Claritev is an Equal Opportunity Employer and complies with all applicable laws and regulations. Qualified applicants will receive consideration for employment without regard to age, race, color, religion, gender, sexual orientation, gender identity, national origin, disability or protected veteran status. If you would like more information on your EEO rights under the law, please click here.
Director of Security Architecture & Engineering
Location
United States
Posted
11 days ago
Salary
$175K - $220K / year
Seniority
Lead
Job Description
Director of Security Architecture & Engineering
Claritev
Role Description We are seeking a Director of Security Architecture & Engineering to lead the strategy, design, and delivery of enterprise security architecture, security engineering, application/product security, AI security enablement, and security automation capabilities. This leader will help modernize the security program for a rapidly evolving technology and threat landscape by advancing secure-by-default architecture, scalable controls, pragmatic automation, and safe use of AI across business and security use cases. The role will partner closely with Security Operations, IAM, GRC, Engineering, Infrastructure, Enterprise Architecture, Data, AI, Product, and business leaders to reduce risk, improve execution, and enable secure technology outcomes across regulated, modern, and legacy environments. Qualifications - 10+ years of progressive experience in cybersecurity, with significant leadership experience spanning security architecture, security engineering, application security, product security, security automation, AI security, and/or closely related domains. - Experience leading senior technical teams and managing a mix of full-time employees, contractors, consultants, vendors, and external partners. - Demonstrated ability to build or mature security functions, including role clarity, operating model design, prioritization, hiring, coaching, and delivery accountability. - Strong background in enterprise security architecture and the design of scalable security patterns and controls for regulated, hybrid, cloud, SaaS, application, identity, data, and AI-enabled environments. - Practical experience leading security engineering functions across cloud security, identity, endpoint/server hardening, automation, infrastructure security, SaaS security, and control implementation. - Experience building or maturing application and product security programs, including secure SDLC practices, secure design, threat modeling, code and pipeline security, SAST/DAST/SCA/IaC, vulnerability remediation, and developer engagement. - Familiarity with AI security, agentic AI considerations, data security, AI governance, AI-generated code risks, model/tool access control, prompt and data leakage risks, shadow AI, and safe AI enablement patterns. - Experience or strong working knowledge of non-human identity security, including service accounts, API keys, OAuth applications, tokens, secrets, machine identities, agent identities, ownership, lifecycle management, least privilege, and automated revocation. - Experience applying automation to security engineering, application security, vulnerability triage, remediation workflows, compliance evidence, control validation, or reporting. - Demonstrated understanding of exposure reduction and impact reduction strategies, including ZTNA, microsegmentation, egress filtering, privileged access controls, phishing-resistant MFA, device posture, hardening, and compensating controls for legacy systems. - Demonstrated ability to partner effectively with Engineering, Infrastructure, Architecture, Data, AI, Product, Legal, Procurement, Finance, Talent, GRC, IAM, SOC, and executive stakeholders. - Strong judgment in balancing strategic direction with pragmatic execution in lean, evolving, or resource-constrained organizations. - Excellent communication skills, including the ability to simplify complex technical topics, explain risk and tradeoffs, influence senior leaders, and align technical teams around outcomes. - Experience in healthcare, regulated environments, or other complex enterprise settings. - Experience designing controls that support regulatory compliance requirements, including HIPAA and related security, privacy, and assurance expectations. - Familiarity with modern cloud-native architectures, DevSecOps practices, enterprise platform transformation, application modernization, and resilient infrastructure and application design. - Experience rationalizing or modernizing security tools and processes, including vendor evaluation, integration strategy, automation opportunities, build-vs-buy decisions, and measurable value realization. - Background supporting secure architecture and engineering in hybrid environments with both legacy and modern platforms. - A strong technical leader with architectural depth, engineering credibility, and the ability to assess modern security products, AI-enabled capabilities, and automation opportunities. - Comfortable operating in a lean organization where prioritization, leverage, and cross-functional influence matter. - Able to set direction while also driving execution, removing blockers, and holding teams accountable for measurable outcomes. - Skilled at building trust across security, infrastructure, engineering, data, AI, product, and business teams. - Focused on outcomes, not just activity, with a bias toward reducing material risk and enabling the business safely. - Effective in leading teams through change, role clarity, capability uplift, and maturity improvement. - Comfortable inheriting a team with mixed tenure, mixed skill profiles, and contractor support, then shaping it into a more cohesive, automation-enabled function. Requirements - Ensure compliance with HIPAA regulations and requirements. Benefits - Medical, dental and vision coverage with low deductible & copay - Life insurance - Short and long-term disability - Paid Parental Leave - 401(k) + match - Employee Stock Purchase Plan - Generous Paid Time Off – accrued based on years of service - 10 paid company holidays - Tuition reimbursement - Flexible Spending Account - Employee Assistance Program - Sick time benefits – for eligible employees, one hour of sick time for every 30 hours worked, up to a maximum accrual of 40 hours per calendar year, unless the laws of the state in which the employee is located provide for more generous sick time benefits Company Description Claritev is an Equal Opportunity Employer and complies with all applicable laws and regulations. Qualified applicants will receive consideration for employment without regard to age, race, color, religion, gender, sexual orientation, gender identity, national origin, disability or protected veteran status.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Cybersecurity Architect
Depot Connect International - DCIDepot Connect International (DCI) is a trusted network of ISO tank container service providers across North America. With decades of combined industry experience, DCI specializes i
Title: Cybersecurity Architect Job Description: Department:Corp Clrcl-IT 906 Discover a career at Depot Connect International (DCI), a global leader in the Tank/ISO Tank Container Services and Tank Trailer Parts industry. We're more than just a service provider; we're a unified team combining the expertise of industry leaders Quala, Boasso Global, and PSC. Headquartered in Tampa, Florida, with over 160 locations worldwide, our team of over 3,500 employees excels in offering a multitude of mission-critical services. The Mission We are looking for a proficient Cybersecurity Architect to spearhead the strategic planning and management of our global security framework. The ideal candidate will align DCI’s broader business objectives—including CIS compliance, network consolidation, and AWS CI/CD security guidelines with the technical strategies necessary to safeguard our data. Location: Tampa, FL; Channelview, TX; Remote Pay Range: $130,000 - $150,000 annual salary We are not able to offer visa sponsorship at this time. DCI Benefits: - Medical, dental and vision insurance - 401(k) with generous employer match - Paid time off, including 10 paid holidays - Optional health savings account & flexible spending account - Life insurance - Employee assistance program - Parental leave - Referral program - Tuition reimbursement Primary Roles and Responsibilities What You’ll Own: - Architectural Evaluation: Analyze the existing cybersecurity landscape, covering Cloud Security, network controls, Governance, Risk, and Compliance (GRC), and vulnerability management. This also includes evaluating Endpoint Detection and Response (EDR), Security Operations Center (SOC), Security Information and Event Management (SIEM), Identity and Access Management (IAM), and Privileged Access Management (PAM). - Security Assessment: Assess the current-state cybersecurity architecture across Identity and Access Management (IAM), Privileged Access Management (PAM), Endpoint Detection and Response (EDR), Security Operations Center (SOC), Security Information and Event Management (SIEM), vulnerability management, Governance, Risk, and Compliance (GRC), Cloud Security, and network controls. - Architecture Strategy: Define and maintain a target-state and transition architecture, aligned to DCI’s chosen operating model, governing regulations, and compliance requirements. - Advisory & Authority: Provide advisory and act as the single architectural authority to ensure controls are implemented consistently and without overlapping or gaps. - Risk Identification: Identify architectural risks related to Managed Service Provider (MSP) tool ownership, control-plane dependencies, and SOC continuity. - Design Review: Review configurations conceptually for security design correctness (focusing on architecture rather than day-to-day administrative changes) and data flow. - Gap Prioritization: Identify and prioritize high-risk gaps including privileged access, segmentation, endpoint exposure, audit gaps, protocol mismatch, and tier architecture or hybrid layouts. - Remediation Planning: Recommend pragmatic remediation measures aligned to DCI’s specific risk tolerance and budget. - Program Management: Lead and oversee the implementation of the strategy with the internal DCI and external partners. - Zero Trust Implementation: Ensure Zero Trust and "secure by design" principles are applied safely and incrementally to avoid business disruption. - Standards Maintenance: Define and maintain security architecture principles, standards, and reference patterns. - Leadership Support: Support leadership decision-making with detailed architecture options, risk trade-offs, cost vs. benefit views, and environmental or cultural fit assessments. - Cross-Functional Collaboration: Partner with Legal/HR to ensure adherence to GDPR, CCPA, or HIPAA. - Vendor & Compliance Management: Handle vendor coordination, license monitoring, and compliance management with associated third parties. Qualifications: - Education: Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Information Technology, or a related field. - Experience: 10+ years of experience in cybersecurity, with at least 3 years specifically in a security architecture or senior engineering role. - Technical Expertise: Proven experience with cloud security (AWS preferred), IAM/PAM solutions, and SOC/SIEM operations. Willingness and expertise to roll-up the sleeves and work side-by-side with the internal DCI and external partner teams on incidents, forensics and improving DCI’s cybersecurity posture. - Certifications: Professional certifications such as CISSP (Certified Information Systems Security Professional), CCSP (Certified Cloud Security Professional), or CISM (Certified Information Security Manager) are highly preferred. - Skills: Strong understanding of Zero Trust principles, risk management, and regulatory compliance frameworks. - Communication: Exceptional ability to communicate complex technical risks and trade-offs to senior leadership.
Role Description The IT Support / Sysadmin Intern will support the day-to-day IT operations of the company, helping employees with technical issues related to their computers, hardware, software, access, connectivity and internal tools. The role will involve managing IT support tickets through Jira, assisting with the setup and maintenance of employee devices, troubleshooting performance issues, documenting recurring problems and supporting the IT team in keeping our internal systems running smoothly. This internship is designed for someone who wants to gain practical experience in IT support, workplace technology, device management and basic systems administration within a SaaS company. What will you be doing? - IT Ticket Management: Receive, classify, follow up and resolve internal IT support requests through Jira, ensuring clear communication with employees and proper documentation of each case. - Employee Technical Support: Support employees with day-to-day technical issues related to laptops, monitors, peripherals, operating systems, applications, internet connectivity, VPN, access permissions and internal tools. - N1 Security Response: Serve as the primary point of contact for internal security events, managing the initial intake and response for potential threats. Key responsibilities include: - Receiving, triaging and investigating phishing reports submitted by employees. - Documenting and escalating confirmed security threats to the specialized security team. - Supporting incident tracking and internal communication during active security events. - Endpoint and Server Hardening: Support the IT department in the implementation and maintenance of security hardening protocols for both employee workstations and internal infrastructure servers, with a focus on: - Configuring OS-level hardening for Windows and macOS endpoints. - Reviewing and enforcing established security baselines, such as CIS Benchmarks. - Securing internal IT servers and core services. - Maintaining documentation on applied configurations and any identified deviations. - Device Setup and Maintenance: Assist with the preparation, configuration and maintenance of employee computers, including software installation, updates, basic security settings and hardware checks. - Hardware Troubleshooting: Help diagnose and resolve issues related to laptop performance, battery problems, overheating, slow devices, screens, keyboards, docking stations, headsets and other equipment. - Onboarding and Offboarding Support: Support the IT setup for new joiners, including preparing devices, configuring accounts and ensuring they have access to the tools they need. Assist with device recovery and access removal during offboarding processes. - Inventory and Asset Management: Help keep track of IT equipment, devices, accessories and assignments, ensuring records are updated and equipment is properly managed. - Documentation: Create and update internal guides, troubleshooting steps and procedures for recurring IT issues and common employee requests. - Collaboration with Internal Teams: Work closely with People, Tech and other departments to support employee needs and improve internal IT processes. Qualifications - Foundational IT Knowledge: Basic understanding of computers, operating systems, hardware, software installation and common troubleshooting steps. - Security-Aware Mindset: Strong understanding of the importance of security in day-to-day IT work. - User Support Mindset: Willingness to help employees, communicate clearly and provide practical solutions to technical problems. - Attention to Detail: Rigorous and organized approach when handling devices, access, tickets, documentation and IT inventory. - Problem-solving Skills: Ability to investigate technical issues, identify possible causes and escalate when needed. - Communication Skills: Ability to explain technical topics clearly to both technical and non-technical users. - Organization: Ability to manage several requests at the same time, prioritize issues and keep ticket information updated. Requirements - Basic knowledge of Windows and macOS environments. - Basic understanding of hardware components and common laptop performance issues. - Experience or familiarity with ticketing tools such as Jira, Zendesk or similar. - Basic knowledge of Google Workspace administration. - Basic knowledge of user access management and permissions. - Basic networking knowledge, such as WiFi, VPN, DNS, IP or connectivity troubleshooting. - Basic knowledge of endpoint and server hardening practices (e.g. CIS Benchmarks, OS hardening guides). - Familiarity with common phishing patterns and N1 security response procedures. - Interest in cybersecurity, device management, EDR tools and IT operations. - Basic scripting knowledge, such as Bash or PowerShell, would be a plus. Benefits - Opportunity to gain hands-on experience in IT support, internal systems administration and cybersecurity within an established SaaS company. - Mentorship and guidance from experienced professionals. - Practical exposure to employee support, device management, troubleshooting, endpoint hardening, IT documentation and internal operations. - Flexible working hours and the possibility of remote work. - 30h to 35h per week. - 7€/hour.
City Sales Manager
Weekday (YC W21)We are a Y-Combinator-backed startup building your AI-powered Recruiter Agent
Role Description This role is for one of the Weekday's clients. - Salary range: Rs 300000 - Rs 900000 (ie INR 3 - 9 LPA) - Experience: 2+ yrs - Location: India - Job Type: full-time Experience: 2–6 years of progressive experience in Enterprise Solution Sales, demonstrating a proven track record of successfully closing complex deals and managing long sales cycles. Candidates with exposure to Fintech, SaaS, Employee Benefits, Gift cards, or Loyalty platforms will be highly preferred, as familiarity with these sectors enhances the ability to tailor solutions to client needs and market demands. - Building and maintaining strong client relationships - Identifying new business opportunities - Driving revenue growth in competitive environments Education: A Bachelor’s degree is mandatory for this role, ensuring a solid foundational knowledge base. Possession of an MBA is considered a significant advantage, especially for candidates who will engage in ROI-driven, strategic conversations with CFOs and senior stakeholders. - Advanced business acumen - Financial literacy - Strategic thinking skills necessary to navigate high-level negotiations - Present value propositions effectively Local Market Expertise: A strong understanding of the corporate ecosystem within the respective city is essential. - Deep knowledge of the local business culture - Key industry players and influential decision makers - Familiarity with local market trends, regulatory environment, and competitive landscape - Building and leveraging a network of professional contacts Qualifications - 2–6 years of progressive experience in Enterprise Solution Sales - Bachelor’s degree (mandatory) - MBA (significant advantage) Requirements - Channel Sales - Enterprise Sales
Title: Senior SaaS Security Engineer – Customer Trust & Assurance Job Description: Contracted Security Experienced Location: Remote, US only Employment Type: Contractor Targeted start date: Immediate Rate: $70 - $85/hr W2 hourly // $80 - $100/hr C2C. Compensation will be determined based on relevant experience, skills, and overall qualifications. Requirements: must be authorized to work legally in the US without sponsorship, now or in the future. About Us Concord isn't your typical consulting firm; we are an execution company with a passion for making things happen. Our mission is to help clients enhance customer experiences, optimize operations, and revolutionize their product offerings through seamless integration, optimization, and activation of technology and data. We are purpose-built, merging the industry’s top specialty companies to amplify our Innovation Capabilities in analytics & AI, data management & engineering, UX and digital experience, and technical platform integration, automation & security engineering. About the Role We are seeking a highly skilled security professional to join our client’s Customer Trust and Assurance team within a dynamic and growing cybersecurity program. In this role, you will represent the security of a modern SaaS platform by delivering accurate, engineering‑informed responses to security questionnaires, RFIs, and due diligence requests. You will work closely with internal engineers to understand how the platform is architected, validate the security design, and translate complex technical information into clear, customer‑ready explanations. You will develop deep familiarity with the product’s cloud architecture, application security controls, and threat mitigation strategies. You will articulate how the platform is built and secured to both technical and non‑technical audiences, earning trust through clarity, confidence, and technical credibility. Operating at the intersection of product security, cloud security, and customer assurance, you will help transform detailed engineering knowledge into strong customer confidence in the platform's security posture. Success in this role requires fluency in SaaS cloud architecture (tenant isolation, IAM/federation, data protection), hands-on familiarity with security frameworks including HITRUST CSF, and the credibility to represent platform security directly to enterprise security teams without escalation. What You Will Be Doing - Respond to customer RFIs, security questionnaires, and due‑diligence inquiries related to security, privacy, and compliance. - Collaborate closely with internal teams to gather, validate, and align accurate technical responses. - Interpret and translate technical security concepts into clear, customer‑ready explanations. - Support customer trust initiatives, including audits, certifications, and process improvements. - Ensure timely, high‑quality delivery of all responses and maintain excellent communication throughout the customer lifecycle. - Develop a deep understanding of the platform’s architecture, including cloud infrastructure, application components, identity flows, and data protection mechanisms. - Articulate security design decisions, architectural patterns, and threat mitigation strategies in a way that builds high customer confidence. - Partner with engineering teams to ensure externally communicated security details accurately reflect system design and controls. - Enhance and maintain technical security documentation, architectural diagrams, and reusable content for customer assurance. - Identify opportunities to improve clarity, consistency, and technical depth across customer‑facing security materials. Qualifications Technical: - 8–12+ years of hands-on experience in cybersecurity, cloud security, application security, or software engineering, with demonstrable depth in security architecture. - Proven experience in customer-facing security assurance: responding to enterprise security questionnaires, RFIs, and due-diligence requests with engineering-grounded answers, not templated responses. - Strong working knowledge of SaaS cloud architectures (AWS, Azure, or GCP) from a security design perspective, including tenant isolation models, IAM/federation patterns, secrets management, encryption strategies, network segmentation, and logging/observability. - Ability to discuss security design tradeoffs, attack surfaces, and control decisions at an engineering level, both internally and directly with enterprise customers. - Practical familiarity with HITRUST CSF as a compliance and technical framework, with the ability to ground requirements in actual implementation detail. - Experience conducting or contributing to threat modeling using STRIDE or MITRE ATT&CK on SaaS platform components such as APIs, identity flows, and data pipelines. - Hands-on collaboration with engineering teams on system design reviews, security controls implementation, and architecture validation. - Familiarity with SOC 2, ISO 27001, PCI-DSS, CSA STAR, and NIST frameworks; ability to connect policy requirements to technical implementation. - Experience creating and maintaining architectural diagrams, threat models, and technical security documentation for external audiences. Note: Candidates should expect to be evaluated on foundational security and cloud architecture concepts during the interview process, including the ability to discuss security design decisions at an engineering level. Compliance & Customer Assurance: - Familiarity with security and compliance frameworks such as HITRUST CSF, SOC 2, ISO 27001, or CSA STAR — with the ability to ground compliance requirements in technical implementation, not just policy. - Experience responding to customer security questionnaires, RFIs, and due-diligence requests, with responses anchored in engineering detail rather than templated answers. - Experience creating or maintaining architectural diagrams, threat models, and technical security documentation. Communication & Collaboration: - Exceptional written and verbal communication skills — able to translate engineering-level security decisions into clear, accurate, customer-ready explanations for both technical and non-technical audiences. - Confident representing the platform's security posture directly to customers and able to handle follow-up technical questions without escalation. - Able to work cross-functionally across engineering, product, and compliance teams in a distributed environment. Certifications (Strongly Preferred): - CISSP, CCSP, or CISM - Cloud security certifications: AWS Security Specialty, Google Professional Cloud Security Engineer, or equivalent - HITRUST Certified CSF Practitioner (CCSFP) is a plus What We Offer (W2 Employment) - Health, Dental, and Vision Insurance: Comprehensive coverage to support your well-being. - Employer Contributions to Health Savings Accounts (HSA): Helping you save for medical expenses. - Flexible Spending Accounts (FSA): Options for healthcare and dependent care expenses, plus a $200 Lifestyle Spending Account (LSA). - Disability Insurance: Short- and long-term coverage, fully paid by the employer. - Life and AD&D Insurance: Employer-provided coverage, with options for additional voluntary coverage. - Employee Assistance Program (EAP): Access to personal and professional support resources. - Career Growth Opportunities: Pathways for advancement and skill development. - Team Engagement Activities: Regular team-building events and company-sponsored activities to foster collaboration and connection. *** Concord is an execution partner helping organizations drive digital transformation, modernization, and scalable technology solutions. We deliver results that solve real business challenges. We operate globally and are growing fast, shaping the future of technology. Join a team trusted by top companies to drive strategic growth and operational excellence!
