Security Architect
- Full-time
- Job Family Group: Technology and Operations
Company Description
Visa is a world leader in digital payments, facilitating more than 215 billion payments transactions between consumers, merchants, financial institutions and government entities across more than 200 countries and territories each year. Our mission is to connect the world through the most innovative, convenient, reliable and secure payments network, enabling individuals, businesses and economies to thrive.
When you join Visa, you join a culture of purpose and belonging – where your growth is priority, your identity is embraced, and the work you do matters. We believe that economies that include everyone everywhere, uplift everyone everywhere. Your work will have a direct impact on billions of people around the world – helping unlock financial access to enable the future of money movement.
Join Visa: A Network Working for Everyone.
Job Description
Cybersecurity is at the beating heart of our culture. Our diligence and expertise is what makes us the undisputed leader in electronic payments. We’ve made it our priority to create a top-tier Cybersecurity team, poised to defend us against any potential cyber threats. We’re looking for those of you who are inherently driven and fascinated by the art and science of cybersecurity and more specifically, mergers and acquisitions with a specific focus on Cybersecurity integration. We’ll equip you with the very best tools and tech so that you can deliver top notch results. Continuous self-development underpins job fulfilment at Visa.
As a Security Architect within the Cybersecurity M&A Team you will:
- Lead security initiatives, due diligence and integration of Visa acquired entities.
- Perform Threat Modelling, Design and Pentest reviews on the entity’s applications/infrastructure and provide guidance on effective countermeasures.
- Be a subject matter expert and provide security guidance and recommendations to engineering and operational teams.
- Lead Mergers & Acquisitions (M&A) post-close integration activities for Cybersecurity deliverables.
- Contribute to Visa’s security policies, standards, and guidelines related to Information security.
- Perform dynamic and manual security assessments on web applications, mobile applications, thick clients to identify vulnerabilities and provide recommended counter measures.
- Improve on existing framework, processes, methodologies related to due diligence and integration of entities.
- Enhance the security posture of the entity hosted in public cloud or on-prem environment
- Understand the broad regulatory landscape affecting Visa business areas, remain current with emerging regulatory sentiments as well as solution trends in the marketplace
This is a hybrid position. Hybrid employees can alternate time between both remote and office. Employees in hybrid roles are expected to work from the office two days a week, Tuesdays and Wednesdays with a general guidepost of being in the office 50% of the time based on business needs.
Qualifications
Preferred Qualifications
• 8 or more years of work experience with a Bachelor’s Degree or 4 or more years of relevant experience with an Advanced Degree (e.g. Masters, MBA, JD, MD) or up to 3 years of relevant experience with a PhD
• Hands on experience performing Security Architecture reviews / Threat Modeling using industry standards
• Hands on experience performing Pentest is a great plus
• A proven record of accomplishment in designing security controls for complex web applications with backend services expertise such as API Gateway, Identity and Access Management Services, Data Protection technologies, Security Information Event Management etc.
• Strong knowledge of deep design review and Secure Development Lifecycle methodologies, Agile based methodologies, middleware platforms, development platforms (Java, C, C++, .NET etc.)
• Extensive knowledge in OWASP Web Top 10 and CWE Top 25
• An individual with experience of working on large scale cloud-based services (including SaaS, PaaS, IaaS) and understanding of security challenges in deploying Cloud Applications
• Technical experience with security technologies including, but not limited to, intrusion detection/prevention, event correlation, firewall, antivirus, anti-spam, policy enforcement, patch/configuration management, usage monitoring, audit, secure application development, etc.
• Nice to have or willing to obtain industry standard certifications like CISSP, GIAC- GWAPT, GPEN, OSCP
• Strong written and oral communication skills to document reports on assessments and communicate potential weaknesses to the IT team or management
• Experience supporting M&A Activities is a plus