Information Security Architect
Western UnionAbout the role
Senior Cybersecurity Architect – Denver, CO OR Austin, TX (Hybrid)
Are you an expert in cybersecurity with a passion for leading high stakes architectural projects in a large global company? Do you thrive in diverse, globally connected environments where your contributions shape the security landscape? Western Union is seeking a top tier Cybersecurity Architect to support our Security Architecture program and drive innovation across our global operations.
Position Overview:
As a Senior Cybersecurity Architect, you will be pivotal in primarily crafting and advancing our application security architecture strategy, enhancing architectural processes, and fortifying our global enterprise architecture portfolio. Your role involves forming solid alliances with cross functional teams and architects, thereby elevating our enterprise's security maturity. You will spearhead initiatives to design new solutions and groundbreaking capabilities, ensuring the security of our financial services on a global scale.
This position is Hybrid and will require 3 days a week in the office.
Key Responsibilities:
- Guide and implement security best practices throughout the Software Development Lifecycle (SDLC).
- Establish shift-left security-by-design principles, standards, and frameworks seamlessly within existing software engineering teams.
- Principal architect for the implementation of DevSecOps within existing DevOps environments, establishing key capabilities, standards and automated gating processes in multiple CI/CD pipelines.
- Direct the security architecture for application and data design processes and reviews.
- Architectural specification of data security standards and best practices, i.e. encryption protocols, data at rest/in-transit, data residency requirements, access controls, etc.
- Cybersecurity architecture reviews for Mergers and Acquisitions (M&A) due diligence efforts & partner with various teams to address architectural needs related to M&A, applications, and data
- Develop, evaluate, and endorse security architectures, aligning them with organizational goals and industry standards.
- Design security frameworks for emerging technologies across diverse platforms and environments.
- Monitor and integrate advancements in cyber security to refine our architectural practices.
- Provide expert guidance and write technical specifications for the procurement and deployment of security technologies.
- Manage cyber security aspects of internal and external audits, facilitating compliance and resolution of audit findings.
- Contribute to the development of security policies and procedures, enhancing audit and regulatory adherence.
- Identify and implement opportunities for process automation and improvement.
- Lead overarching security architecture projects.
Required Expertise:
- Proficiency in security assessments, application architectures, data structure security and integrating security within the SDLC and CI/CD pipelines.
- Extensive knowledge in AppSec technologies and the automation of, for SSDLC. E.g. SAST, DAST, SCA, SBOM, etc.
- Deep knowledge in Mergers and Acquisitions related to cyber security.
- Extensive experience in infrastructure and cloud security, including best practices in cloud environments such as AWS, GCP, OCI, or Azure as it relates to securing CI/CD, infrastructure as code, code repos, Terraform, CloudFormation, etc
- Over ten years of IT experience, with substantial involvement in information security.
- Background in software development, DevOps & Agile practices a plus
- Previous experience as a team lead, cross-collaboration with engineering teams in a global environment a plus
- Exceptional communication skills and a track record of successful cross disciplinary collaboration.
- Minimum of a bachelor’s degree in information security, Computer Science, or related field, with at least six years of focused experience in information security architecture.
Highly Desirable Expertise and Experience:
- Advanced degrees and/or security certifications
- Skills in:
- Expertise in secure coding standards and best practices (e.g. OWASP)
- Ability to identify common vulnerabilities (e.g. SQL injection, XSS, CSRF)
- Knowledge of programming languages, e.g. Java, Python, Jscript, etc
- Experience with scripting languages (e.g. Bash, PowerShell) for automation tasks
- Experience deploying AppSec tools for SAST/DAST/SCA (e.g. Checkmarx, Snyk, Veracode, SonarQube, OWASP ZAP, etc.)
- Experience as a multidomain security SME.
- Familiarity with IT Audit lifecycle and frameworks.
- Familiarity with multiple operating systems and various hardening techniques.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s