{"id":2102954,"url":"https://alion.io/job/entrust-application-security-architect","title":"Application Security Architect","company":{"id":4788,"name":"Entrust","domain":"entrust.com","url":"https://alion.io/company/entrust","size_band":"201-500","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":{"grade":"B","score":75,"open_postings":12,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-10-10T05:45:15Z"}},"role":"Security","role_family":"Security","seniority":"staff","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Shakopee, United States","United Kingdom"],"countries":["US","GB"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":143635,"max":210664,"currency":"USD","period":"year","gross":null,"usd_annual":210664},"salary_estimate":null,"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AI Agents","optional":false},{"name":"CI/CD","optional":false},{"name":"Defense in Depth","optional":false},{"name":"Least Privilege","optional":false},{"name":"Threat Modeling","optional":false},{"name":"Zero Trust","optional":false},{"name":"AWS","optional":true},{"name":"Azure","optional":true},{"name":"Kubernetes","optional":true},{"name":"Microsoft Defender","optional":true},{"name":"Microsoft Sentinel","optional":true}],"status":"live","first_seen_at":"2026-10-08T19:18:47Z","employer_posted_date":"2026-10-08","last_verified_at":"2026-10-11T19:10:17Z","board_verified":true,"closed_at":null,"days_open":3,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":3},"description":"Join us at Entrust\nAt Entrust, we’reshaping the future of identity centric security solutions. From our comprehensive portfolio of solutions to our flexible, global workplace, we empower careers, foster collaboration, and build solutions that help keep the world moving safely.\nGet to Know Us\nHeadquartered in Minnesota, Entrust is an industry leader in identity-centric security solutions, serving over 150 countries with cutting-edge, scalable technologies. But our secret weapon? Our people. It’sthe curiosity, dedication, and innovation that drive our success and help us anticipatethe future.\nEntrust is seeking an Information Security Architect to join the Information Security Architecture and Engineering team, reporting to the Director, Information Security Architecture and Engineering. This role partners across Information Security, Information Technology, product, cloud, and business teams to design practical security controls, assess technology risk, and help implement secure, resilient services across enterprise, cloud, software-as-a-service, and hosted environments. This position may be based near an Entrust office and work in a hybrid capacity, subject to current business requirements.\nPosition Overview:\nThe Information Security Architect designs and reviews security architectures that support Entrust’s enterprise and customer-facing services. The architect translates business, technical, regulatory, and threat requirements into clear security requirements, logical designs, standards, and implementation guidance. The role works under the direction of senior architects and the Director, contributes to technology evaluations and risk decisions, and remains engaged through implementation and validation. Primary coverage includes:\nEnterprise artificial intelligence and agent security, including data protection, identity, prompt-injection resistance, logging, monitoring, and containment\nCloud, software-as-a-service, and hybrid security architecture\nIdentity and access management, privileged access, machine identities, and Zero Trust design\nNetwork security, segmentation, firewalls, web application firewalls, secure access, and cloud-delivered controls\nSecurity monitoring and telemetry architecture and related integrations\nCloud-native application protection, secure access, vulnerability management, endpoint security, and security posture management\nSecurity automation, orchestration, infrastructure as code, policy as code, and repeatable control deployment\nResilience, recovery, cryptography, secrets management, and key management\nThis role works closely with Information Technology, Information Security, product and application teams, and service owners. The architect must be able to collaborate across disciplines, document decisions clearly, and follow designs through implementation. Practical experience configuring, integrating, testing, or operating security controls is important, but the role is not expected to be the senior subject-matter expert for every technology in scope.\nResponsibilities:\nOverall Security Architecture\nLearn and apply Entrust security principles, reference architectures, standards, and approved design patterns.\nDevelop security requirements and logical designs for new and changed services across cloud, on-premises, software-as-a-service, and hybrid environments.\nAssess trust boundaries, data flows, identities, threats, failure modes, and regulatory obligations that materially affect a design.\nApply Zero Trust, least privilege, defense in depth, secure-by-design, and privacy-by-design principles.\nPartner with enterprise, cloud, network, application, identity, data, and security specialists to produce implementable designs.\nIdentify control gaps, document material risk and assumptions, recommend proportionate mitigations, and escalate residual risk for decision when needed.\nContribute to security standards, patterns, and reusable guidance based on lessons from architecture engagements.\nDetailed Security Design\nTranslate approved requirements into logical and physical security designs, control configurations, and implementation guidance.\nDesign or integrate controls for identity, network, endpoint, cloud, application, data protection, security monitoring, and resilience.\nDefine required security telemetry, logging, alerting, retention, and operational ownership so implemented controls can be monitored and supported.\nSupport threat modeling and technical risk assessments for applications, infrastructure, cloud services, artificial intelligence solutions, and third-party platforms.\nEvaluate security capabilities and vendor claims through documented requirements, proofs of concept, testing, and evidence.\nPromote automation, infrastructure as code, policy as code, and secure continuous integration and continuous delivery practices where they improve consistency and control evidence.\nWork with implementers to validate that designs are feasible, supportable, resilient, and aligned with recovery requirements.\nDesign Review\nReview solution designs, data-flow diagrams, threat models, build documentation, test plans, and implementation changes for security impact.\nProvide clear findings, required actions, and risk-based recommendations to technical teams and decision-makers.\nVerify that security requirements and control ownership are reflected in implementation and test evidence.\nParticipate in architecture, design, and change reviews for material technology changes.\nSupport troubleshooting of complex issues that cross security, cloud, network, identity, application, or data domains.\nResearch emerging technologies, attack techniques, and control capabilities, including artificial intelligence and agentic systems, and recommend practical adoption or mitigation actions.\nBasic Qualifications:\nBachelor’s degree in cybersecurity, computer science, information systems, engineering, or a related field, or equivalent relevant experience.\nTypically five or more years of relevant experience across information security, infrastructure, cloud, networking, software engineering, or technology risk, including at least two years contributing to security design, engineering, or architecture work.\nWorking knowledge of security architecture principles, common threats and vulnerabilities, risk assessment, and compensating controls.\nExperience with at least two relevant domains, such as cloud security, identity and access management, network security, application security, security monitoring, endpoint security, data protection, or vulnerability management.\nExperience reviewing technical designs and converting requirements and risks into practical security controls.\nFamiliarity with public cloud and software-as-a-service security concepts, shared-responsibility models, and modern identity-centered security.\nAbility to create clear architecture diagrams, requirements, decision records, standards, and implementation guidance.\nAbility to communicate effectively with engineers, architects, service owners, risk and compliance partners, and business stakeholders.\nAbility to work across multiple teams, manage assigned architecture engagements, and follow work through implementation and validation.\nWork authorization and travel requirements will be defined for the hiring location and business need.\nPreferred Qualifications:\nHands-on experience with Microsoft Azure, Amazon Web Services, Microsoft Sentinel, Microsoft Defender, Microsoft Purview, or comparable security platforms.\nExperience with Zero Trust, cloud-native application protection, data loss prevention, cloud access security brokers, security information and event management, endpoint detection and response, web application firewalls, network segmentation, or privileged access.\nExperience with threat modeling, application programming interface security, containers, Kubernetes, DevSecOps, infrastructure as code, or policy as code.\nExposure to artificial intelligence security, agent security, model and prompt risk, machine identities, or governance controls for enterprise artificial intelligence.\nKnowledge of recognized frameworks and standards such as the National Institute of Standards and Technology Cybersecurity Framework, NIST Zero Trust Architecture, International Organization for Standardization 27001, Payment Card Industry Data Security Standard, Federal Risk and Authorization Management Program, or Cloud Security Alliance guidance.\nExperience in a global enterprise, regulated environment, software-as-a-service provider, managed service, or high-availability environment.\nIndustry certification such as Certified Information Systems Security Professional, Certified Cloud Security Professional, Azure Security Engineer Associate, AWS Certified Security - Specialty, or a comparable credential.\nExperience evaluating security products, conducting proofs of concept, or validating controls with implementation and test evidence.\nAt Entrust, we don’tjust offer jobs - we offer career journeys. Here is what you can expect when you join our team:\nCareer Growth: Whether you’rea budding developer or a seasoned expert, we’reinvested in your professional journey. With learning-forwardinitiatives and exciting challenges, your growth is our priority.\n\nFlexibility: Life is all about balance. Whether you’reremote, hybrid, or on-site, we offer flexible options that fit your lifestyle.\n\nCollaboration: Here, your voice matters. Our teams thrive on sharing ideas, brainstorming solutions, and working together to build a better tomorrow.\n\nWe believe in securing identities-but it doesn’tstop there. At Entrust, we’repassionate about valuing all identities. Our culture is built on diversity, inclusion, and respect. From unconscious biastraining for our leaders to global affinity groups that connect colleagues across the globe, we’recreating a community where everyone is encouraged to be themselves.\nReady to Make an Impact?\nIf you’reexcited by the prospect of innovating, growing your career, and collaborating in a dynamic environment, Entrust is the place for you. Join us in making a difference. Let’sbuild a more secure world-together.\nApply today!\nFor more information, visit www.entrust.com. Follow us on, LinkedIn, Facebook, Instagram, and YouTube\nCompensation Range:\nThe anticipated starting base pay for this position is: $143,635-$210,664 per year (in the primary posting location). Actual compensation will be determined based on geographic location, education, skills and experience. This position is also eligible for the company’s discretionary annual incentive plan. In addition to your pay, Entrust offers eligible colleagues and their dependents comprehensive health and well-being programs which include medical, vision, dental, a generous 401(k) matching contribution, life and disability insurance, mental health coaching, virtual fitness programs, paid personal time off plus 12 paid holidays, parental leave and education reimbursement. Please speak with the recruiter for more details. Note: Benefit and Compensation programs are subject to eligibility requirements and other terms of the applicable plan or program. Entrust has the right to end, suspend or amend any of its plans at any time in whole or in part.\nFor US roles, or where applicable:\nEntrust is an EEO/AA/Disabled/VeteransEmployer\nFor Canadian roles, or where applicable:\nEntrust values diversity and inclusion and we are committed to building a diverse workforce with wide perspectives and innovative ideas. We welcome applications from qualified individuals of all backgrounds, and we strive to provide an accessible experience for candidates of all abilities.\nIf you require an accommodation, contact .\nRecruiter:\nSteve ","description_format":"text","description_chars":11775,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":["Parental leave"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Application Security","Cybersecurity","Identity Management","Digital Signature"],"lifecycle":[{"event":"open","at":"2026-10-08T19:18:47Z"}],"visa":[],"liveness":{"score":63,"band":"ok","label":"Likely open","p_open":1,"p_active":0.632,"p_room":1,"age_days":1,"expected_fill_days":51,"reasons":["conf:0","stale_co","velocity","win:early"],"computed_at":"2026-10-10T05:45:15Z"},"pay":{"stated_usd_annual":210664,"is_top_pay":true},"html_url":"https://alion.io/job/entrust-application-security-architect","json_url":"https://alion.io/job/entrust-application-security-architect.json","meta":{"generated_at":"2026-10-11T20:37:36Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler_verified","counted_by":"address","units_charged":1,"used_today":8809,"day_limit":null,"remaining_today":null,"minute_limit":300,"resets_at":"2026-10-12T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":4788},"rest":"https://alion.io/mcp/rest/get_company?id=4788"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fentrust-application-security-architect"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fentrust-application-security-architect"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fentrust-application-security-architect"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/entrust-application-security-architect\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fentrust-application-security-architect"}]}