Security Architect
Listed on 2026-07-15
-
IT/Tech
Cybersecurity, Data Security, Cloud Computing: Infrastructure & Operations, Systems Engineer
Location: Remote / Hybrid
Experience
Required:
8+ year relevant experience
ORO Labs is an agentic procurement orchestration company on a mission to humanize the procurement experience. Founded in 2020 by former SAP Ariba product leaders, ORO delivers effortless user experiences so businesses can shorten cycle times, decrease risk through end-to-end process visibility, and remain agile in response to change with a no-code platform purpose-built for procurement. Trusted by users in over 70 countries, and supported by an extensive network of implementation and technology partners, ORO helps Fortune 500 and fast-growing global companies automate processes, improve cross-team collaboration, and scale procurement operations.
The ORO platform is trusted by the world’s largest brands, including The Coca-Cola Company, Novartis, Danone, Roche, BASF, Liberty Global, Bayer, Millennium, and
We are seeking a highly experienced Security Architect to lead the design, implementation, and governance of secure software development and CI/CD infrastructure across cloud and on-premises environments. This role will be responsible for establishing enterprise-wide software supply chain security standards, hardening development and deployment platforms, and implementing controls that ensure the integrity, provenance, and security of software artifacts throughout the development lifecycle.
The ideal candidate combines deep expertise in Dev Sec Ops , cloud infrastructure, software supply chain security, and secure engineering practices with the ability to influence architecture standards across engineering organizations.
Design and implement secure software development and CI/CD infrastructure supporting cloud and on-premises procurement platforms and enterprise applications.
Secure and harden development ecosystems, including source code repositories, build systems, package registries, artifact repositories, deployment pipelines, and cloud-native platforms.
Define and enforce enterprise security standards for:
- Source control and repository security
- Branch protection and code governance
- CI/CD pipeline security
- Secret and credential management
- Artifact integrity and verification
- Dependency governance and package management
- Container and image security
Implement software supply chain security controls to protect procurement and third-party integration environments, including:
- Software Bill of Materials (SBOM)
- Artifact signing and verification
- Binary provenance and attestation
- Dependency and package validation
- Third-party library and vendor risk management
- Open-source governance and policy enforcement
Establish processes and monitoring capabilities to identify, respond to, and remediate dependency compromise events, malicious packages, and software supply chain threats.
Partner with Engineering, Infrastructure, Product Security, and Procurement Technology teams to integrate Dev Sec Ops and secure development practices into enterprise procurement platforms and services.
Conduct security architecture reviews and risk assessments for internally developed applications, vendor integrations, APIs, and deployment workflows.
Drive automation, governance, and continuous improvement initiatives to strengthen software integrity, platform resilience, and compliance across procurement technology environments.
Provide technical leadership and guidance on secure software architecture, cloud security, and software supply chain best practices across the organization.
What We’re Looking For Key Qualifications Required- Bachelor’s degree in Computer Science, Information Security, Engineering, or related field (or equivalent practical experience).
- 8+ years of experience in cybersecurity, Dev Sec Ops , platform engineering, or security architecture.
- Deep expertise in CI/CD platforms, secure software development, and cloud-native infrastructure.
- Strong experience securing:
- Git Hub, Git Lab, Bitbucket, or equivalent source control platforms
- Jenkins, Git Hub Actions, Git Lab CI/CD, Azure Dev Ops, or similar pipeline technologies
- Artifact repositories such as Artifactory, Nexus, or Harbor
- Container platforms and Kubernetes ecosystems
- Hand…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).