IT Security Architect
Cherwell Software, Denver, CO
Frictionless ITSM software for the modern enterprise
Cherwell Software (@Cherwell) is a global leader in enterprise service management, empowering organizations through the use of intuitive technology for better, faster, and more affordable innovation. Our solutions and our people build lasting relationships. We are a growing company with offices in the US, Europe, and Australia.
We are looking for an IT Security Architect to join our team in Colorado or Remote.
Who Will Love This Job
- A problem-solver: You use your technical background and experience to solve difficult problems. You constantly look for areas of improvement and seek out solutions.
- A learner: You learn quickly and maintain a diverse workload in a fast-paced environment.
- Someone who is process-driven: You follow established processes and also looks for areas where operations could be more efficient or otherwise improved.
- Someone who is action-oriented: You enjoy working hard! You are full of energy for the things you find challenging. You are not afraid of acting quickly and you are willing to jump on problems quickly.
What You'll Do
The IT Security Architect supports the Director of Information Technology, IT, Cherwell's SaaS environment, business lines and employees with governance, compliance and communication of Cherwell's information security policies, procedures and standards. The IT Security Architect functions as the focal point for information security operations. Working with Information Technology team, the candidate be the lead on engineering, tuning and implementing security controls. The key responsibilities of this job include:
- Develops policies and procedures which enable agreed upon best security practices in the organization. The IT Security Architect coordinates and administers documentation for security processes and procedures for department and company.
- Coordinates response to information security incidents.
- Coordinates and executes IT security projects.
- Participates in company-wide data classification assessment and security audits and manage remediation plans.
- Creates, manages and maintains user security awareness training.
- Provides on-call support as required, co-administers key applications assisting the IT System Engineer and provides assistance for security related incident response.
- Provides security positioning statements and consultation as it relates to company and SaaS environment for RFP’s and Sales opportunities.
- Collaborates with IT management, legal department, safety and security, and law enforcement agencies to manage security vulnerabilities.
- Manages security tools, hardware and vulnerabilities scanning tools to ensure they meet compliancy requirements.
- Ensures all tasks performed adhere to the firm’s ISO 27001 Information Security Management System (ISMS). This includes participation in annual information and network security training and acceptance of spot checks on an ad hoc basis to guarantee that Cherwell is constantly improving upon the organization’s ISMS.
- Provide technical expertise to it while implementing security controls across multiple data centers.
- Assist in security reviews of production infrastructure and systems.
- Provide security subject matter expertise on cloud control implementation for enterprise-scale projects
- Provide guidance and technical assistance to Product Development team for secure coding and review against OWASP top 10.
What You Should Have
The IT Security Architect will have a varied technology background, with a working knowledge of networking systems, LAN/WAN, Microsoft client and server operating systems, server virtualization technologies, and security methodologies. The candidate will have a strong customer service ethic and demonstrate a level of organization and prioritization. The Architect will be able to align business goals with security requirements and formulate requirements and recommendations for IT and the business as a whole.
The IT Security Architect will have complementary skills in understanding security requirements and technologies such as firewalls, secure application design, secure coding, intrusion detection and prevention, VPNs, remote access, encryption, data protection, antivirus, spyware, etc. Ideally, the candidate will have software industry and SaaS specific knowledge and experience, with emphasis on specific regulations and concerns. Applicable security certifications will be considered as advantageous to the candidate.
- Bachelor’s degree in a related filed or equivalent experience.
- 3-5 years’ experience in a security Architect role with exposure to general system administration.
- Security Certifications such as Security+, CISSP, GIAC, and others are desirable.
- Excellent troubleshooting skills.
- Experience and knowledge in securing technical platforms.
- Experience and knowledge of IT systems/data security as it relates to the SaaS environment.
- Strong understanding of regulations and best practices for technical deployments in a SaaS environment and software industry.
- Knowledge of information security standards (e.g., ISO 27001/27002, etc), rules and regulations related to information security and data confidentiality (e.g., HIPAA, HITECH, FERPA, HITRUST, Etc.).
- Experience and knowledge in secure server and workstation deployment and support.
- Strong communication skills (written, verbal, and listening).
- General understanding of networking and telecommunications.
- Ability to learn quickly and maintain a diverse workload in a fast-paced environment.
- Proficiency with Word, Excel, PowerPoint, Microsoft Project, and Visio.
- This position requires some weekend and evening assignments as well as availability during off-hours for participation in scheduled and unscheduled activities.
- You like working with intelligent and driven colleagues
- You would enjoy working for a fast-growing software company
- Bragging rights – check out our awards!
- We’re a fun, close-knit team
- We have a fast-paced, exciting work environment
- We offer a competitive salary and benefits package, including health, dental, vision, and other benefits
- PTO plan to provide work-life balance
- 401(k) with employer matching program
- Commuter perks for some locations
- Paid community service day and philanthropy projects
- Our work environments vary by location; however, we believe in offering amenities and fun activities to fuel our energy. You may find fully stocked micro kitchens, standing/sitting desks, free onsite gym, basketball and volleyball courts, ping pong, videogames, shuffleboard, and darts.
- Fun group competitions, team outings, and new hire lunches with the CEO
Cherwell Software is an Equal Opportunity Employer Minority/Female/Disability/Veteran. We do not tolerate discrimination against any applicant on the basis of gender, sexual orientation, race, religion, national origin, ethnicity, veteran status, disability or age. Cherwell encourages diversity in hiring, recognizing that this enriches the work environment and that a broad variety of perspectives enhances decision-making and creativity. If you require accessibility assistance applying for open positions in the US, please send an email with your request to [email protected]
About Cherwell Software
Welcome to Cherwell Software At Cherwell, we help organizations achieve their core purpose through the use of intuitive technology that enables better, faster and more affordable innovation. Our co-founders, industry veterans who personally experienced the frustrations, disappointments and broken promises standard within the software industry, dreamed of a better kind of company. They wanted to put customers first and provide an exceptional customer experience—confident that profits and other business rewards would follow. They also wanted to build a company that would stand the test of time. (Read a letter from our Executive Chairman, Vance Brown.) With decades of combined experience in the IT industry, our founders began by tackling the core workload of all IT departments: IT Service Management. By providing the tools needed to automate routine maintenance tasks and simplify the delivery of IT services, our technology gives IT teams the freedom to focus on business enablement and transformation. In fact, our technology was built from the ground up—not retrofitted—to empower innovation beyond the traditional boundaries of IT. Our modern, metadata platform lets you rapidly build and refine business solutions without the need to manage code, employ costly development resources, or worry about breaking what you’ve already built when it’s time to upgrade. Armed with unprecedented power and flexibility, Cherwell customers have automated workflow for thousands of line-of-business solutions—from Employee Onboarding to Loan Processing to Student Information Systems. And with our Enterprise Service Management mApps (merge-able applications), IT teams can download pre-built solutions into their Cherwell environment that instantly extend service management capabilities to other areas of the business, such as HR, Facilities, Information Security, and Project Management. With each new solution designed, another Cherwell customer achieves something amazing. The question is, where will YOU go with Cherwell at your side?
Want to learn more about Cherwell Software? Visit Cherwell Software's website.
Jobs You May Like
Senior Software Engineer, iOS
Evernote, Austin, TX, Redwood City, CA
Hudl, Omaha NE
Senior Design Engineer
Specialized, Morgan Hill, CA
Infrastructure Security Engineer / Red Team
Helix, San Carlos
Vice-President Software Engineering
EnerNOC, US - Boston, MA
Engineering Manager, Partner Experience
Coursera, Mountain View, CA