Entrust
Application Security Architect
United States - Shakopee, MN (GHQ) · United Kingdom - Field
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Seniority
- Mid level
- Countries
- US, GB
- Work mode
- On-site / unstated
- First seen by hirly
- 9 Oct 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Join us at Entrust
At Entrust, we’re shaping the future of identity centric security solutions. From our comprehensive portfolio of solutions to our flexible, global workplace, we empower careers, foster collaboration, and build solutions that help keep the world moving safely .
Get to Know Us
Headquartered in Minnesota, Entrust is an industry leader in identity-centric security solutions, serving over 150 countries with cutting-edge , scalable technologies. But our secret weapon? Our people. It’s the curiosity , dedication, and innovation that drive our success and help us anticipate the future.
Entrust is seeking an Information Security Architect to join the Information Security Architecture and Engineering team, reporting to the Director, Information Security Architecture and Engineering . This role partners across Information Security, Information Technology, product, cloud, and business teams to design practical security controls, assess technology risk, and help implement secure, resilient services across enterprise, cloud, software-as-a-service, and hosted environments. This position may be based near an Entrust office and work in a hybrid capacity, subject to current business requirements.
Position Overview:
The Information Security Architect designs and reviews security architectures that support Entrust’s enterprise and customer-facing services. The architect translates business, technical, regulatory, and threat requirements into clear security requirements, logical designs, standards, and implementation guidance. The role works under the direction of senior architects and the Director, contributes to technology evaluations and risk decisions, and remains engaged through implementation and validation. Primary coverage includes:
- Enterprise artificial intelligence and agent security, including data protection, identity, prompt-injection resistance, logging, monitoring, and containment
- Cloud, software-as-a-service, and hybrid security architecture
- Identity and access management, privileged access, machine identities, and Zero Trust design
- Network security, segmentation, firewalls, web application firewalls, secure access, and cloud-delivered controls
- Security monitoring and telemetry architecture and related integrations
- Cloud-native application protection, secure access, vulnerability management, endpoint security, and security posture management
- Security automation, orchestration, infrastructure as code, policy as code, and repeatable control deployment
- Resilience, recovery, cryptography, secrets management, and key management
This role works closely with Information Technology, Information Security, product and application teams, and service owners. The architect must be able to collaborate across disciplines, document decisions clearly, and follow designs through implementation. Practical experience configuring, integrating, testing, or operating security controls is important, but the role is not expected to be the senior subject-matter expert for every technology in scope.
Responsibilities:
Overall Security Architecture
- Learn and apply Entrust security principles, reference architectures, standards, and approved design patterns.
- Develop security requirements and logical designs for new and changed services across cloud, on-premises, software-as-a-service, and hybrid environments.
- Assess trust boundaries, data flows, identities, threats, failure modes, and regulatory obligations that materially affect a design.
- Apply Zero Trust, least privilege, defense in depth, secure-by-design, and privacy-by-design principles.
- Partner with enterprise, cloud, network, application, identity, data, and security specialists to produce implementable designs.
- Identify control gaps, document material risk and assumptions, recommend proportionate mitigations, and escalate residual risk for decision when needed.
- Contribute to security standards, patterns, and reusable guidance based on lessons from architecture engagements.
Detailed Security Design
- Translate approved requirements into logical and physical security designs, control configurations, and implementation guidance.
- Design or integrate controls for identity, network, endpoint, cloud, application, data protection, security monitoring, and resilience.
- Define required security telemetry, logging, alerting, retention, and operational ownership so implemented controls can be monitored and supported.
- Support threat modeling and technical risk assessments for applications, infrastructure, cloud services, artificial intelligence solutions, and third-party platforms.
- Evaluate security capabilities and vendor claims through documented requirements, proofs of concept, testing, and evidence.
- Promote automation, infrastructure as code, policy as code, and secure continuous integration and continuous delivery practices where they improve consistency and control evidence.
- Work with implementers to validate that designs are feasible, supportable, resilient, and aligned with recovery requirements.
Design Review
- Review solution designs, data-flow diagrams, threat models, build documentation, test plans, and implementation changes for security impact.
- Provide clear findings, required actions, and risk-based recommendations to technical teams and decision-makers.
- Verify that security requirements and control ownership are reflected in implementation and test evidence.
- Participate in architecture, design, and change reviews for material technology changes.
- Support troubleshooting of complex issues that cross security, cloud, network, identity, application, or data domains.
- Research emerging technologies, attack techniques, and control capabilities, including artificial intelligence and agentic systems, and recommend practical adoption or mitigation actions.
Basic Qualifications:
- Bachelor’s degree in cybersecurity, computer science, information systems, engineering, or a related field, or equivalent relevant experience.
- Typically five or more years of relevant experience across information security, infrastructure, cloud, networking, software engineering, or technology risk, including at least two years contributing to security design, engineering, or architecture work.
- Working knowledge of security architecture principles, common threats and vulnerabilities, risk assessment, and compensating controls.
- Experience with at least two relevant domains, such as cloud security, identity and access management, network security, application security, security monitoring, endpoint security, data protection, or vulnerability management.
- Experience reviewing technical designs and converting requirements and risks into practical security controls.
- Familiarity with public cloud and software-as-a-service security concepts, shared-responsibility models, and modern identity-centered security.
- Ability to create clear architecture diagrams, requirements, decision records, standards, and implementation guidance.
- Ability to communicate effectively with engineers, architects, service owners, risk and compliance partners, and business stakeholders.
- Ability to work across multiple teams, manage assigned architecture engagements, and follow work through implementation and validation.
- Work authorization and travel requirements will be defined for the hiring location and business need.
Preferred Qualifications:
- Hands-on experience with Microsoft Azure, Amazon Web Services, Microsoft Sentinel, Microsoft Defender, Microsoft Purview, or comparable security platforms.
- Experience with Zero Trust, cloud-native application protection, data loss prevention, cloud access security brokers, security information and event management, endpoint detection and response, web application firewalls, network segmentation, or privileged access.
- Experience with threat modeling, application programming interface security, containers, Kubernetes, DevSecOps, infrastructu
Listed on hirly, a job board. hirly is not the employer: Entrust is hiring for this role.
Similar jobs
- Zero Trust Security ArchitectStarfish · 2 LocationsFirst seen 4d ago
- Security ArchitectKslaw · 2 LocationsFirst seen 10d ago
- Security Architect IIAkamai · United StatesFirst seen today
- Associate Security ArchitectCaesars Entertainment · Las Vegas, NV, United States; Reno, NV, United StatesFirst seen today
- Global Cloud & AI Security ArchitectKla · Ann Arbor, MIFirst seen yesterday
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job