Enterprise Architect- Application Security and Cloud Platform; On-Site in Springfield, MO
Listed on 2025-12-09
-
IT/Tech
Systems Engineer, Cybersecurity, Cloud Computing, IT Consultant
Position Summary
The Enterprise Architect for Application Security & Cloud Platform will work onsite at our corporate office in Springfield, MO. and is a senior strategic role within IT Security, responsible for defining, governing, and continuously improving the secure‑by‑design architecture for applications and cloud platforms across the enterprise. Operating at an enterprise‑wide scope, this role provides architectural leadership spanning secure application patterns, cloud‑native platform controls, identity, containerization, API security, and integration governance.
You will collaborate across Security, Engineering, Operations, and business technology teams to ensure all application and platform designs meet enterprise risk tolerance, regulatory standards, and modern architectural principles. This role will define the long‑term vision for secure application and cloud platform architecture, develop enterprise guardrails and reusable patterns, and guide solution and domain architects in consistent adoption.
This position is based at our corporate office in Springfield, MO.
Essential Functions Enterprise Security Architecture Leadership- Define the enterprise architecture strategy for application security and cloud platform security
- Develop and govern secure design principles, reference architectures, and reusable security patterns
- Partner with Security to align enterprise architecture with risk, compliance, and threat intelligence
- Lead architecture review boards (ARBs) in evaluating system designs for adherence to enterprise guardrails
- Provide architectural oversight for major programs, transformation initiatives, and cloud modernization efforts
- Architect secure application patterns across microservices, APIs, serverless workloads, and legacy platforms
- Define enterprise‑wide secure coding standards, threat modeling frameworks, and application‑layer guardrails
- Evaluate and select application security platforms (SAST, DAST, SCA, RASP, API security, etc.)
- Oversee security integration into CI/CD pipelines, supporting enterprise Dev Sec Ops maturity
- Guide development teams on secure design, vulnerability mitigation, and adoption of shift‑left practices
- Architect enterprise‑secure patterns for identity, workload isolation, data protection, and perimeter‑less security
- Develop and enforce security architecture for container platforms, serverless, Kubernetes, and cloud‑native services
- Define enterprise controls leveraging CSPM, CWPP, CNAPP, zero trust, and identity‑first security models
- Partner with Cloud Engineering to implement platform guardrails, landing zones, and compliance automation
- Establish enterprise standards for multi‑cloud security configurations, logging, and monitoring
- Define strategic direction for securing legacy Web Sphere Commerce Suite (WCS) and similar systems
- Develop compensating controls, hardening baselines, and integration security patterns
- Lead architectural decision‑making for modernization and migration paths away from legacy platforms
- Create and maintain policies, standards, and architecture principles governing secure application and cloud design
- Conduct enterprise‑level threat modeling and risk assessments across platforms and business solutions
- Serve as the primary architecture liaison with audit, risk, and compliance stakeholders (PCI, SOC 2, NIST, ISO)
- Evaluate emerging technologies, conduct platform capability assessments, and guide long‑term investment strategy
- Mentor solution architects, engineers, and developers across ETS pillars on secure architecture practices
- Bachelor’s degree in Computer Science, Engineering, or equivalent experience
- 12+ years in software architecture, application security, or cloud platform architecture
- 7+ years designing and securing cloud‑native architectures in Azure or GCP
- Deep expertise in secure application patterns, Dev Sec Ops , and CI/CD security integration
- Strong architectural knowledge of microservices, Kubernetes, containers, and serverless
- Familiar it…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).