Application Security Architect
Application Security
Casb
Cloud Platforms
Cybersecurity Tools
Data Security
Endpoint Security
Identity and Access Management
Information Security
InfoSec
Risk Management
Security Architecture
Security Architecture Review
Security Compliance
Security Standards
Software Security
Solution Architecture
Threat Modeling
Zero Trust
Zero Trust Architecture
Job Description
Entrust seeks an Application Security Architect to design and evaluate security architectures for enterprise and customer-facing services. This hybrid role in Shakopee, MN translates business, technical, regulatory, and threat requirements into security requirements and actionable implementation guidance across cloud, on-premises, SaaS, and hybrid environments.
Responsibilities
- Learn and apply Entrust security principles, reference architectures, standards, and approved design patterns.
- Develop security requirements and logical designs for new and changed services across cloud, on-premises, SaaS, and hybrid environments.
- Assess trust boundaries, data flows, identities, threats, failure modes, and regulatory obligations that materially affect designs.
- Apply Zero Trust, least privilege, defense in depth, secure-by-design, and privacy-by-design principles.
- Partner with specialists across enterprise, cloud, network, application, identity, data, and security to produce implementable architectures.
- Identify control gaps, document material risk and assumptions, recommend proportionate mitigations, and escalate residual risk for decision when needed.
- Contribute to security standards, patterns, and reusable guidance informed by architecture engagements.
- Translate approved requirements into logical and physical security designs, control configurations, and implementation guidance.
- Design or integrate controls for identity, network, endpoint, cloud, application, data protection, security monitoring, and resilience.
- Define required security telemetry, logging, alerting, retention, and operational ownership for monitorable and supportable controls.
- Support threat modeling and technical risk assessments for applications, infrastructure, cloud services, artificial intelligence solutions, and third-party platforms.
- Evaluate security capabilities and vendor claims using documented requirements, proofs of concept, testing, and evidence.
- Promote automation and consistent control evidence through infrastructure as code and policy as code, including secure CI/CD practices where they improve outcomes.
- Validate that designs are feasible, supportable, resilient, and aligned to recovery requirements through collaboration with implementers.
- Review solution designs, data-flow diagrams, threat models, build documentation, test plans, and implementation changes for security impact.
- Provide clear findings, required actions, and risk-based recommendations to technical teams and decision-makers.
- Verify that security requirements and control ownership are reflected in implementation and test evidence.
- Participate in architecture, design, and change reviews for material technology changes.
- Support troubleshooting for complex issues spanning security, cloud, network, identity, application, and data domains.
- Research emerging technologies, attack techniques, and control capabilities, including artificial intelligence and agentic systems, and recommend practical adoption or mitigation actions.
Requirements
- Bachelor’s degree in cybersecurity, computer science, information systems, engineering, or a related field, or equivalent relevant experience.
- Typically five or more years of relevant experience across information security, infrastructure, cloud, networking, software engineering, or technology risk, including at least two years contributing to security design, engineering, or architecture work.
- Working knowledge of security architecture principles, common threats and vulnerabilities, risk assessment, and compensating controls.
- Experience across at least two relevant domains, such as cloud security, identity and access management, network security, application security, security monitoring, endpoint security, data protection, or vulnerability management.
- Experience reviewing technical designs and converting requirements and risks into practical security controls.
- Familiarity with public cloud and software-as-a-service security concepts, shared-responsibility models, and modern identity-centered security.
- Ability to create clear architecture diagrams, requirements, decision records, standards, and implementation guidance.
- Ability to communicate effectively with engineers, architects, service owners, risk and compliance partners, and business stakeholders.
- Ability to work across multiple teams, manage assigned architecture engagements, and follow through implementation and validation.
- Work authorization and travel requirements will be defined for the hiring location and business need.
Technologies
- Microsoft Azure, Amazon Web Services
- Microsoft Sentinel, Microsoft Defender, Microsoft Purview
- Zero Trust
- Data loss prevention
- Cloud access security brokers
- Security information and event management
- Endpoint detection and response
- Web application firewalls, network segmentation
- Privileged access
- Threat modeling
- Application programming interface security
- Containers, Kubernetes
- DevSecOps, infrastructure as code, policy as code
- Artificial intelligence security, agent security
- Model and prompt risk, machine identities
- Governance controls for enterprise artificial intelligence
- NIST Cybersecurity Framework, NIST Zero Trust Architecture
- ISO 27001
- PCI DSS
- FedRAMP
- Cloud Security Alliance guidance
- Certifications listed: CISSP, CCSP, Azure Security Engineer Associate, AWS Certified Security - Specialty
Benefits
- Comprehensive health and well-being programs including medical, vision, and dental
- 401(k) matching contribution
- Life and disability insurance
- Mental health coaching
- Virtual fitness programs
- Paid personal time off plus 12 paid holidays
- Parental leave
- Education reimbursement
- Eligible for the company’s discretionary annual incentive plan
Compensation
- Anticipated starting base pay: $143,635 - $210,664 per year (in the primary posting location)
- Actual compensation determined based on geographic location, education, skills, and experience
- Eligible for the company’s discretionary annual incentive plan
Work Authorization and Travel
- Work authorization and travel requirements will be defined for the hiring location and business need.
Equal Opportunity
Entrust is an EEO/AA/Disabled/Veterans Employer.
Accommodation Request
- If you require an accommodation, contact [email protected]
Recruiter
- Steve Donahue
- [email protected]
Similar Jobs
A