Security Architect, Product Security
Listed on 2026-09-04
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations, IT Consultant
Security Architect II
The Security Architect II supports Humana's Product Security program by helping identify, assess, and reduce security risk across enterprise applications and technology solutions. Working closely with software engineering, architecture, and security teams, this role serves as a security subject matter expert supporting vulnerability triage, secure software development practices, and security consultation efforts.
This position is ideal for professionals with approximately 2-5 years of cybersecurity, application security, product security, or related security architecture experience who are looking to expand their expertise within a large enterprise environment.
The successful candidate will have experience analyzing vulnerabilities, assessing risk, communicating remediation recommendations, and partnering with technical teams throughout the Software Development Life Cycle (SDLC).
Primary Responsibilities
- Serve as a Level 2 Security SME supporting Product Security Scan & Triage activities.
- Analyze, investigate, and adjudicate complex vulnerability findings and security tool results.
- Assess security risk and provide practical, risk-based remediation guidance to engineering teams.
- Support secure software development lifecycle (SDLC) practices across enterprise technology initiatives.
- Support static application security testing (SAST), software composition analysis (SCA), secrets detection, and open-source/package security activities.
- Partner with development teams to review security findings and improve application security posture.
- Participate in security exception and risk acceptance workflows.
- Assist with the development and improvement of runbooks, knowledge articles, escalation criteria, and operational processes.
- Collaborate with cybersecurity, information security, architecture, and technology teams to address application security risks and improve security outcomes.
Required Qualifications
- 2-5 years of relevant cybersecurity, application security, information security, product security, or security architecture experience.
- Practical experience analyzing vulnerabilities and evaluating security risk.
- Ability to provide clear, actionable remediation guidance to technical teams.
- Working knowledge of:
- Static Application Security Testing (SAST)
- Software Composition Analysis (SCA)
- Secrets Scanning
- Secure SDLC practices
- Understanding of common application security and software security concepts.
- Strong critical thinking, problem-solving, and analytical skills.
- Demonstrated collaboration and communication skills, including the ability to work effectively with software engineers, architects, and security professionals.
- Bachelor's degree preferred; equivalent combination of education and relevant experience will be considered.
Preferred Qualifications
- Experience with enterprise security tooling and vulnerability management workflows.
- Experience supporting application security, product security, cybersecurity, or information security programs.
- Experience with cloud security, container security, API security, DAST, or SaaS security platforms.
- Experience creating documentation, technical guidance, playbooks, or operational processes.
- Experience mentoring junior analysts or supporting team development initiatives.
- Security certification such as Security+, CISSP, CSSLP, GSEC, GWAPT, or similar.
- Bachelor's or Master's degree in Computer Science, Cybersecurity, Information Security, Information Technology, or related technical field.
- Experience working within regulated industries such as healthcare, finance, or insurance.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).