Security Architect
Listed on 2026-05-30
-
IT/Tech
Cybersecurity, Systems Engineer, Cloud Computing
Tebra is looking for a Security Architect to join our technical, hands‑on senior role responsible for designing and implementing robust security architectures across our hybrid and cloud environments. This role will drive the strategy to strengthen our overall security posture, ensure compliance (SOC2, HITRUST, PCI DSS), and proactively manage risk while embedding security into the DNA of our platform and enabling engineering teams to build securely by default in GCP.
Key Responsibilities- Cloudflare & Edge Defense: Own the strategy and execution for the Cloudflare ecosystem to secure the network edge. This includes architecting WAF rules (using Reg Ex
), DDoS protection, Bot Management, and writing custom edge logic using Cloudflare Workers (JS/TS). - GCP Security Architecture: Lead the design of security controls within Google Cloud Platform, specifically for Vertex AI
, Big Query
, VPC Service Controls, IAM, and Security Command Center. - Kubernetes & Container Security: Architect and verify security for GKE environments, including container hardening, securing Helm charts, and implementing runtime security policies.
- Dev Sec Ops & Automation: Embed security into CI/CD pipelines (Cloud Build, Git Hub Actions) using Infrastructure as Code (
Terraform
). Orchestrate security workflows using Workato
, building custom Python API endpoints to expose internal security logic to the platform. - Threat Modeling & Risk: Lead threat modeling for critical applications and feature releases, proactively identifying design‑level flaws before deployment.
- Mentorship & Culture: Be a role model for security best practices; mentor engineers on secure coding standards and up‑level the organization’s understanding of cloud security.
- Incident Response: Lead the technical response to complex security incidents, using SQL/KQL to query logs and forensics data to ensure rapid recovery and root cause elimination.
- Governance: Conduct regular risk assessments to identify control gaps and ensure technical alignment with SOC2, HITRUST, and PCI DSS requirements.
- Experience:
7+ years in Information Security with deep hands‑on expertise in network Architecture. - Education &
Certifications:
Master’s degree in Cybersecurity required. GCP Professional Cloud Security Engineer certification highly preferred. - GCP & AI Depth:
Deep experience securing Google Cloud Platform, including specific experience with Vertex AI services and Big Query analytics controls. - Core Security Stack:
Proven ability to manage and tune Cloudflare (WAF/Zero Trust) and Crowd Strike Falcon (EDR/XDR). - Technical & Automation Fluency:
Expert proficiency in Python for building custom automation APIs and Workato for orchestration. Working knowledge of HCL for Terraform code review, JavaScript/Type Script for Cloudflare Workers, SQL for Big Query analysis, and Reg Ex for custom WAF rule creation. - Kubernetes Mastery:
Strong understanding of Kubernetes (GKE) security, including node pools, network policies, and securing Helm deployments. - Compliance:
Solid understanding of risk assessment methodologies (NIST RMF) and mandatory compliance frameworks (SOC2, HITRUST, PCI DSS).
We are dedicated to attracting and retaining top talent with competitive and fair compensation. For this position, the compensation range reflects our Zone 1 (National Average) pay band. Your specific compensation is thoughtfully determined by your experience, qualifications, the specific requirements of the role, and your Geo Zone. Our geo‑zone system ensures your pay is competitive for your location.
Our four geo zones are designed to reflect this:
Zone 1:
National Average
Zone 2:
Moderately Higher Cost Regions
Zone 3:
High‑Cost Regions
Zone 4:
Lower‑Cost Regions
Zone 1 compensation: $178,500 – $203,500 USD
Beyond base compensation, Tebra offers eligible employees an opportunity for variable pay and a robust benefits package, reflecting our commitment to your overall well‑being. In compliance with California pay transparency laws, the specific compensation range applicable to your Geo Zone will be shared during your initial talent screen.
Perks & BenefitsUnited States:
In addition to our healthcare…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).