Security Architecture Engineer
HUB InternationalAbout the role
ABOUT US
At HUB International, we are a team of entrepreneurs. We believe in protecting and supporting the aspirations of individuals, families, and businesses. We help our clients evaluate their risks and develop solutions tailored to their needs. We believe in empowering our employees to learn, grow, and make a difference. Our structure enables our teams to maintain their own unique, regional culture while leveraging support and resources from our corporate centers of excellence.
HUB is the 5th largest global insurance and employee benefits broker, providing a boundaryless array of business insurance, employee benefits, risk services, personal insurance, retirement, and private wealth management products and services. With over $5 billion in revenue and almost 20,000 employees in 600 offices throughout North America, HUB has grown substantially, in part due to our industry leading success in mergers and acquisitions.
As a Security Architecture Engineer with a focus on DevSecOps, you will play a critical role in ensuring that security is embedded throughout the software development lifecycle (SDLC) and in continuous integration/continuous deployment (CI/CD) pipelines. You will be responsible for designing, building, and maintaining security controls that ensure application, infrastructure, and cloud security across both on-premises and cloud environments.
In this role, you will collaborate with Security Architects, development, operations, and security teams to automate security processes and implement security as code. You will be expected to bring expertise in both DevOps practices and security principles to ensure rapid yet secure software delivery. This position requires strong technical skills and the ability to work in a fast-paced, collaborative environment.
Key Responsibilities
1. Security Integration in DevOps Pipelines
- Design and implement security solutions that integrate seamlessly with DevOps workflows and CI/CD pipelines.
- Automate security testing (SAST, DAST, IAST) and integrate with existing CI/CD tools like Jenkins, GitLab CI, Azure DevOps, or CircleCI.
- Develop and enforce security-as-code principles, ensuring that security policies and compliance controls are applied programmatically during application deployment.
- Collaborate with development teams to embed security into containerization and orchestration platforms like Docker and Kubernetes.
2. Secure Architecture Design & Reviews
- Review and advise on secure architectural patterns for applications, microservices, APIs, and cloud infrastructure.
- Perform threat modeling, risk assessments, and security reviews of applications and infrastructure to identify and mitigate security risks early in the development process.
- Ensure that the design and deployment of applications align with security best practices such as zero trust architecture, least privilege access, and data encryption.
3. Automation & Security Tooling
- Implement and maintain security automation tools to monitor and enforce security policies across the development lifecycle.
- Desired experience with tools such as Terraform, Ansible, or Puppet used to automate infrastructure provisioning with security baked in.
- Desired experience with tools used to manage and enhance security testing for code analysis, container security, and open-source vulnerabilities (e.g., Aqua, Twistlock, Trivy, Boost).
4. Vulnerability Management & Incident Response
- Work with development and operations teams to fix vulnerabilities identified during automated scans or manual reviews.
- Ensure continuous monitoring of cloud and application environments through security information and event management (SIEM) and cloud security monitoring tools.
- Establish security incident response workflows within DevOps processes to ensure rapid detection and remediation of security incidents.
5. Collaboration & Security Culture
- Serve as a liaison between development, operations, and security teams in a decentralized, regionally dispersed organization to drive the adoption of DevSecOps practices.
- Conduct training and knowledge-sharing sessions to educate developers and operations staff on secure coding practices, security testing, and DevSecOps principles.
- Work closely with compliance and governance teams to ensure that regulatory requirements (e.g., GDPR, HIPAA, PCI-DSS) are met within the DevOps environment.
6. Continuous Improvement
- Continuously assess and improve security processes and tools to keep pace with evolving threats and industry
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s