
C2c jobs
Job Title: Security Architect with Java exp
Location: Austin`, TX
Duration: Contract
Rate : $65/Hr on C2C
Role Summary
We are looking for a Security Architect to own the security architecture and design assurance of enterprise web applications and services. You will review and define application security architecture, identify design-level weaknesses, specify the correct target-state design, and establish reusable secure-design patterns and assurance standards that engineering teams build to.
This is a design-authority role. The emphasis is on architectural judgement — trust boundaries, identity and authorization models, and data-protection design — rather than on tool operation or test execution.
Key Responsibilities
Security architecture and design review
• Review the security architecture of enterprise applications and services: trust boundaries, identity and tenancy models, authorization models, and sensitive-data flows
• Conduct threat modelling (STRIDE or equivalent) with engineering teams and derive prioritized, testable review plans from the model
• Identify design-level weaknesses that automated tooling does not surface — perimeter and gateway bypass, internal-trust assumptions that fail under external exposure, loss of end-user identity across service-to-service hops, and client-side-enforced tenant isolation
• Review authentication and authorization architecture: OAuth2/OIDC usage, token validation completeness, service-to-service authentication, and object- and function-level authorization across roles and tenants
• Review data-protection design: encryption in transit and at rest, key management, secrets handling, and logging hygiene for sensitive data
• Review platform architecture: container and Kubernetes security posture, infrastructure-as-code, and cloud IAM least privilege
Target-state design and patterns
• Specify target-state designs for architectural weaknesses, not problem statements alone
• Develop and publish reusable secure-design patterns and reference architectures for adoption across engineering teams
• Act as the design authority engineering teams consult before implementing security remediation
• Feed systemic recommendations into SDLC and CI/CD controls to prevent recurrence
Assurance and standards
• Define security review standards, assessment criteria and scoring or rating models, and defend them under challenge
• Assess applications against those standards and produce the resulting assurance findings and ratings
• Provide technical direction and quality assurance for a small security review team, including offshore members
• Mentor engineers in architecture-level security review
Stakeholder engagement
• Partner with central information security functions on assessment scope, coverage and findings
• Advise application owners and engineering leads on remediation design and prioritization
• Escalate risks and blockers clearly and early
Required Skills and Experience
• 10+ years in application or product security, including time in a named security architect or design authority role on enterprise systems
• Demonstrable track record of identifying design-level security weaknesses and specifying target-state designs that were adopted
• Experience authoring reference architectures or secure-design patterns used by multiple engineering teams
• Experience on, or running, an architecture or design review board or equivalent design gate
• Threat modelling at architecture level, including facilitating sessions with teams new to the practice
• Java and Spring Boot secure design and code review, including Spring Security and API gateway layers; awareness of reactive/non-blocking codebases
• Identity and access architecture — OAuth2/OIDC, JWT validation, federated enterprise identity providers, service-to-service authentication (HMAC-signed requests, app-to-app token exchange), session and token lifecycle
• Multi-tenant authorization architecture — broken object- and function-level authorization, tenant isolation design and verification
• Cloud and container security architecture — Kubernetes and Helm, container hardening, infrastructure-as-code review, cloud IAM across at least two major providers
• Working knowledge of OWASP ASVS, OWASP Top 10, OWASP API Security Top 10, and CVSS v4.0
• Experience handling confidential or regulated data under a formal classification scheme
• Ability to build the security model of a proprietary or undocumented internal framework from its source code
• Strong written communication — designs, findings and rationale must be actionable by engineers
• Ability to influence without direct authority, and to work credibly with both central security functions and delivery teams
Preferred:
• AI / LLM application security architecture — retrieval-augmented generation design, tenant isolation on retrieval, prompt and template provenance, treating model output as untrusted, agent and tool credential scope, Model Context Protocol (MCP) exposure
• Hands-on security testing or penetration testing background, sufficient to validate and demonstrate a finding
• API security architecture and authorization-matrix testing
• Software supply chain, SBOM and dependency risk management
• Experience establishing a security assurance programme where no formal process previously existed
• Familiarity with enterprise CI/CD security gates (SAST, SCA, secrets scanning)
Certifications
Demonstrable architectural depth is weighted above certification. One or more of the following is expected:
• CISSP, CSSLP, CISSP-ISSAP, or SABSA
• Valuable additions: CCSP, CKS, OSCP, GWAPT, or a recognized threat-modelling credential
To apply for this job email your details to venu@flexontechnologies.com