Cyber Security Architect
Location
Brazil
Posted
2 days ago
Salary
0
Seniority
Lead
Job Description
Cyber Security Architect
TD SYNNEX
• Design and implement robust application security solutions including use of AI and threat modeling. • Ensure that application security measures are integrated into all aspects of the organization's application infrastructure. • Deliver Data flow documentation for applications. • Advises IT and Security leaders in evolving TD SYNNEX’s application security strategies, technologies and processes. • Work closely with cross-functional teams, application developers, and business units, to ensure the security of applications, AI applications and API architectures. • Perform risk assessments of internal applications and API services, drive remediation and improvements. • Develop application security policies, standards and procedures.
Job Requirements
- >10 to 15 Years of relevant work experience.
- Experience with application security tools and techniques.
- Expertise in scripting languages such as Python or PowerShell for automation.
- Expertise with secure software development lifecycle (SDLC) and DevSecOps practices and OWASP.
- Selection of security and technology certifications and/or equivalent proven work experience.
- Experience of AI solutions including MCP.
- Experience of threat modeling using STRIDE or similar.
- Knowledge of SAP architectures.
- Strong knowledge of security frameworks such as NIST CSF, ISO 27001, and SOC 2.
- Knowledge of identity and access management (IAM), Cryptography and data loss prevention (DLP) .
Benefits
- Elective Benefits: Our programs are tailored to your country to best accommodate your lifestyle.
- Grow Your Career: Accelerate your path to success (and keep up with the future) with formal programs on leadership and professional development, and many more on-demand courses.
- Elevate Your Personal Well-Being: Boost your financial, physical, and mental well-being through seminars, events, and our global Life Empowerment Assistance Program.
- Diversity, Equity & Inclusion: It’s not just a phrase to us; valuing every voice is how we succeed. Join us in celebrating our global diversity through inclusive education, meaningful peer-to-peer conversations, and equitable growth and development opportunities.
- Connect with Your Community: Participate in internal, peer-led inclusive communities and activities, including business resource groups, local volunteering events, and more environmental and social initiatives.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Cybersecurity Specialist
GuidehouseSolving big problems, building trust in society, and empowering our clients to shape the future.
• Support secure operations, compliance, risk management, and continuous monitoring for a mission-critical federal grants platform. • Emphasize federal security requirements, ATO support, POA&M management, incident response, security documentation, and vulnerability coordination. • Contribute to secure operations through security documentation, continuous monitoring, vulnerability tracking, POA&M coordination, incident response support, ATO activities, and security oversight. • Support implementation, monitoring, and documentation of federal cybersecurity, privacy, and compliance requirements for Grants.gov applications and platform services. • Manage and support POA&M activities by tracking findings, coordinating remediation owners, documenting milestones, validating closure evidence, and communicating risk status to program and security leadership. • Coordinate vulnerability management activities, including scan review, issue triage, remediation planning, exception tracking, patch coordination, and verification of resolved findings. • Coordinate with development, operations, cloud, database, network, and application platform teams to ensure security considerations are incorporated into releases, configuration changes, deployments, maintenance activities, and enhancements. • Maintain and update security-related artifacts, including system security documentation, control implementation details, risk registers, incident reports, remediation plans, operating procedures, and compliance evidence. • Support transition-in and transition-out activities by helping validate security documentation, accounts, certificates, licenses, support systems, inventories, controls, and operational security responsibilities. • Prepare and communicate security status, risks, issues, remediation progress, incident impacts, control gaps, and compliance recommendations in formats appropriate for executive, federal, technical, and non-technical audiences.
Associate Security Engineer, Identity Security
KBR, Inc.We deliver science, technology and engineering solutions to governments and companies around the world.
• Support the administration and operation of Microsoft Entra ID, Active Directory, hybrid identity, and directory synchronization services. • Perform identity administration activities for users, groups, devices, applications, service accounts, and access permissions. • Troubleshoot authentication, authorization, provisioning, account lifecycle, and access-related issues. • Review logs, alerts, and system data to identify and resolve identity-related incidents and operational problems. • Support Conditional Access, multifactor authentication (MFA), passwordless authentication, and other modern access control solutions. • Assist with privileged access management activities, including role assignments, access reviews, and least-privilege enforcement. • Support identity governance processes, including access reviews, entitlement management, and joiner, mover, and leaver activities. • Assist with enterprise application integrations and identity federation technologies, including SAML, OAuth, OpenID Connect, and SCIM. • Support application identities, service principals, managed identities, workload identities, and service accounts. • Assist with Active Directory administration, Group Policy management, directory health monitoring, and hybrid identity operations. • Support PKI and certificate lifecycle management activities, including certificate issuance, renewal, inventory, and trust relationships. • Identify and help remediate identity-related risks, including excessive access, stale accounts, weak authentication, and unmanaged credentials. • Support security monitoring, threat detection, and incident investigations using Microsoft security platforms and related tools. • Gather technical evidence, perform root cause analysis, and assist with remediation activities during security and operational incidents. • Participate in cloud deployments, application onboarding, tenant migrations, and other identity-related projects and initiatives. • Support audit, compliance, and governance activities through evidence collection, documentation, and control validation. • Create and maintain technical documentation, procedures, knowledge articles, and operational runbooks. • Assist with reporting, automation, and continuous improvement efforts using PowerShell, Microsoft Graph, KQL, and related technologies. • Follow established security, change management, incident management, and operational procedures. • Collaborate with engineers, administrators, and stakeholders to improve identity security controls and operational effectiveness. • Communicate technical issues, findings, and project updates clearly while continuing to develop identity security knowledge and expertise.
RMF Cybersecurity ISSO/SME 3
KBR, Inc.We deliver science, technology and engineering solutions to governments and companies around the world.
• Manage one or more information systems throughout the full six-step RMF lifecycle, including assessment, authorization, and continuous monitoring activities • Serve as an RMF Subject Matter Expert (SME), advising stakeholders on cybersecurity compliance, risk posture, and ATO readiness • Develop, review, and maintain RMF packages and associated documentation, including Security Plans, POA&Ms, Risk Assessment Reports, and security control policies • Assess system compliance against NIST SP 800-53 controls and DHA RMF requirements as part of self-assessment and annual reviews • Document and maintain evidence supporting control implementation and compliance • Lead and participate in A&A and stakeholder meetings to track system status, resolve issues, and drive RMF progress • Coordinate with engineers and system owners to develop architecture diagrams, system asset inventories, and security policies • Prepare and deliver status reports to DHA leadership on system authorization and compliance efforts
• Lead security audits and assessments—annual, periodic, and ad hoc—serving as the primary liaison to internal assessors and external auditors. • Guide implementation of security controls and ensure alignment with CBP, DHS, NIST, and federal requirements. • Oversee development and maintenance of security documentation, assessment artifacts, and audit evidence to support audit readiness. • Lead remediation of audit findings and security deficiencies, ensuring timely corrective actions. • Provide technical leadership on cybersecurity, vulnerability mitigation, and security compliance across the application lifecycle. • Partner with BEMSD stakeholders and development teams to integrate security requirements into application design, development, and operations. • Evaluate emerging cybersecurity technologies, threats, and best practices to strengthen program security. • Deliver security reports, risk assessments, dashboards, and compliance updates to BEMSD and GDIT leadership.



