Job Summary:
Hitachi Vantara is a trusted data foundation for innovators, focusing on empowering businesses with data. They are seeking a Master Security Architect to ensure that products meet US Government security requirements and to evaluate the compliance of security offerings.
Responsibilities:
โข Working with Hitachi Vantara engineering teams and customers to ensure products meet US Government security requirements.
โข Evaluate the posture and compliance of security offerings (i.e. product or services) based upon internal/external criteria (e.g., standards, checklist, scanning tools, etc.), perform gap analysis, and report/brief the findings
โข Hardening Hitachi Vantara product and service offerings
โข Assisting the process of achieving and maintaining ATOs for both traditional and Fedramp based solutions.
โข Drafting, reviewing, and maintaining documents like System Security Plans (SSPs), Contingency Plans, and Plans of Action and Milestones (POA&Ms)
โข Providing security guidance and define requirements for Hitachi Vantaraโs internal systems, customer-facing services, and products
โข Be a master of identifying security design gaps in existing and proposed product and service architectures and recommend changes or enhancements
โข Collaborate with the other leaders of Hitachi Vantara including sales, product security and engineering
Qualifications:
Required:
โข Minimum 8 years of security architecture and/or engineering experience including a solid technical foundation in security and compliance.
โข Advanced technical capabilities in a wide array of platforms and systems (e.g., Linux, Windows, VMWare, SQL, etc.).
โข Familiar with industry and government security standards and baselines such as the DISA STIGs, CIS benchmarks, NIST 800-53, NIST Risk Management Framework, FIPS 140-2/3, the NIST Cybersecurity Framework and NIST 800-171.
โข Experience with Fedramp approval process and securing solutions deployed to public and private clouds, including AWS, Azure or GCP.
โข In-depth knowledge of risk assessments, network security, cryptography, authentication, secure systems development, and authorization.
โข Strong understanding of application security patterns including web application security (OWASP top 10, XSS, injection vulnerabilities, CSRF, platform security hardening), and mobile security (device fingerprinting, mobile authentication and key exchange) strategies.
โข Familiar with IAM federated identity strategies - SAML, OAuth, and OIDC protocols.
โข Ability to facilitate meetings with strong presentation skills and ability to quickly discern differing points of view versus derailing points of view.
โข Strong/expert level understanding of trends in the industry for information security policy, audit, compliance, and risk management.
Preferred:
โข Certifications Desired: CISSP, CSA, Security+
Company:
Hitachi Vantara drives data to meaningful outcomes. It is a sub-organization of Hitachi. Founded in 1979, the company is headquartered in Santa Clara, USA, with a team of 5001-10000 employees. The company is currently Late Stage.