Application Security Architect

Birmingham, AL

SCS Technology Security

Application Security Architecture

Job Description

Schedule: M-F

Location: Primarily remote/Hybrid 20% in office – Atlanta or Birmingham

Position Summary:

Southern Company, a major U.S. energy firm, is seeking an experienced security architect and technical leader, to design creative solutions and reduce risk. The candidate will directly support the company’s efforts to mitigate real and potential cyber threats to the company’s facilities, personnel, technology, operations, and brand – including critical electric and gas utility infrastructure and its privately owned telecommunications network. In this role, the potential for individual impact is substantial and has high visibility within the corporate leadership and governance.

This role will have responsibility for setting the strategic direction for the Enterprise Security Architecture teams in the areas of Application and Cloud Security and then execute projects against the strategic roadmap. This position is primarily focused on Application and Code Security but does touch other security domains as well. Interested applicants should be well rounded in their understanding and application of different security and technology platforms; in areas such as identity, networking, endpoint, data, monitoring, cloud, and/or application security. Qualified candidates need to be able to align strategy and execution to increase cybersecurity maturity, anticipate future requirements for complex traditional, hybrid, and multi-cloud environments, drive initiatives via influence and relationships into business processes, keep up with current security trends, be focused on results, and be a self-starter.

This position is responsible for ensuring the confidentiality, integrity, and availability of the company’s information assets. This will be accomplished by:

  • Establishing and implementing an information security framework and technical architecture.

  • Designing, developing, and implementing information security products.

  • Providing information security expertise and consulting.

While Southern Company is headquartered in Atlanta, we bring energy to homes and businesses across the country. We’ve made our name as a leading producer of clean, safe, reliable, and affordable energy, and we approach each day as a vital step in building the future of energy. We’re always looking ahead, and our innovations in the industry—from new nuclear to deployment of electric transportation and renewables —help brighten the lives and businesses of millions of customers nationwide. Our team is critical to building the future of energy with secure, resilient, and sustainable cyber solutions.

Job Responsibilities:

  • Align forward thinking strategy with business goals to integrate and raise the bar on security practices and solutions.

  • Assist in the ongoing development of Southern Company’s security architecture – identify areas of opportunity, research alternatives and recommend solutions.

  • Develop creative solutions to meet business needs while ensuring appropriate security controls and best practices are implemented.

  • Partner with others to identify and resolve information security issues.

  • Plan, coordinate, and lead information security projects.

  • Help customers understand and apply information security concepts, processes, and technologies.

  • Maintain current knowledge of information security concepts, technologies, and practices.

  • Mentor others to strengthen cybersecurity principles and best practices to outside operational areas.

  • Establish and maintain excellent working relationships and partnerships across the Technology Organization functions, business partners, and external vendors and suppliers.

  • Create an environment that fosters accountability, innovation, and engagement at all levels.

  • Streamline the software development lifecycle to reduce application vulnerabilities, improve developer productivity, and code quality.

Education/Experience:

  • Experience with software development and programing, code reviews, and application vulnerability remediation.

  • Experience with network infrastructure, modern operating systems, database applications, web applications and other computing technologies

  • Hands-on experience designing, architecting, and implementing various information security tools/products such as PKI, Static or Dynamic Code Analysis, Next-Generation Firewalls, HSM’s, SIEM, Multi-Factor Authentication, IPS, NetFlow Monitoring, Full Packet Capture, Database Encryption, Privileged Identity Management, Cloud Posture Management, etc.

  • Ability to lead a project from concept through implementation and anticipate potential problems.

  • Comprehensive knowledge and understanding of information security concepts and best practices (NIST, COBIT, ISO, PCI, OWASP, etc)

  • Ability to perform detailed information security risk assessments and recommend mitigating controls.

  • Experience promoting security as a business enablement function through the use of documentation, metrics, and strong verbal communication.

  • Industry certification preferred (CISSP, CCSP, CISA, GIAC, etc)

Requirements and qualifications:

Minimum

  • Experience with software development and programing, code reviews, and application vulnerability remediation.

  • Strong technical knowledge of application development practices, CI/CD pipelines, various cloud platforms including Azure, AWS, or GCP, modern operating systems, networking protocols and designs, and identity management.

  • Experience with development platforms and CI/CD tools, such as TFS/ADO/Git or Jenkins.

  • Proficiency in one or more coding languages, such as C#, Python, Java, or Java Script

  • Experience promoting security as a business enablement function using influence, metrics, documentation, strong verbal communication, and presentation skills.

  • At least 5 years of work experience playing a key role in building technical programs.

  • Ability to lead a project from concept through implementation and anticipate potential problems.

  • Experience prioritizing and executing with minimal direction or oversight.

  • Must pass NERC CIP & Insider Threat Protection background checks.

Preferred Qualifications

  • Development or Programming background.

  • Azure, AWS, and GCP certifications preferred.

  • Competency in APIs (Rest, Graph) and/or JavaScript/JSON/Kubernetes/SQL.

  • Industry certifications such as: CISSP, CCSP, CISA, GIAC, OSCP, CRISC, CCNP, etc.

  • Experience with information security frameworks such as: COBIT, NIST, OWASP, etc.

  • Familiarity with nation state, sophisticated criminal, and supply chain threats.

  • Up-to-date knowledge of current hacking techniques, vulnerability disclosures, and data breach incidents.

  • Working knowledge of cloud and traditional security network architectures.

  • Experience with cybersecurity analysis and analytic tradecraft.

#LI

Southern Company (NYSE: SO) is a leading energy provider serving 9 million residential and commercial customers across the Southeast and beyond through its family of companies. Providing clean, safe, reliable and affordable energy with excellent service is our mission. The company has electric operating companies in three states, natural gas distribution companies in four states, a competitive generation company, a leading distributed energy infrastructure company with national capabilities, a fiber optics network, and telecommunications services. Through an industry-leading commitment to innovation, resilience, and sustainability, we are taking action to meet our customers’ and communities’ needs while advancing our commitment to net zero emissions by 2050. Our uncompromising values ensure we put the needs of those we serve at the center of everything we do and are the key to our sustained success. We are transforming energy into economic, environmental and social progress for tomorrow. Our corporate culture and hiring practices have earned the company national awards and recognition from numerous organizations, including Forbes, Military Times, DiversityInc, Black Enterprise, J.D. Power, Fortune, Human Rights Campaign and more. To learn more, visit www.southerncompany.com.

Southern Company is an equal opportunity employer where an applicant's qualifications are considered without regard to race, color, religion, sex, national origin, age, disability, veteran status, genetic information, sexual orientation, gender identity or expression, or any other basis prohibited by law.

Job Identification: 5661

Job Category: Cybersecurity

Job Schedule: Full time

Company: Southern Company Services

Apply