Senior Lead III, Security Architect (Hybrid or Virtual)
S&P GlobalAbout the role
About the Role:
Grade Level (for internal use):
13The Team:
S&P Ratings Security team focuses on protecting our clients and users from all aspects of modern-day security threats. The mission of our team is to safeguard systems and data by developing, innovative solutions for the biggest security challenges. We are passionate problem solvers with deep security expertise.
Responsibilities and Impact:
This is a Director level individual contributor role with broad experience in application security, cloud security, and security architecture that will work across Security, software development, Data science/LLM, QA, and Operations teams to identify component and system level technical risks, identify and evaluate critical failure points, determine technical security controls to mitigate risks, prioritize and schedule controls with application development timelines, and work with cross functional teams to implement remediations.
This role will drive the Secure SDLC roadmap, Application and Network Security strategy, Cloud security architecture. The role will assist with maturing the security engineering program, develop security tooling, mentor others, and be hands-on partner to our development teams to deliver innovative and secure applications.
Responsibilities:
Evaluate threats and identify vulnerabilities to prioritize data security risks.
Develop and enforce data security policies for compliance with industry standards.
Review access management controls for security gaps.
Implement encryption techniques to protect sensitive data.
Maintain Application and Cloud security strategies.
Guide security best practices in software development, UI design, and technologies.
Lead the creation of a security architecture, balancing business risks and customer needs.
Perform threat modeling, secure code reviews, and design reviews for high-risk apps.
Conduct vulnerability research and advise on new technologies.
Automate security testing using scripting and open-source tools.
Assist developers with vulnerability remediation.
Coach teams on security practices like threat modeling and code reviews.
Stay updated on emerging security technologies and trends.
Develop repeatable security patterns based on data and system purpose.
Consult on incident response processes and App Penetration tests.
Guide teams in building secure Cloud Native applications with best practices.
What We’re Looking For:
Basic Required Qualifications:
Bachelor’s degree in Computer Science or related field, or relevant experience.
12+ years in Security engineering roles.
Expertise in Application Security, Web services, and Network Security.
Proficiency in Java, Python, and Agile SDLC.
Experience with threat modeling, risk analysis, and controls.
Experience leading security for Cloud-native applications.
In-depth knowledge of network security and authentication.
Advanced understanding of vulnerability exploitation and remediation.
Expertise in security architecture, SOA, web services, and JavaScript.
Skills in security audits, vulnerability assessments, and packet analysis.
Knowledge of TCP/IP, encryption, TLS, and PKI/Certificates.
Experience with Identity & Access Management.
Additional Preferred Qualifications:
Experience securing Gen AI models.
Experience with security automation.
Knowledge of AWS, Containers, Kubernetes, and VMware.
Experience defining security reference architectures and standards.
Familiarity with automation tools for DevOps and CI/CD pipelines.
Knowledge of SAST/DAST/SCA tools (e.g., Fortify, Whitesource).
Experience with databases (Postgres, Oracle, Snowflake).
Familiarity with Secure SDLC frameworks (e.g., NIST SSDF, OpenSAMM).
Security Forensic analysis skills.
Right to Work Requir
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s