Contract to Hire
Salary: Open
Bill Rate: Open
Location: Bloomington, MN. Hybrid: (Onsite Tue, Wed, Thur)
Top Skills:
- Application Security
- AWS Cloud & Platform Security
- DevSecOps
- Tooling Familiarity
- Local to Twin Cities
Application Security - Secure design, secure coding principles, API security, authentication, authorization, session management, input validation, dependency risk, and data protection.
Cloud and platform security - Cloud security principles, network segmentation, workload identity, secrets management, container security, infrastructure-as-code security, and least-privilege design.
DevSecOps - Security integration with CI/CD pipelines, automated controls, security gates, vulnerability triage, build/release enforcement, and developer feedback loops.
Architecture and governance - Reference architectures, design review practices, risk-based decisions, policy creation, reusable patterns, exception handling, and architecture guardrails.
Tooling familiarity Experience - with tools such as GitHub Advanced Security, SonarQube, Snyk, Datadog, Azure Defender/Security Center, vulnerability scanners, container scanners, or equivalent platforms.
-
Ideas Revenue Solutions
Security Architect
Location: Bloomington, MN (Weekly Hybrid)
Contract to Hire
This role acts as a strategic partner to engineering, architecture, product, platform, and operations teams to ensure security is embedded throughout the software development lifecycle. The Security Architect will define security standards, lead security assessments of mission-critical applications, guide remediation, implement scalable security capabilities, and help build a culture where security is everyone’s responsibility.
The ideal candidate combines hands-on technical depth, architectural judgment, organizational influence, and automation-first thinking to improve security posture across modern cloud-based, distributed software platforms.
Technical Skills:
Application Security - Secure design, secure coding principles, API security, authentication, authorization, session management, input validation, dependency risk, and data protection.
Cloud and platform security - Cloud security principles, network segmentation, workload identity, secrets management, container security, infrastructure-as-code security, and least-privilege design.
DevSecOps - Security integration with CI/CD pipelines, automated controls, security gates, vulnerability triage, build/release enforcement, and developer feedback loops.
Architecture and governance - Reference architectures, design review practices, risk-based decisions, policy creation, reusable patterns, exception handling, and architecture guardrails.
Tooling familiarity Experience - with tools such as GitHub Advanced Security, SonarQube, Snyk, Datadog, Azure Defender/Security Center, vulnerability scanners, container scanners, or equivalent platforms.
Key Responsibilities
Security Governance and Architecture
- Define, maintain, and evolve enterprise security policies, standards, patterns, and architectural guardrails.
- Establish security governance processes that integrate with architecture reviews, roadmap planning, project delivery, and operational practices.
- Develop reusable security reference architectures for common product and platform patterns.
- Partner with Enterprise Architecture to ensure security requirements are reflected in platform strategies, modernization efforts, and engineering standards.
- Align security practices to relevant industry frameworks such as NIST CSF, NIST SSDF, OWASP, ISO 27001, and
- SOC 2 where applicable.
Application Security
- Review mission-critical applications and services for architectural and implementation-level security risk.
- Lead threat modeling exercises and identify risks early in solution design.
- Review vulnerability findings and provide clear, risk-based remediation guidance to engineering teams.
- Partner with development teams to improve secure coding practices and reduce repeat vulnerability patterns.
- Define practical security requirements for APIs, distributed systems, identity flows, data handling, cloud-native services, and AI-enabled capabilities.
Platform Security Capabilities
- Partner with platform engineering teams to implement security capabilities that improve the security posture of all product teams.
- Advance tooling and controls for SAST, DAST, SCA, secret scanning, dependency management, container security, infrastructure-as-code scanning, and CI/CD enforcement.
- Design automated controls that can be embedded into build, test, release, and deployment pipelines.
- Develop security metrics and dashboards that provide leadership visibility into vulnerability backlog, remediation progress, policy adherence, and platform risk.
- Promote secure-by-default capabilities that reduce security burden on individual product teams.
Security Awareness and Enablement
- Establish and lead a Security Champions model across engineering teams.
- Security Architect Job Description | IDeaS
- Deliver targeted security awareness and secure development enablement for developers, architects, product owners, and technical leaders.
- Provide consultative coaching to teams without becoming a delivery bottleneck.
- Create practical guidance, playbooks, and reusable examples that make secure behavior easier to adopt.
- Promote a culture of shared accountability where security is built into normal engineering practice.
Security Automation
- Automate security governance and validation processes to reduce manual review overhead.
- Improve automated vulnerability detection, triage, and remediation workflows.
- Partner with teams to build automated policy checks, compliance evidence, and exception tracking where appropriate.
- Continuously evaluate tools and platform investments that improve security outcomes at scale.
Required Qualifications
- Bachelor’s degree in Computer Science, Cybersecurity, Software Engineering, or a related field, or equivalent professional experience.
- 8+ years of experience in software engineering, platform engineering, application security, cloud security, or security architecture.
- 3+ years in a security-focused technical leadership or architecture role.
- Demonstrated experience securing cloud-native applications, distributed systems, APIs, and CI/CD delivery models.
- Hands-on experience with secure SDLC practices, threat modeling, vulnerability management, and engineering remediation workflows.
- Ability to influence architects, engineers, and leaders through practical guidance, clear tradeoff analysis, and collaborative problem solving.