wide Technology Healthcare Solutions

Founded in 1990, World Wide Technology (WWT) is a global systems integrator with $13.4 billion in annual revenue that provides digital strategy, innovative technology and supply chain solutions to large public and private organizations.

Full TimeRemoteSince 1990H1B No Sponsor

Role Description We are seeking a Lead Security Consultant specializing in SASE/SSE technology to play a role in delivering outcomes across a wide range of global clients. Desired skillsets are centered around core Secure Service Edge (SSE) or Secure Access Service Edge (SASE) capabilities offered in the portfolios of both Netskope and Zscaler technology domains. This Lead Consultant position will require deployment experience of both the core products of these technologies as well as extended parts of the portfolio that customers require assistance deploying. This will be accomplished by engaging with project & practice leadership to plan outcomes for engagements, expanding the capabilities and offerings of the security practice and delivering on consulting engagements in a supporting capacity. Responsibilities - Play a critical role in delivering on projects leveraging Zscaler/Netskope products. - Lead and execute Zscaler/Netskope platform delivery, proxy migration efforts and testing. - Mentor other members of the Global Security Consulting practice on security strategy and architectures as well as consulting approach and skillsets. - Ensure the successful delivery of the most complex engagements involving Zscaler/Netskope technologies that result in meaningful outcomes to large global enterprise and government customers. - Create communication plans with an objective of informing on capabilities, services, and processes to support goals and objectives. - Participate or lead customer facing meetings, workshops, or other events related to cybersecurity lines of business. - Possess the ability to work in a client environment and develop a multitude of relationships, up to the executive level, with excellent communication skills. - Have expert level knowledge in one or more of the following cybersecurity areas: security architecture, cloud security, remote access, SOC operations, compliance, security governance, networks, protocols, threat management, change management, vulnerability management and overall cyber security best practices. - Provide support to multiple engagements across the Zscaler/Netskope portfolio. - Excellent communications skills that need to be demonstrated to internal and external teams. - Oversight and review of engagement collaterals such as presentation and deliverables. Qualifications - 7-plus years of cybersecurity experience with a background as a practitioner, or an industry facing consultant. - Minimum of a Bachelor’s Degree in Computer Science, Computer Information Systems, Information Security, or related field experience. - Technical expert in core Zscaler/Netskope solutions across a variety of deployment scenarios. - Highest level of technical pre-sales & post-sales certification(s) for Zscaler and/or Netskope such as: - Zscaler Certified Professional – Cloud Security (ZCCP-CS) - Zscaler Certified Professional – Zero Trust Network Access (ZCCP-ZPA) - Zscaler Certified Architect – Cloud Security (ZCCA-CS) (highly desired) - Zscaler Certified Deployment Specialist - Netskope Certified Cloud Security Architect (NCCSA-Arch) (highly desired) - Netskope Certified Cloud Security Engineer (NCCSE) - Netskope Certified Deployment Professional - Netskope Certified Cloud Security Integrator (NCCSI) - Demonstratable experience as a project or task lead and working with professionals across organizations. - Experience defining and scoping consulting engagements, including level of effort. - Experience leading multifunctional teams in the execution of complexity security consulting engagements. - Knowledge of the various industry and government strategies and standards in privacy and cybersecurity. - Extensive ability to perform concurrent tasks in complex environments under adjusting priorities. - Ability to communicate and modify approach, language, and style to different audiences. - Extensive experience in organizing resources, establishing priorities, and leading security initiatives. - Must have excellent communication skills, writing skills, and the ability to work with team members at all levels. - Must be a performance-driven team player with a superior attitude. - Working knowledge of other SASE/SSE technologies, such as Palo Prisma SASE or FortiSASE/SD-WAN, is a plus. - CISSP or CISM Preferred. Requirements - Strong leadership ability and proven skills bringing cyber security expertise from a consultant and/or technical background. - Experience in developing and refining service methodologies, as well as positioning them with senior leaders. - Diversified background is a plus and expertise in security domains such as strategy, security architectures, vulnerability management or others is required. Benefits - Health and Wellbeing: Health, Dental, and Vision Care, Onsite Health Centers, Employee Assistance Program, Wellness program. - Financial Benefits: Competitive pay, Profit Sharing, 401k Plan with Company Matching, Life and Disability Insurance, Tuition Reimbursement. - Paid Time Off: PTO and Sick Leave (starting at 20 days per year) & Holidays (10 per year), Parental Leave, Military Leave, Bereavement. - Additional Perks: Nursing Mothers Benefits, Voluntary Legal, Pet Insurance, Employee Discount Program.

United States
$134.8K - $168.5K / year
Full TimeRemoteTeam 1,001-5,000H1B Sponsor

• Lead client engagements and project execution providing information security consultation and assessment services, helping our clients meet their compliance obligations by evaluating their business, technology, and operations against industry security standards • Educate, mentor, advise, and share your expertise with clients and colleagues to aid in making decisions on topics like Artificial Intelligence, organizational security strategy and services scope as well provide consultative guidance on complex projects • Providing clear, organized findings and recommendations to clients and tracking progress towards resolution and compliance • Consult/advise with C-level Security Leaders (CISO, CSO, CIO, etc.) and the Board of Directors with our most valued and strategic clients • Develop strategic, operational, and tactical recommendations tailored to each client with the intent to improve a client’s security posture and compliance position • Create detailed strategic security roadmaps with short-term, mid-term, and long-term goals that prioritize remediation recommendations and address all instances of non-compliance with applicable regulatory, statutory, contractual, and organizational obligations • Lead large security engagements in concert with other cybersecurity practices and Presidio teams • Develop security policies, standards, and procedures that are custom-tailored to each client’s unique culture, security goals, and organizational objectives using industry best practices and compliance requirements • Review, analyze, and assess key factors, including inherent risk, mitigating controls, business impact, likelihood and other key elements to determine organizational security risk • Ensure and assess client alignment to, and/or compliance with, applicable regulatory, federal, state, local, contractual, and organizational requirements and best practices standards such as ISO 27001, NIST Cyber Security Framework (CSF), PCI DSS, HIPAA, FERPA, NIST 800-171, CMMC, etc. • Work closely with organizations to conduct security program development by establishing the foundation for a best of breed security program architecture reference model using industry frameworks and standards such as ISO 27001, NIST 800-53, NIST CSF, etc. • Work with other seasoned Principal Security Consultants in a collaborative setting to support and assist on the execution and delivery of key services such as Cloud Governance, Advisory Services, security program development, documentation review, and security consulting services • Execute tabletop exercises after collaborating with client stakeholders to select the scenario then create an After-Action Report • Deliver PCI Advisory Services, including PCI Gap Analysis, SAQs, ROCs and AOCs • Deliver CMMC Advisory Services, including CMMC Readiness Assessments • Assist leadership in cybersecurity administrative functions, such as documentation maintenance, documentation creation, peer review, and other internal cybersecurity activities

United States
Full TimeRemoteTeam 501-1,000H1B No Sponsor

• Lead Product Security across Chainalysis' SaaS offerings • Own Unified Security Review process for new product launches, vendor evaluations, and AI tooling • Drive Security Engineering Risk Management Framework • Lead the Vulnerability Disclosure Program and security bug reporting workflow • Drive SOC2 and compliance-related security remediation • Provide security review and guardrails for internal AI platforms and coding agents • Participate in a shared on-call rotation for high-severity production security incidents

United Kingdom
Aviatrix logo

Senior Cloud Network Engineer

Aviatrix

Aviatrix cloud network platform delivers advanced networking, security and operational visibility required by enterprises with the simplicity and automation of cloud. More than 400 customers worldwide leverage Aviatrix and it’s proven multi-cloud network reference architecture to design, deploy and operate a repeatable network and security architecture that is consistent across any public cloud. Combined with the industry’s first and only multi-cloud networking certification (ACE), Aviatrix is empowering IT to lead and accelerate the transformation to the cloud. Learn more at Aviatrix.com.

Full TimeRemoteTeam 223Since 2014

Role Description As a Sr. Cloud Network Engineer, you will be a part of Aviatrix's Customer Support team. This position is critical for our customers’ adoption of Aviatrix's enterprise multi-cloud Networking and Security Services Software. - Guide customers for quick and consistent adoption and accelerated integrations with our multi-cloud software products. - Provide real-time support and strategy to ensure customer satisfaction with Aviatrix's products. - This is a weekend shift role, with working hours spanning Sunday through Thursday. Qualifications - Minimum 5+ years of work experience in customer success, resident engineer, network engineer, or similar roles. - Solid understanding of networking, Routing, BGP, IPsec VPN, virtualization, Linux, and infrastructure software. - Experience with Amazon Web Services (AWS), Microsoft Azure, and/or Google Cloud Platform is a plus. - Experience in configuring, testing, and troubleshooting various networking products/solutions (e.g., Cisco ISR routers, ASA firewalls, Meraki, Palo Alto Firewalls, Checkpoint, Juniper, Fortinet, Riverbed, Barracuda, Sonicwall, Aruba, Sophos). - Experience with Python, shell scripting, automation. - Experience with security products is a plus. - Ability to multi-task and work in a dynamic environment. - Availability to work a Sunday through Thursday shift schedule, including after-hours support on a scheduled/non-scheduled basis. Requirements - Report product issues to development and advocate for the customer to help Aviatrix deliver high-quality products. - Develop and improve knowledge-based content, identifying gaps and enhancing troubleshooting guidance and best practices. - Lead resolution of complex and high-priority customer support issues, coordinating and prioritizing timely resolutions with engineering and solution engineering teams. - Provide "hands-on" support for complex customer environments and production issues. - Bring solutions to the leadership team, providing feedback on recommended solutions. - Identify opportunities to improve case management workflows and support processes. Benefits - US: 100% of employee premiums and 88% of dependent(s) premiums for medical, dental, and vision coverage. - 401(k) match, short and long-term disability, life/AD&D insurance. - $1,000/year education reimbursement, and a flexible vacation policy. - Outside the US: Comprehensive benefits package which may include pension, private medical for you and dependents, generous holiday allowance, life assurance, long-term disability, annual wellbeing stipend. - Total compensation package based on job-related knowledge, education, certifications, and location.

United States
$139.3K - $163.9K / year
Job Closed