Sr Security Architect Vulnerability Management

 Posted an hour ago
     
5-10 years experience
Apply Now

Please mention DailyRemote when applying

AI Summary

The role involves designing and scaling a holistic vulnerability management and application security program across AWS and hybrid environments. You will partner with engineering and IT teams to embed security into development workflows while maintaining clear risk metrics and remediation SLAs.

OEC provides software solutions to those who work in the automotive parts and repair industry. Our solutions make it easier for automotive industry professionals to buy and sell parts, conduct repair research & planning, optimize estimates, improve the parts supply chain, and more. OEC partners with many of the world’s largest manufacturers, dealers and suppliers, shops and repairers, and service providers, giving our customers access to a comprehensive network and a streamlined workflow.

Job Summary/Objective

Serves as a hands-on Security Engineer to help shape and execute the company’s modern security vision. Designs, builds, and scales a holistic, end-to-end Vulnerability Management and Application Security program. Establishes clear risk metrics, embedding security into software development workflows, and partners closely with Engineering and IT to ensure pragmatic, timely remediation. Delivers steady, incremental security improvements without stalling engineering velocity.

 

Key Responsibilities & Duties (essential to the job)

  1. Builds and oversees a unified Vulnerability Management Life Cycle spanning AWS cloud environments, legacy co-located infrastructure, containers, and application code.
  2. Defines, tracks, and reports on core program metrics (e.g., MTTR by severity, SLA compliance, SLA breach rates, patch coverage) to demonstrate risk reduction to executive leadership.
  3. Establishes clear, risk-based Remediation SLAs in collaboration with Engineering, DevOps, and IT Operations.
  4. Shifts security "left" by embedding automated SAST, DAST, SCA, and secret-scanning tools into modern developer pipelines (e.g., CI/CD workflows, Terraform checks).
  5. Expands application security controls beyond basic infrastructure/log monitoring to cover open-source dependency risk, code composition, and secure development practices.
  6. Designs and maintains security standards and architectures within AWS.
  7. Secures cloud configurations and Infrastructure as Code (IaC) templates in AWS using automated security scanning and continuous compliance rules.
  8. Partners with IT Infrastructure and Systems teams to streamline patch management practices across hybrid datacenter and cloud workloads.
  9. Monitors emerging threat vectors, zero-day vulnerabilities, and active exploits (EPSS/KEV catalogs) to dynamically adapt remediation priorities.
  10. Coordinates targeted vulnerability assessments, third-party penetration testing, and post-remediation verification.

 

Education

A bachelor’s degree from an accredited college or university is required, with a focus in Cybersecurity, Computer Science, Information Technology, or related discipline. In the absence of a degree, equivalent work experience directly related to the key responsibilities of the role will be considered as a substitute for the degree.

 

Experience, Skills and Key Competencies

At least 6 years of experience in hand-on cybersecurity, with significant experience operating as a Senior/Lead Security Engineer or Security Architect in growing engineering organizations, demonstrated experience navigating hybrid environments, and deep practical experience writing and deploying Terraform.

 

 

Experience, Skills and Key Competencies (continued)

Must also be able to demonstrate the following knowledge, skills and abilities:

  • Strong working knowledge of native AWS security services (GuardDuty, Security Hub, IAM, KMS, Org-level controls).
  • Versatile, generalist knowledge across Security Operations (SecOps), SIEM architecture, Detection & Response, and Vulnerability Management life cycles.
  • Ability to build strong relationships with DevOps, IT, and software development teams through collaborative problem-solving rather than rigid auditing.
  • Understanding of AWS architecture and Terraform configuration scanning to identify cloud-native misconfigurations and drift.
  • Demonstrated ability to define program SLAs, build executive dashboards, and drive culture change around patch compliance and code hygiene.
  • Flexible and adaptable approach to work and can easily adjust to shifts in priorities as the needs of the business change.
  • Able to effectively work and thrive in a remote work environment that has limited opportunities for in-person interactions.
  • Excellent communication skills and can tailor messaging to a specific audience/situation.

 

 

Special Position Requirements

  • Willing and able to attend virtual meetings with the laptop camera on.

What makes working at OEC awesome? It varies from employee to employee. For some, it's the flexibility - whether it's remote work or a hybrid or in-person role, OEC takes our teams across multiple time zones and international communities. For others, it's the strong sense of camaraderie and community that celebrates both individuals and team-driven contributions. Or it could be the empowerment and how the team is encouraged to take risks, learn, and grow within a dynamic and supportive environment. But no matter what gets us out of bed in the morning, our whole global community is inspired to be forward thinking and drive innovative solutions for the automotive parts and repair industry. 
 

OEConnection is subject to certain governmental recordkeeping and reporting requirements for the administration of civil rights laws and regulations. In order to comply with these laws, we invite applicants and employees to voluntarily self-identify their gender, race and ethnicity. Submission of this information is strictly voluntary and refusal to provide it will not subject you to any adverse treatment. The information obtained will be kept confidential and may only be used in accordance with the provision of applicable laws, executive orders, and regulations, including those that require the information to be summarized and reported to the federal government for civil rights enforcement. When reported, data will not identify any specific individual. This information will be maintained separately from your application for employment. If you do not wish to self-identify at this time, you may do so in the future by submitting this form. Failure to provide the following information will not subject you to any adverse action or treatment. OEConnection is an Equal Opportunity/ Affirmative Action employer. We provide equal employment opportunities to all qualified employees and applicants for employment without regard to race, religion, sex, age, marital status, national origin, sexual orientation, citizenship status, veteran status, disability or any other legally protected status. We prohibit discrimination in decisions concerning recruitment, hiring, compensation, benefits, training, termination, promotions, or any other condition of employment or career development.

Similar Jobs

See all Remote Software Development jobs →

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Security Architect

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified