Jobs and Careers
HU

Director of Product Security Architecture(remote)

Humana
Remote US, United States, United StatesRemotefull_timeVerifiedPosted 28 Aug 2025
💰 $236,900/yr($172,200/yr$236,900/yr)

About the role

Become a part of our caring community and help us put health first
 

This role will include managing a team of segment security architects, our threat modeling program, drive security outcomes, determining security strategy for our various business units, and contributing to our enterprise security architecture strategy.
They are looking for someone with at least 7+ years of application security and security architecture experience. You will be critical in helping secure Humana’s information systems and digital portfolio.
You will work with relevant Humana stakeholders to create, prioritize, and manage product iteration backlogs. Ensure final products meet IT and Humana standards and deliver maximum value to end-users. Advise executives to develop functional strategies (often segment specific) on matters of significance. Exercises independent judgment and decision making on complex issues regarding job duties and related tasks, and works under minimal supervision, uses independent judgment requiring analysis of variable factors and determining the best course of action.
You are a passionate self-starter and drive to outcomes with little oversight or direction.
You will report directly to the Associate Vice President of Product Security.

Responsibilities:

• Collaborate with engineering, operations, and security teams to integrate security best practices into our development processes

• Define and track key security metrics to measure the effectiveness of our application security initiatives

• Stay abreast of emerging security threats and technologies, and incorporate them into our strategy

• Partner with cross-functional teams to ensure compliance with industry standards and regulations (e.g., SOC 2, ISO 27001, GDPR)

• Create and deliver executive-level presentations on security strategies and initiatives

• Partner with our Security Automation Product Owner, Compliance and governance, enterprise security architecture, enterprise architecture, DevSecOps and DevOps teams.

• Improve and expand product security across our entire portfolio of applications, systems and platforms. Foster and build a security-conscious culture across the organization

• Manage continuous release planning and execution and integrate with security design and engineering work across multiple groups and technical constituencies

• Develop and maintain relationships across technology organizations, the security industry, peer organizations and other entities as necessary to benchmark Company Application Security program and keep current in best practices

• Develop and mentor staff to achieve career goals and maintain leadership succession planning

• Responsibility for budget and impact for your team.


Use your skills to make an impact
 

Required:

• Bachelor’s degree in related field (Business, Information Services, IT, Information Security, Computer Science etc.);

• 5 years of director+ level work-experience in a highly diversified organization. Experience with a complex work environment in progressive management roles in large, complex organizations.

• At least 3 years+ of experience with Applications Security, including familiarity with the leading toolsets supporting Application Security (dynamic and static). Experience with Checkmarx, AppScan, Burp Suite, Contrast, Veracode, Fortify or similar tooling.

• Strong experience executing application security or product security strategy

• Excellent communication skills with the ability to influence others

• Analytical, problem solving skills, self-starter, passionate and able to execute with little direction.

• Must be passionate about contributing to an organization focused on continuously improving consumer experiences

• Must be passionate about developer experience, privacy, security and product delivery
 

Preferred:

• Strong experience in establishing and rolling out Threat Modeling enterprise wide that can be consumed by developers and engineers

• Cloud experience with Azure, GCP, AWS, Heroku – Azure Preferred. 

• At least 2 years of experience with product design, delivery, and ownership and managing an operational delivery team.

• Knowledge of common information security management frameworks, including but not limited to:

ISO 27001/27002, ITIL, COBIT, NIST, BSIMM, CSF, etc.

• Professional security management certification, such as a Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA) or other similar credentials preferred but not required if devsecops experience.

Remote/WAH requirements:

  • WAH requirements: Must have the ability to provide a high speed DSL or cable modem for a home office. Associ

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Humana

View company profile →