Authentication, Centralized Operations/Management, Certificate Issuance, Cloud Computing, Cryptography, Data Collection, Defense in Depth, Dental Insurance, Distributed Computing, Production Systems, Public Key Infrastructure (PKI), Regulatory Requirements, SASL (Simple Authentication and Security Layer), SSL-TLS (Secure Socket Layer - Transport Layer Security), Security Architecture, Threat Modeling, Vision Plan, X.509 Digital Certificate
Location:
Chandler, AZ
Salary Range:
Competitive, based on experience
Introduction
The position is accountable for the end-to-end security architecture, threat modeling, and compliance posture of the Collector Agent Layer. This role serves as a mandatory Phase-0 security gate, with formal sign-off required before any agent or collector is permitted to interact with production environments. The architect designs and governs cryptographic trust models, secure identity and authentication mechanisms, tamper-detection controls, and enterprise secret-management integrations to ensure that all agent-based data collection is secure, auditable, and compliant with enterprise and regulatory requirements.
Required Skills & Qualifications
- 7 years experience with threat modeling for distributed systems and agent-based architectures.
- Strong knowledge of PKI, X.509 certificates, mTLS, and cryptographic trust models.
- Hands-on expertise with Kafka security, including SASL/SCRAM authentication and authorization.
- Proven experience designing HMAC-based integrity and tamper-detection mechanisms.
- Enterprise-scale experience integrating with Vault or centralized secrets-management platforms.
Preferred Skills & Qualifications
Day-to-Day Responsibilities
- Own the Collector Agent Layer Threat Model, serving as a signed Phase-0 blocker for production deployment.
- Define trust boundaries, attack surfaces, and threat vectors for agent-based architectures.
- Ensure threat models are reviewed, approved, and version-controlled prior to any production access.
- Design and govern the mutual TLS (mTLS) PKI architecture, including certificate issuance, rotation, revocation, and trust chains.
- Architect HMAC-based tamper detection to ensure message integrity and non-repudiation across the agent pipeline.
Company Benefits & Culture
- Comprehensive health, dental, and vision insurance
- Flexible working hours and remote work options
- Professional development opportunities
For immediate consideration please click APPLY to begin the screening process.