Sr Advanced Cyber Security Architect/Engineer
Listed on 2026-08-03
-
IT/Tech
Cybersecurity, Systems Engineer, Information Security & Data Protection
Solstice is seeking a highly skilled and experienced Sr Adv Cyber Security Architect to build, lead, and continuously evolve its penetration testing program. This is a senior, hands‑on leadership role in which the successful candidate will serve as the primary point of contact for penetration testing activities across the organization.
The role is responsible for designing a comprehensive penetration testing program, directly contributing to technical assessments, and mentoring a growing team of security professionals.
Key ResponsibilitiesTechnical Responsibilities
Design, execute, and lead end‑to‑end penetration tests across a wide range of environments, including web applications, APIs, cloud infrastructure, internal and external networks, and mobile applications.
Conduct penetration testing across software‑as‑a‑service and platform‑as‑a‑service environments, identifying unique risks and attack surfaces specific to cloud hosted and multi‑tenant platforms. Perform AI and machine learning application security assessments, including testing of large language model applications for vulnerabilities such as prompt injection, model inversion attacks, data poisoning, insecure output handling, and training data leakage.
Simulate real‑world adversarial attack scenarios using threat intelligence and red team methodologies.
Conduct vulnerability assessments, threat modeling, and risk analysis across diverse technology stacks.
Develop and maintain custom exploits, scripts, and tooling to support advanced testing scenarios.
Perform social engineering, phishing simulations, and physical security assessments as required.
Program Development and LeadershipArchitect and build a comprehensive, scalable penetration testing program aligned with recognized industry frameworks, including OWASP, PTES, NIST, and MITRE ATT&CK.
Define penetration testing standards, methodologies, playbooks, and reporting templates.
Establish key performance indicators and metrics to measure the eAectiveness and maturity of the penetration testing program.
Serve as the primary point of contact for all internal and external penetration testing engagements.
Collaborate with Engineering, Dev Sec Ops , Information Technology, Risk, and Compliance teams to integrate security testing into the software development lifecycle and continuous integration and delivery pipelines.
Manage relationships with third‑party penetration testing vendors and coordinate external assessments.
Present findings, risks, and remediation strategies to executive leadership and technical stakeholders.
Team Leadership and MentorshipLead, mentor, and develop a team of penetration testers at various skill levels.
Conduct regular knowledge‑sharing sessions, red team exercises, and skills development programs.
Define career paths and growth frameworks for the penetration testing team.
Foster a culture of continuous learning and maintain awareness of the evolving threat landscape.
Recruit and onboard new team members as the program scales.
ResponsibilitiesKey Responsibilities
Leading the design and implementation of cyber security solutions to protect critical systems and data
Conducting vulnerability assessments and penetration testing to identify and address security vulnerabilities
Developing and implementing security policies, standards, and procedures to ensure compliance with industry regulations and best practices
Collaborating with cross functional teams to integrate security controls into new and existing systems
Providing guidance and support to internal stakeholders on cyber security best practices and incident response procedures
10+ years of hands‑on penetration testing experience in enterprise environments.
Proven experience building or significantly maturing a penetration testing program.
Extensive experience testing software‑as‑a‑service and platform‑as‑a‑service environments and cloud‑native applications.
Strong knowledge of OWASP, PTES, NIST 800-115, MITRE ATT&CK, and CVSS frameworks.
Demonstrated experience leading and mentoring technical security teams.
Strong understanding of secure coding practices and software development lifecycle integration.
Experi…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).