Security Architect, Product Security
Listed on 2026-10-02
-
IT/Tech
Cybersecurity, Security Management & Operations, Information Security & Data Protection, IT Consultant
Become a part of our caring community
The Security Architect II supports Humana's Product Security program by partnering with engineering, architecture, and security teams to identify and address security risks across enterprise applications. This role analyzes security findings, provides risk-based remediation guidance, and helps drive secure development practices while building expertise in product security and security architecture.
Become a part of our caring community
The Security Architect II supports Humana's Product Security program by partnering with engineering, architecture, and security teams to identify and address security risks across enterprise applications. This role analyzes security findings, provides risk-based remediation guidance, and helps drive secure development practices while building expertise in product security and security architecture.
Work StyleRemote
Candidates must reside in or be willing to relocate to one of the following locations:
Atlanta, GA, Boston, MA, Charlotte, NC, Chicago, IL, Dallas, TX, Washington, DC, Ft. Lauderdale, FL, Louisville, KY, Nashville, TN, New York, NY, or Tampa, FL.
DescriptionThe Security Architect II supports Humana's Product Security program by helping identify, assess, and reduce security risk across enterprise applications and technology solutions. Working closely with software engineering, architecture, and security teams, this role serves as a security subject matter expert supporting vulnerability triage, secure software development practices, and security consultation efforts.
This position is ideal for professionals with approximately 2-5 years of cybersecurity, application security, product security, or related security architecture experience who are looking to expand their expertise within a large enterprise environment.
The successful candidate will have experience analyzing vulnerabilities, assessing risk, communicating remediation recommendations, and partnering with technical teams throughout the Software Development Life Cycle (SDLC).
Primary Responsibilities- Serve as a Level 2 Security SME supporting Product Security Scan & Triage activities.
- Analyze, investigate, and adjudicate complex vulnerability findings and security tool results.
- Assess security risk and provide practical, risk-based remediation guidance to engineering teams.
- Support secure software development lifecycle (SDLC) practices across enterprise technology initiatives.
- Support static application security testing (SAST), software composition analysis (SCA), secrets detection, and open-source/package security activities.
- Partner with development teams to review security findings and improve application security posture.
- Participate in security exception and risk acceptance workflows.
- Assist with the development and improvement of runbooks, knowledge articles, escalation criteria, and operational processes.
- Collaborate with cybersecurity, information security, architecture, and technology teams to address application security risks and improve security outcomes.
Use your skills to make an impact
- 2-5 years of relevant cybersecurity, application security, information security, product security, or security architecture experience.
- Practical experience analyzing vulnerabilities and evaluating security risk.
- Ability to provide clear, actionable remediation guidance to technical teams.
- Working knowledge of:
- Static Application Security Testing (SAST)
- Software Composition Analysis (SCA)
- Secrets Scanning
- Secure SDLC practices
- Understanding of common application security and software security concepts.
- Strong critical thinking, problem-solving, and analytical skills.
- Demonstrated collaboration and communication skills, including the ability to work…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).